Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Anubis ransomware affiliates are chaining the new Citrix Bleed 2 flaw (CVE-2025-5777) with BYOVD and compromised supply-chain credentials — a converging-TTPs pattern that demands layered perimeter and endpoint defences.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.

"Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral

Editorial Analysis

Why it matters

Citrix NetScaler remains a prime gateway into European enterprises; a second Bleed variant actively exploited by ransomware affiliates demands immediate patching and network-segmentation review.

What to do

Patch CVE-2025-5777 on all Citrix NetScaler instances immediately, audit remote-management tool usage, and review driver-allowlisting to counter BYOVD.

Board brief

A successor to the notorious Citrix Bleed vulnerability is already being weaponised by ransomware groups — unpatched gateways are an imminent breach risk.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Vulnerabilities Desk