Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Anubis ransomware affiliates are chaining the new Citrix Bleed 2 flaw (CVE-2025-5777) with BYOVD and compromised supply-chain credentials — a converging-TTPs pattern that demands layered perimeter and endpoint defences.
Summary written by editorial AI · Source link below
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.
"Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral
Editorial Analysis
Citrix NetScaler remains a prime gateway into European enterprises; a second Bleed variant actively exploited by ransomware affiliates demands immediate patching and network-segmentation review.
Patch CVE-2025-5777 on all Citrix NetScaler instances immediately, audit remote-management tool usage, and review driver-allowlisting to counter BYOVD.
A successor to the notorious Citrix Bleed vulnerability is already being weaponised by ransomware groups — unpatched gateways are an imminent breach risk.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Vulnerabilities Desk
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More20 Jul
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.20 Jul
- [NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere Schwachstellen20 Jul
- [NEU] [hoch] Grafana: Schwachstelle ermöglicht Manipulation von Dateien20 Jul
- [NEU] [hoch] IBM Langflow Desktop OSS: Mehrere Schwachstellen20 Jul