Postmortem
CitrixBleed and MOVEit: what a stack watchtower would have shown
Updated 2026-08-28
CitrixBleed and MOVEit were not subtle. They were KEV-class events on products companies forgot they still ran. A SaaS watchtower does not replace patching — it names the blast radius on the day CISA does.
The pattern is not “zero-day.” It is “we still have that box.”
CitrixBleed (CVE-2023-4966) leaked session tokens from NetScaler. MOVEit Transfer (CVE-2023-34362 and follow-ons) became a ransomware supply-chain story. Both spent time as news, then as KEV, then as board questions: were we on it, who owns it, when did we know?
Scanners help if the device is in inventory. Many Citrix and file-transfer boxes were not. SaaS-first companies still had them in a closet, at a subsidiary, or at a payroll vendor. The failure was awareness across the vendor list, not a missing CVSS decimal.
What the briefing should have contained
CVE identifier. Product name as CISA wrote it. Whether it matched a tool you listed (direct) or a parent/supplier. Ransomware-use flag if present. Required action in CISA’s words. A link to the advisory. That is a page, not a 30-page threat report.
ZeroDayTracker stores exactly that shape. Citrix and Ivanti are in the catalog because hybrid estates are real. MOVEit-class file-transfer tools should be named on your stack if you still run them — we cannot match a vendor you did not add.
Do not wait for the meme
By the time a vulnerability has a nickname, defenders who needed the first 48 hours have already lost them. KEV plus a named catalog is how a company without a CTI desk gets the first 48 hours at all. Newsletters are slower. Twitter is louder. Neither is a watchlist.
Watch the SaaS that holds your data.
Three tools free. Keep Track is $20/month for supplier blast-radius, full history, and a digest.