Comcast Cable's Xfinity brand has revealed a major data breach impacting 35.9 million customers, that resulted from exploitation of a Citrix vulnerability.
Reports suggested that the vulnerability had been exploited in the wild as far back as August 2023.
Found in Citrix NetScaler ADC and NetScaler Gateway appliances, exploitation allows threat actors to bypass multi-factor authentication and hijack user sessions.
Xfinity said that it determined on November 16 that its attackers had accessed customer data.
The firm has issued a password reset across all affected accounts and recommended customers enable multi-factor authentication.
Although the firm did not explicitly reveal the number of customers impacted, a notice published by the Office of the Maine Attorney General did have the figure.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Wed, 20 Dec 2023 09:31:11 +0000