When you purchase through links on our site, we may earn an affiliate commission.Heres how it works.

The campaigns allegedly started in late August this year.

Prior to Citrixs reaction, both Mandiant and CISA warned about the flaw.

password manager security

Mandiant said hackers were probably using it to hijackauthenticationsessions and steal corporate data since August.

In the meantime, someone posted a proof-of-concept on GitHub, called Citrix Bleed.

ViaBleepingComputer

More from TechRadar Pro