Companies Are Ripping Citrix Devices Offline. Here's Why

Oct 7, 2026

Citrix NetScaler customers were pulling devices offline as attackers moved faster than the traditional patch and response cycle. What happens when cyberattacks move faster than security teams can react?

In this episode of ShipTalk, Martin Reynolds and Adam Arellano are joined by Starr Brown, Director of Open Source Projects at OWASP, to break down the latest Citrix NetScaler ADC and Gateway security vulnerabilities, active exploitation, and the rapidly shrinking window between vulnerability discovery and attack.

Then the conversation gets bigger.

The team looks at an AI-powered campaign targeting PaperCut that compromised hundreds of systems across 395 organizations in 48 countries, and asks whether human defenders can realistically respond when AI agents can operate at machine speed.

They also discuss:

  • Why security and resilience may matter more than shipping the next feature
  • Whether AI companies can effectively regulate themselves
  • Who actually writes technology regulations like FedRAMP
  • Goldman Sachs, Morgan Stanley, OpenAI, Anthropic and the enormous amount of money flowing into AI
  • Why buying an AI or security tool does not automatically make your organization secure

ShipTalk is a news podcast about how software delivery is changing in the AI era, brought to you by Harness.

CHAPTERS

00:00 Ransomware is already deployed

00:13 Meet Starr Brown from OWASP

00:33 The Citrix NetScaler security crisis

03:04 Citrix is forced to move fast

04:27 The “-6 hour” exploit window

04:51 AI agents attack PaperCut

06:44 Can humans respond fast enough?

08:00 Resilience vs. shipping more features

10:12 Can AI companies regulate themselves?

12:13 Who actually writes tech regulation?

13:03 OpenAI, Anthropic and Wall Street

15:35 What companies get wrong about AI security

16:37 Final takeaways

17:36 Stop talking. Start shipping.

Learn more about ShipTalk and follow the show for more conversations about AI, cybersecurity, DevOps, software engineering and the future of software delivery.

Follow
Adam Arellano: https://www.linkedin.com/in/adamrossarellano/
Martin Reynolds: https://www.linkedin.com/in/martinreynolds/
Starr Brown: https://www.linkedin.com/in/starr-brown-8837547/

#Cybersecurity #AI #Citrix