When indications of exploit activity against an unknown vulnerability in Citrix NetScaler ADC and Gateway appliances late last week, researchers at watchTowr were among the first to speak up publicly about what was going on. They had information from national CERT authorities about the exploits, and recommended that customers take their appliances offline until fixes were ready.

It was a long weekend as customers and security teams waited for any sort of communication from Citrix, which didn't come until an advisory and patches were released Sunday afternoon. This case is yet another reminder just how important vendor communication is in such incidents and how much uncertainty can hamper security.

Ben Harris of watchTowr joins Dennis Fisher to walk through the Citrix NetScaler zero days that emerged over the weekend, from first detection of exploitation to reporting to finally some patches and why vendor communication is so vital in these cases.