# TW Week 76 KM

Source: https://www.youtube.com/watch?v=zEN0pGH4gos
Recap page: https://rapidrecap.app/video/zEN0pGH4gos
Generated: 2025-07-17T01:32:04.445+00:00

---
## Quick Overview

NVIDIA has issued a security notice regarding a high-severity Rowhammer exploit now ported to GPUs, affecting various GDDR memory types, with a mitigation recommendation to enable system-level ECC. Concurrently, CitrixBleed2, a critical vulnerability (CVE-2025-5777) allowing authentication bypass via an out-of-bounds memory read in NetScaler ADC and Gateway products, has been confirmed as actively exploited in the wild by CISA, despite initial claims from Citrix of no active exploitation.

**Key Points:**
- University of Toronto researchers successfully ported the Rowhammer attack, previously known for CPUs, to GPUs, demonstrating it on an NVIDIA A6000 with GDDR6 memory.
- The GPUHammer attack causes bit-flips in GDDR memory, compromising security and reliability, but was mitigated when Error-Correcting Code (ECC) was enabled.
- NVIDIA has released a security notice and recommends enabling system-level ECC across affected products to counter the GPUHammer exploit.
- CISA confirmed active exploitation of CitrixBleed2 (CVE-2025-5777), adding it to their Known Exploited Vulnerabilities Catalog.
- CitrixBleed2 allows authentication bypass in Citrix NetScaler ADC and Gateway products via an out-of-bounds memory read.
- Citrix initially stated no active exploitation of CitrixBleed2 but later retracted this claim after researchers published working exploits and telemetry confirmed its use in the wild.
- CitrixBleed2 carries a high severity CVSS score of 9.3.

![Screenshot at 0:11: A woman speaks into a microphone with a text overlay 'CPU Exploit Ported to GPU' at the bottom of the screen.](https://ss.rapidrecap.app/screens/zEN0pGH4gos/00-00-11.png)

**Context:** This Threat Wire episode discusses two critical cybersecurity vulnerabilities. The first involves a CPU-based memory attack called Rowhammer being successfully adapted to target GPUs, raising concerns for systems utilizing GDDR memory. The second focuses on the ongoing active exploitation of CitrixBleed2, a vulnerability in Citrix NetScaler products that allows for authentication bypass, highlighting a significant shift in Citrix's public stance on its severity.

## Detailed Analysis

This week's Threat Wire covers two significant cybersecurity updates. First, NVIDIA released a security notice about a high-severity issue where the Rowhammer attack, traditionally affecting CPUs, has been successfully ported to GPUs, specifically impacting GDDR memory types. Researchers at the University of Toronto published a paper demonstrating this GPUHammer attack on an NVIDIA A6000 GPU with GDDR6 memory, noting that the exploit was effective when Error-Correcting Code (ECC) was disabled but failed when ECC was enabled. NVIDIA recommends implementing system-level ECC as a mitigation. Second, the CitrixBleed2 vulnerability (CVE-2025-5777), affecting Citrix NetScaler ADC and Gateway products, has been confirmed as actively exploited in the wild by CISA, which added it to its Known Exploited Vulnerabilities Catalog. This vulnerability, introduced in June 2025, allows authentication bypass through an out-of-bounds memory read, building on the original CitrixBleed from 2023. Despite Citrix's initial statements denying active exploitation, the publication of working exploit versions by researchers and telemetry from GreyNoise honeypots confirmed its widespread use, forcing Citrix to retract their earlier claims.

### GPUHammer Vulnerability

- NVIDIA issued a high-severity security notice
- University of Toronto researchers demonstrated a Rowhammer attack on GPUs
- Rowhammer causes bit-flips by rapidly accessing memory rows
- Attack was successful on NVIDIA A6000 with GDDR6 memory when ECC was disabled
- Attack was unsuccessful when ECC was enabled

### Rowhammer on GPUs Challenges

- Proprietary mapping of physical memory to GDDR banks and rows
- High memory latency and faster refresh rates hinder effective hammering
- Proprietary mitigations in GDDR memories are difficult to reverse-engineer without FPGA-based test platforms

### NVIDIA Mitigation

- NVIDIA recommends implementing system-level ECC across affected products to mitigate the GPUHammer exploit

### CitrixBleed2 Confirmation

- CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities Catalog
- This confirms active exploitation of CitrixBleed2 in the wild
- Citrix initially denied active exploitation but later walked back their statement

### CitrixBleed2 Details

- Affects Citrix NetScaler ADC and Gateway products
- Allows authentication bypass via an out-of-bounds memory read
- Has a CVSS score of 9.3, indicating high severity
- Researchers published working exploit versions (POC/GTFOL)
- GreyNoise honeypot telemetry showed exploitation attempts as early as June 23rd

![Screenshot at 0:11: Text overlay 'CPU Exploit Ported to GPU' appears over the host](https://ss.rapidrecap.app/screens/zEN0pGH4gos/00-00-11.png)
![Screenshot at 0:25: A scientific paper titled 'GPUHammer: Rowhammer Attacks on GPU Memories are Practical' is displayed](https://ss.rapidrecap.app/screens/zEN0pGH4gos/00-00-25.png)
![Screenshot at 0:52: A quote from the paper's abstract explaining Rowhammer vulnerability is shown over a blurred city map](https://ss.rapidrecap.app/screens/zEN0pGH4gos/00-00-52.png)
![Screenshot at 1:14: Another quote from the paper's abstract detailing unique challenges for Rowhammer on GPUs is displayed](https://ss.rapidrecap.app/screens/zEN0pGH4gos/00-01-14.png)
![Screenshot at 1:59: Text overlay 'CitrixBleed2 Confirmed' appears over the host](https://ss.rapidrecap.app/screens/zEN0pGH4gos/00-01-59.png)
![Screenshot at 2:11: A CISA alert document titled 'CISA Adds One Known Exploited Vulnerability to Catalog' is shown](https://ss.rapidrecap.app/screens/zEN0pGH4gos/00-02-11.png)
