TW Week 76 KM
Quick Overview
NVIDIA has issued a security notice regarding a high-severity Rowhammer exploit now ported to GPUs, affecting various GDDR memory types, with a mitigation recommendation to enable system-level ECC. Concurrently, CitrixBleed2, a critical vulnerability (CVE-2025-5777) allowing authentication bypass via an out-of-bounds memory read in NetScaler ADC and Gateway products, has been confirmed as actively exploited in the wild by CISA, despite initial claims from Citrix of no active exploitation.
Key Points: University of Toronto researchers successfully ported the Rowhammer attack, previously known for CPUs, to GPUs, demonstrating it on an NVIDIA A6000 with GDDR6 memory. The GPUHammer attack causes bit-flips in GDDR memory, compromising security and reliability, but was mitigated when Error-Correcting Code (ECC) was enabled. NVIDIA has released a security notice and recommends enabling system-level ECC across affected products to counter the GPUHammer exploit. CISA confirmed active exploitation of CitrixBleed2 (CVE-2025-5777), adding it to their Known Exploited Vulnerabilities Catalog. CitrixBleed2 allows authentication bypass in Citrix NetScaler ADC and Gateway products via an out-of-bounds memory read. Citrix initially stated no active exploitation of CitrixBleed2 but later retracted this claim after researchers published working exploits and telemetry confirmed its use in the wild. CitrixBleed2 carries a high severity CVSS score of 9.3.
Context: This Threat Wire episode discusses two critical cybersecurity vulnerabilities. The first involves a CPU-based memory attack called Rowhammer being successfully adapted to target GPUs, raising concerns for systems utilizing GDDR memory. The second focuses on the ongoing active exploitation of CitrixBleed2, a vulnerability in Citrix NetScaler products that allows for authentication bypass, highlighting a significant shift in Citrix's public stance on its severity.
Detailed Analysis
This week's Threat Wire covers two significant cybersecurity updates. First, NVIDIA released a security notice about a high-severity issue where the Rowhammer attack, traditionally affecting CPUs, has been successfully ported to GPUs, specifically impacting GDDR memory types. Researchers at the University of Toronto published a paper demonstrating this GPUHammer attack on an NVIDIA A6000 GPU with GDDR6 memory, noting that the exploit was effective when Error-Correcting Code (ECC) was disabled but failed when ECC was enabled. NVIDIA recommends implementing system-level ECC as a mitigation. Second, the CitrixBleed2 vulnerability (CVE-2025-5777), affecting Citrix NetScaler ADC and Gateway products, has been confirmed as actively exploited in the wild by CISA, which added it to its Known Exploited Vulnerabilities Catalog. This vulnerability, introduced in June 2025, allows authentication bypass through an out-of-bounds memory read, building on the original CitrixBleed from 2023. Despite Citrix's initial statements denying active exploitation, the publication of working exploit versions by researchers and telemetry from GreyNoise honeypots confirmed its widespread use, forcing Citrix to retract their earlier claims.