No, Citrix does not have a security updates mailing list. I inquired about this and they do not plan to do that in the near future.
A search through the knowledgebase found some security rollup patches for specific configurations (i.e. German XPe, or XP SP2 on NT4 TSE) and some security bulletins with general security information or (again) information on specific products and configurations (NFuse 1.5) My point is that since Citrix is a smaller piece of the puzzle than Microsoft's operating system, there are simply fewer opportunities for coding mistakes that lead to security holes (that and I personally think Citrix hires better programmers). I could not find any security patches that looked relevant to my environment and it is pretty standard (Win2K SP3, XPe FR2, Nfuse 1.7, ICA 6.3).
There are tons of security holes once a user has access to your server though (via published app or desktop). If you haven't you should look into using security policies or GPO (if you have Active Directory) to disable things like task manager that give users the ability to a run command. You should secure the file system and registry as tightly as you can without breaking your applications. Really too many tweaks to go over. Good luck.