<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Edge Devices on Martin&#39;s Blog</title>
		<link>https://mac.sploit.dk/tags/edge-devices/</link>
		<description>Recent content in Edge Devices on Martin&#39;s Blog</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Sat, 03 Oct 2026 15:22:20 +0200</lastBuildDate>
		
			<atom:link href="https://mac.sploit.dk/tags/edge-devices/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>NetScaler Needs More Than Another Patch</title>
				<link>https://mac.sploit.dk/blog/netscaler-needs-more-than-a-patch/</link>
				<pubDate>Fri, 02 Oct 2026 08:00:00 +0200</pubDate>
				<guid>https://mac.sploit.dk/blog/netscaler-needs-more-than-a-patch/</guid>
				<description>&lt;p&gt;Another critical NetScaler advisory. Another emergency upgrade. Another security team trying to establish whether the box protecting access to the network has already let somebody in.&lt;/p&gt;&#xA;&lt;p&gt;The routine is becoming far too familiar. We buy an appliance to handle hostile traffic, give it certificates, authentication duties and access to internal services, then organise an emergency every time it mishandles the traffic it was bought to handle.&lt;/p&gt;&#xA;&lt;p&gt;My patience with that arrangement has run out.&lt;/p&gt;&#xA;&lt;p&gt;NetScaler is worth examining because it brings the problem into focus: a substantial security role, a long vulnerability history, and an installed base with plenty of reasons to keep renewing. The same procurement questions belong in front of every edge vendor.&lt;/p&gt;&#xA;&lt;p&gt;There is one very recent development. On 1 October 2026, Citrix released a Linux-based NetScaler VPX 15.1 as a Tech Preview, with changes to the platform and its hardening. On paper it looks like the right direction. But it is a preview and a feature list, not yet a product customers run, and the question is how much it improves the security boundaries they actually depend on. We need to see the shipping product before giving it credit.&lt;/p&gt;&#xA;&lt;p&gt;I want evidence that the next serious bug has somewhere to stop.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
