Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Citrix

Citrix Vendor Cyber Rating & Cyber Score

citrix.com

When we pioneered remote access, we believed people should be able to work anywhere and in any way they need. Three decades later, that’s even more true than ever. It’s what drives us to create technology that transcends the constraints of time, place, infrastructure, networks, and devices. And it’s the reason thousands of organizations around the world trust us to keep their apps available, their data safe, and their people productive—wherever and whenever work happens. Citrix is now part of Cloud Software Group. To see career and people content, visit Cloud Software Group's LinkedIn page: https://www.linkedin.com/company/cloudsoftwaregroup/


Citrix A.I CyberSecurity Scoring

Citrix
Company Information
Website:https://www.citrix.com/
Employees number:4,268
Number of followers:581,823
NAICS:5112
Industry Type:Software Development
Homepage:citrix.com
Citrix Risk Score (AI oriented)
Between 0 and 549
logo
CitrixSoftware Development
Updated:
19/06/2026
416/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Citrix Global Score (TPRM)
xxxx
logo
CitrixSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Citrix
CitrixCritical
Current Score
416C (CRITICAL)
01000
19 incidents
-31.83 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
412Before Incident
MAY 2026
411Before Incident
Vulnerability
16 May 2026Citrix
Citrix and BlackCat: MSN

Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability

407After Incident
CRITICAL-4
CITBLA1778977440
Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability A recent cyberattack has disrupted operations across multiple U.S. healthcare providers, with the ransomware group BlackCat (ALPHV) exploiting a previously unknown zero-day vulnerability in Citrix NetScaler ADC and Gateway systems. The flaw, tracked as CVE-2023-4966 (dubbed "Citrix Bleed"), allows attackers to bypass authentication and gain unauthorized access to sensitive networks. The attack, detected in late October 2023, targeted hospitals, clinics, and medical billing firms, leading to delayed patient care, system outages, and data exposure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the vulnerability’s active exploitation, warning that threat actors could steal session tokens to maintain persistent access even after patches are applied. BlackCat, known for its double-extortion tactics, has demanded ransoms ranging from $1 million to $10 million per victim. While some organizations have restored systems from backups, others remain locked out of critical infrastructure. The incident underscores the growing risk of zero-day exploits in healthcare, where legacy systems and high-value data make providers prime targets. Citrix released emergency patches on October 10, 2023, urging all users to update immediately. However, CISA’s advisory notes that compromised credentials may still pose a threat, requiring additional mitigation steps, including credential resets and network segmentation. The full scope of affected entities remains unclear, though reports indicate at least dozens of organizations have been impacted.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware), Data exfiltration
IMPACT
Data Compromised: Session tokens, sensitive healthcare dataSystems Affected: Citrix NetScaler ADC and Gateway systemsDowntime: Delayed patient care, system outagesOperational Impact: Disrupted healthcare operationsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Session tokens, sensitive healthcare dataSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Likely
APRIL 2026
405Before Incident
MARCH 2026
402Before Incident
Vulnerability
23 Mar 2026Citrix
Cloud Software Group: Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group

398After Incident
CRITICAL-4
CLO1774312166
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group Cloud Software Group has released emergency security updates for NetScaler ADC and NetScaler Gateway, addressing two high-severity vulnerabilities that could enable unauthenticated remote attacks on affected systems. The most critical flaw, CVE-2026-3055 (CVSS 9.3), is an out-of-bounds read vulnerability in SAML Identity Provider (IDP) configurations. Exploitable without authentication or user interaction, it allows attackers to trigger memory overreads, potentially leading to system compromise. The issue was discovered internally, with no evidence of active exploitation at the time of disclosure. Administrators can check for exposure by verifying SAML IDP configurations in NetScaler settings. The second vulnerability, CVE-2026-4368 (CVSS 7.7), involves a race condition causing session mixups in appliances configured as Gateways (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual servers. While exploitation requires low-privilege authentication and precise timing, successful attacks could fully compromise session confidentiality and integrity. Affected Versions & Patches: - CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and FIPS/NDcPP before 13.1-37.262. - CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54. Fixed releases include 14.1-66.59 or later, 13.1-62.23 or later, and 13.1-FIPS/NDcPP 13.1.37.262 or later. The patches apply only to customer-managed deployments, as Citrix-managed cloud services and Adaptive Authentication instances have already been updated. Given NetScaler’s widespread use in enterprise VPN and application delivery, unpatched systems pose a significant risk. Security teams are advised to prioritize updates, particularly for SAML IDP-configured appliances.
INCIDENT DETAILS -
TYPE
Vulnerability Disclosure
IMPACT
Systems Affected: NetScaler ADC and NetScaler Gateway appliancesOperational Impact: Potential system compromise, session confidentiality and integrity risks
FEBRUARY 2026
393Before Incident
Vulnerability
01 Feb 2026Citrix
Citrix: Threat Actors Conduct Widespread Scanning for Exposed Citrix NetScaler Login Pages

Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered

389After Incident
CRITICAL-4
CIT1770201552
Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered A sophisticated reconnaissance campaign targeting Citrix ADC (NetScaler) Gateway infrastructure has been detected, involving over 63,000 residential proxy IPs and AWS cloud instances to map login panels and enumerate software versions. The operation, which generated 111,834 scanning sessions, was highly targeted 79% of traffic focused on Citrix Gateway honeypots indicating deliberate pre-exploitation preparation rather than random scanning. The campaign unfolded in two phases: 1. Login Panel Discovery (Primary Phase) - 109,942 sessions from 63,189 unique IPs probed the `/logon/LogonPoint/index.html` authentication interface. - 64% of traffic originated from residential proxies across Vietnam, Argentina, Mexico, Algeria, and Iraq, while a single Microsoft Azure IP in Canada accounted for 36%. - Threat actors used unique browser fingerprints and residential proxies to evade geographic and reputation-based blocking. 2. Version Disclosure Sprint (AWS Phase) - On February 1, 2026, 10 AWS instances in us-west-1/us-west-2 executed a six-hour scan, sending 1,892 requests to `/epa/scripts/win/nsepa_setup.exe` to identify Citrix Endpoint Analysis (EPA) versions. - Activity peaked at 362 sessions around 02:00 UTC before tapering off by 05:00 UTC. - All requests used an outdated Chrome 50 user agent (2016) and uniform HTTP fingerprints, suggesting a coordinated effort to exploit known vulnerabilities. Researchers from GreyNoise noted the focus on the EPA setup file path indicates potential interest in version-specific exploits, particularly given recent critical Citrix vulnerabilities: - CVE-2025-5777 ("CitrixBleed 2") - CVE-2025-5775 (remote code execution, exploited as a zero-day). Detection and Indicators of Compromise (IOCs) - User agents: `blackbox-exporter` (unauthorized sources), Chrome 50 (2016) - Targeted paths: `/logon/LogonPoint/`, `/epa/scripts/win/nsepa_setup.exe` - AWS IPs (Version Disclosure): `44.251.121.190, 13.57.253.3, 50.18.232.85, 52.36.139.223, 54.201.20.56, 54.153.0.164, 54.176.178.13, 18.237.26.188, 54.219.42.163, 18.246.164.162` - Azure IP (Login Panel Discovery): `52.139.3.76` The campaign’s scale and precision suggest threat actors are actively preparing for potential exploitation, likely targeting unpatched or misconfigured Citrix ADC deployments.
INCIDENT DETAILS -
TYPE
Reconnaissance
MOTIVATION
Pre-exploitation preparation
IMPACT
Systems Affected: Citrix ADC (NetScaler) Gateway infrastructure
JANUARY 2026
393Before Incident
DECEMBER 2025
379Before Incident
NOVEMBER 2025
372Before Incident
Vulnerability
01 Nov 2025Citrix
Citrix and VMware: Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware

Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft

368After Incident
CRITICAL-4
CITVMW1776702564
Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft Cybercriminals are increasingly abusing QEMU, a legitimate open-source virtualization tool, to bypass endpoint security and deploy ransomware or steal credentials undetected. By running malicious operations inside hidden virtual machines (VMs), attackers exploit a critical blind spot security tools on the host system cannot inspect activity within the VM, leaving minimal forensic traces. Sophos researchers have identified two active campaigns leveraging this technique since late 2025: 1. STAC4713 (November 2025) – Linked to the PayoutsKing ransomware group (GOLD ENCOUNTER), which operates independently (not as a ransomware-as-a-service). The group targets VMware and ESXi hypervisors, using QEMU to execute attacks. The infection chain begins with a scheduled task ("TPMProfiler") running QEMU under the SYSTEM account, booting from a disguised virtual disk (initially vault.db, later bisrv.dll). The VM establishes a reverse SSH tunnel via custom ports (32567, 22022) to port 22, creating a persistent backdoor. Tools inside the VM include AdaptixC2, Linker2, and a WireGuard obfuscator (wg-obfuscator). 2. STAC3725 (February 2026) – Exploits the CitrixBleed2 vulnerability (CVE-2025-5777) for initial access, then deploys a malicious ScreenConnect client for persistence. Attackers manually compile a toolkit inside the QEMU VM, including Impacket, KrbRelayX, BloodHound.py, NetExec, and Metasploit, to harvest credentials, enumerate Active Directory, and stage payloads via FTP. Both campaigns demonstrate a growing trend of virtualization-based evasion, where trusted tools like QEMU are repurposed to conceal malicious activity. The technique’s stealth and lack of detectable artifacts make it particularly challenging for defenders to identify and mitigate in real time.
INCIDENT DETAILS -
TYPE
ransomwarecredential theft
MOTIVATION
financial gaincredential harvesting
IMPACT
credentialsActive Directory enumeration dataVMware and ESXi hypervisorsWindows systems with QEMUIdentity Theft Risk: high
DATA BREACH
credentialsActive Directory dataSensitivity Of Data: highData Encryption: yes (ransomware)
OCTOBER 2025
540Before Incident
Breach
19 Oct 2025Citrix
F5

Oracle E-Business Suite Remotely Exploitable Vulnerability (CVE-2025-61884)Microsoft Zero-Day Exploits (CVE-2025-24990, CVE-2025-59230, CVE-2025-47827)F5 Data Breach: Nation-State Attackers Stole BIG-IP Source CodeAdobe Experience Manager 'Perfect' Vulnerability (CVE-2025-54253)Microsoft Revokes 200 Certificates Used for Malicious Teams Installers (Vanilla Tempest Ransomware)Cisco Zero-Day Rootkit Deployment on Network Switches (CVE-2025-20352)U.S. Seizes $15B in Bitcoin Linked to Forced-Labor Crypto ScamUnitree G1 Humanoid Robot Bluetooth Vulnerability (Espionage Risk)Healthcare Cybersecurity Breakdown: 93% of U.S. Organizations Attacked (Patient Care Disruptions)

369After Incident
CRITICAL-171
F50032500101925
US tech company F5 confirmed a data breach in which nation-state attackers stole the source code and vulnerability information related to its BIG-IP family of networking and security products. BIG-IP is a critical infrastructure component used by enterprises for traffic management, load balancing, and security, making this breach particularly severe. The stolen data could enable adversaries to identify and exploit undiscovered flaws in BIG-IP systems, potentially leading to supply-chain attacks, unauthorized network access, or large-scale disruptions in organizations relying on F5’s solutions. The breach underscores the escalating risks of state-sponsored cyber espionage targeting foundational IT infrastructure, with implications for global cybersecurity resilience. F5 has not disclosed whether customer data was compromised, but the theft of proprietary code and vulnerability details poses a long-term threat to its product ecosystem and the broader digital supply chain.
INCIDENT DETAILS -
TYPE
VulnerabilityZero-Day ExploitsData BreachVulnerabilityMalware Distribution (Ransomware)Zero-Day Exploit (Rootkit)Cryptocurrency FraudHardware Vulnerability (Espionage)Cyberattack Campaign (Healthcare)
MOTIVATION
Cyber Espionage (Source Code Theft)Financial Gain (Ransomware)Financial Gain (Crypto Fraud)Espionage/Data Theft
IMPACT
$15 billion (Seized)BIG-IP Source Code & Vulnerability InfoRobot Sensor/Data LeaksOracle E-Business SuiteMicrosoft Products (Multiple)F5 BIG-IP Networking/Security ProductsAdobe Experience Manager (JEE)Microsoft Teams (Malicious Installers)Cisco Network Switches (IOS/IOS XE)Cryptocurrency Wallets/ExchangesUnitree G1 Humanoid RobotsPatient Care Disruptions (72% of Incidents)Source Code Integrity RiskMalware Distribution InfrastructureNetwork Compromise (Rootkits)Fraud Operation ShutdownEspionage Risk (China-Linked)High (Healthcare)High (F5)High (Microsoft)High (Cisco)Severe (Crypto Scam)High (Unitree/Alias Robotics)Severe (Healthcare Sector)Criminal Charges (Forced Labor)HIPAA/Regulatory ViolationsHigh (Patient Data)High
DATA BREACH
Source Code & Vulnerability DetailsRobot Sensor DataHigh (Proprietary Code)High (Espionage Risk)High (PHI/PII)Yes (Source Code)Yes (China-Linked)Likely (Ransomware)Yes (Patient Data)
SEPTEMBER 2025
537Before Incident
AUGUST 2025
535Before Incident
Vulnerability
26 Aug 2025Citrix
Citrix (Cloud Software Group)

Critical Remote Code Execution Flaw (CVE-2025-7775) in Citrix NetScaler ADC and Gateway

531After Incident
CRITICAL-4
CIT806082725
Citrix disclosed a critical zero-day vulnerability (CVE-2025-7775) in its NetScaler ADC and NetScaler Gateway products, actively exploited in the wild as of August 26, 2025. The flaw—a memory overflow bug—enables unauthenticated remote code execution (RCE) on unpatched devices, posing severe risks to organizations relying on these appliances for secure access. While Citrix did not provide indicators of compromise (IoCs), they confirmed exploitation on systems configured as Gateway (VPN, ICA Proxy, RDP Proxy), AAA virtual servers, or specific load-balancing (LB) setups with IPv6 bindings. No mitigations exist, forcing immediate patching to versions 14.1-47.48, 13.1-59.22, or later.The vulnerability’s exploitation could allow attackers to gain full control over affected systems, potentially leading to lateral movement, data exfiltration, or deployment of malware/ransomware. Citrix also patched two other flaws: a DoS vulnerability (CVE-2025-7776) and an improper access control issue (CVE-2025-8424), further compounding risks. Historical context—such as the prior Citrix Bleed 2 (CVE-2025-5777) exploit—highlights the company’s recurring exposure to high-severity attacks targeting memory corruption. Failure to patch could result in widespread breaches, operational disruptions, or supply-chain attacks given NetScaler’s role in enterprise networks.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationZero-Day AttackRemote Code Execution (RCE)Denial of Service (DoS)Improper Access Control
IMPACT
NetScaler ADC (versions 12.1, 13.1, 14.1)NetScaler Gateway (versions 13.1, 14.1)NetScaler ADC 13.1-FIPS and NDcPPNetScaler ADC 12.1-FIPS and NDcPPPotential unauthorized remote code executionDenial of Service (DoS) risksUnauthorized access to management interfacesPotential reputational damage due to zero-day exploitation
JULY 2025
530Before Incident
JUNE 2025
527Before Incident
Vulnerability
16 Jun 2025Citrix
Citrix

Exploitation of Citrix Vulnerabilities via HexStrike-AI Red Teaming Tool

522After Incident
CRITICAL-5
CIT1555015090425
Cybercriminals are leveraging HexStrike-AI, a legitimate red teaming tool, to automate exploits against Citrix NetScaler ADC and Gateway using recently disclosed vulnerabilities (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424). The tool enables unauthenticated remote code execution (RCE), allowing attackers to deploy webshells and maintain persistent access. While no confirmed breaches are reported yet, the exploitation window has shrunk from days to minutes, drastically reducing the time administrators have to patch systems. The CVE-2025-7775 flaw is already being exploited in the wild, and the use of HexStrike-AI is expected to escalate attack volumes, increasing the risk of unauthorized system takeovers, data exposure, or operational disruptions for organizations relying on Citrix infrastructure. The automation capability of the tool makes manual patch management nearly impossible without dedicated platforms, heightening the urgency for immediate mitigation.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationAutomated AttackUnauthorized Access
MOTIVATION
Financial GainUnauthorized AccessPersistenceData Theft
IMPACT
Citrix NetScaler ADCCitrix NetScaler GatewayReduced Patching WindowIncreased Attack VolumeAutomated ExploitationPotential Reputation Damage for CitrixTrust Erosion in Patch Management
MAY 2025
537Before Incident
Cyber Attack
01 May 2025Citrix
Citrix

Sophisticated Cyberattacks Targeting Critical Infrastructure via Citrix NetScaler Zero-Day Vulnerability

519After Incident
CRITICAL-18
CIT211081225
The Dutch National Cyber Security Centre (NCSC-NL) has issued an urgent warning about sophisticated cyberattacks targeting critical infrastructure through a zero-day vulnerability in Citrix NetScaler devices. The vulnerability, designated CVE-2025-6543, has been actively exploited since early May 2025, compromising several critical organizations across the Netherlands. Attackers gained access to perimeter defenses, demonstrating advanced capabilities by erasing forensic traces and deploying malicious web shells for persistent remote access. The exploitation involved placing suspicious PHP files in system directories, making detection and remediation challenging. The NCSC emphasizes that patching alone is insufficient, as compromised systems may retain attacker access, requiring comprehensive forensic investigation.
INCIDENT DETAILS -
TYPE
Zero-day exploitation
IMPACT
Systems Affected: Citrix NetScaler ADC and Gateway systemsOperational Impact: Significant security breach, access to perimeter defenses
FEBRUARY 2025
586Before Incident
Breach
01 Feb 2025Citrix
Anthropic: Anthropic leaks its own AI coding tool’s source code in second major security breach

Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems

522After Incident
CRITICAL-64
ANT1774981746
Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems Anthropic has inadvertently leaked the source code for Claude Code, its widely adopted AI-powered coding assistant, exposing roughly 500,000 lines of code across 1,900 files. The incident, confirmed by the company as a "release packaging issue" caused by human error, occurred when internal code was mistakenly uploaded to NPM a platform for software distribution instead of the final, compiled version. The leak follows a separate accidental disclosure earlier this month, in which a draft blog post revealed details about Mythos (also referred to as Capybara), an upcoming AI model described as more powerful and potentially more dangerous than Anthropic’s current flagship, Opus. While the latest breach did not expose model weights or customer data, cybersecurity experts warn it could allow competitors to reverse-engineer Claude Code’s underlying "agentic harness" the software layer that governs the AI’s behavior, tool integration, and safety guardrails. This could enable the creation of open-source alternatives or help rivals refine their own AI systems. Security researcher Roy Paz of LayerX Security noted that the leaked code also provided further evidence of Capybara, Anthropic’s next-generation model, which is expected to surpass Opus in capability and cost. The draft blog post previously described it as a new tier, with "fast" and "slow" variants likely replacing Opus as the company’s most advanced offering. Paz highlighted concerns that the exposed code may reveal vulnerabilities in how Claude Code interacts with Anthropic’s internal systems, potentially allowing malicious actors including nation-states to exploit the AI for cyberattacks or bypass existing safeguards. Anthropic’s Opus model is already classified as a high-risk tool due to its ability to autonomously identify zero-day vulnerabilities, a capability that could be weaponized by threat actors. This is not the first time the company has faced such an exposure; in February 2025, an early version of Claude Code was similarly leaked, revealing internal workings and system connections before being removed. The company has stated it is implementing measures to prevent future incidents but has not disclosed further details. The leak underscores the challenges of securing proprietary AI systems as adoption and scrutiny of advanced models continues to grow.
INCIDENT DETAILS -
TYPE
Data Leak
IMPACT
Data Compromised: 500,000 lines of source code across 1,900 filesSystems Affected: Claude Code AI-powered coding assistant, internal AI systemsOperational Impact: Potential reverse-engineering of AI systems by competitors or malicious actorsBrand Reputation Impact: Yes
DATA BREACH
Type Of Data Compromised: Source code, internal AI system detailsNumber Of Records Exposed: 1,900 filesSensitivity Of Data: High (proprietary AI code, agentic harness, internal system connections)File Types Exposed: Source code filesPersonally Identifiable Information: No
JANUARY 2025
591Before Incident
Vulnerability
01 Jan 2025Citrix
F5, Lloyds Banking Group, Citrix, Dutch Ministry of Finance and European Commission: Lloyds Banking Group - Security Affairs

Cybersecurity Roundup: Major Incidents and Emerging Threats

582After Incident
CRITICAL-9
EURF5LLOCITMIN1774989406
Cybersecurity Roundup: Major Incidents and Emerging Threats Recent weeks have seen a surge in high-profile cybersecurity incidents, vulnerabilities, and state-linked attacks targeting governments, financial institutions, and critical infrastructure. Financial Sector Breaches Lloyds Banking Group confirmed a security incident affecting nearly 500,000 mobile customers, though details on the nature of the breach remain undisclosed. Meanwhile, the Dutch Ministry of Finance took treasury systems offline following a cyber incident under investigation. Critical Vulnerabilities Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw (CVE-2026-3055) to its Known Exploited Vulnerabilities catalog after reports of active exploitation, with attackers probing the bug for potential data leaks. CISA also flagged a critical F5 BIG-IP AMP vulnerability under active attack. Additionally, security agencies warned of a severe flaw in PTC Windchill and FlexPLM, urging organizations to apply patches immediately. State-Sponsored Threats Russia-linked APT TA446 deployed the DarkSword exploit in a phishing campaign targeting iPhone users. China-associated groups launched advanced malware attacks against a Southeast Asian government in early 2025. Meanwhile, an Iran-linked group, Handala, compromised the personal email account of FBI Director Kash Patel, marking a significant escalation in espionage efforts. Ransomware and Supply Chain Attacks The Qilin ransomware group claimed responsibility for breaching Dow Inc., a major chemical manufacturer. Attackers also hijacked the Axios npm account, using it to distribute remote access trojan (RAT) malware to unsuspecting developers. In a separate incident, ShinyHunters asserted responsibility for hacking the European Commission, though the full impact remains unclear. Emerging Threats Apple issued urgent lock screen warnings for unpatched iPhones and iPads, highlighting ongoing risks to mobile security. A new macOS malware, Infinity Stealer, was discovered leveraging Nuitka Python payloads and ClickFix techniques to evade detection. Additionally, a new adversary-in-the-middle (AITM) phishing wave targeted TikTok Business accounts, demonstrating evolving social engineering tactics. Government and Institutional Targets The European Commission confirmed a cyberattack affecting part of its cloud infrastructure, though specifics on the attack vector and scope were not disclosed. These incidents underscore the persistent and evolving nature of cyber threats across sectors.
INCIDENT DETAILS -
TYPE
data_breachransomwarephishingmalwaresupply_chain_attackstate-sponsored_attack
MOTIVATION
espionagefinancial_gaindata_exfiltrationdisruption
IMPACT
mobile banking systemstreasury systemscloud infrastructurenpm accountiPhone devicesmacOS systemssystems taken offlinedisrupted services
Vulnerability
01 Jan 2025Citrix
Citrix and F5: Vulnerability affecting F5 BIG-IP APM

Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations

582After Incident
CRITICAL-9
F5CIT1774873786
Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations The UK’s National Cyber Security Centre (NCSC) has issued urgent guidance for organizations to mitigate active exploitation of severe vulnerabilities in F5 BIG-IP Access Policy Manager (APM) and Citrix NetScaler ADC/Gateway. Both flaws enable unauthenticated remote code execution (RCE), posing significant risks to enterprise networks. ### F5 BIG-IP APM (CVE-2025-53521) - Impact: Affects all organizations using BIG-IP APM, particularly large enterprises. Exploitation occurs when a malicious actor sends crafted traffic to a virtual server configured with an APM access policy. - Active Exploitation: F5 has confirmed in-the-wild attacks targeting this vulnerability. - Recommended Actions: - Isolate affected systems immediately to prevent further compromise. - Update to the latest patched version or rebuild systems from scratch if updates are not feasible. - Investigate for compromise, even if systems were recently updated, as exploitation may have occurred prior to patching. - Report incidents to F5 and UK authorities if a breach is suspected. ### Citrix NetScaler ADC/Gateway Vulnerabilities - Impact: Two recently disclosed flaws in Citrix NetScaler products could allow attackers to execute arbitrary code without authentication. - Recommended Actions: - Apply vendor patches without delay. - Monitor for signs of compromise, including unusual network activity or unauthorized access. - Consider engaging an assured Cyber Incident Response provider for forensic analysis if exploitation is suspected. ### Broader Context & NCSC Support The NCSC is actively assessing the UK impact of these vulnerabilities and collaborating with industry partners to track exploitation. Organizations are advised to: - Enable continuous threat hunting to detect post-exploitation activity. - Follow NCSC’s hardening guidance to reduce attack surfaces. - Leverage the NCSC Early Warning service for real-time threat notifications. Both F5 BIG-IP APM and Citrix NetScaler are widely deployed in critical infrastructure, making these vulnerabilities high-priority targets for threat actors. Immediate remediation is essential to prevent potential breaches.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Enterprise networks, critical infrastructureOperational Impact: Potential unauthorized access, arbitrary code execution
DECEMBER 2023
591Before Incident
Breach
01 Dec 2023Citrix
Comcast

Xfinity by Comcast Data Breach

534After Incident
HIGH-57
COM152251223
Xfinity by Comcast reports a data breach following a cyberattack that took use of the CitrixBleed vulnerability. By taking use of this vulnerability, threat actors were able to take over active authenticated connections and get around multifactor authentication and other stringent authentication regulations. The security company Mandiant saw threat actors taking control of sessions in which the threat actor used session data that had been taken prior to the patch being deployed. The business discovered that hashed passwords and usernames are among the different client data that is exposed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Hashed passwordsUsernames
DATA BREACH
Hashed passwordsUsernames
OCTOBER 2023
589Before Incident
Vulnerability
16 Oct 2023Citrix
Comcast Cable Communications

Xfinity Data Breach via Citrix Software Vulnerability

585After Incident
CRITICAL-4
COM020090625
The Vermont Office of the Attorney General disclosed that Xfinity suffered a data breach stemming from a vulnerability in Citrix’s software, enabling unauthorized access between October 16–19, 2023. The exposed data included usernames, hashed passwords, full names, contact details, the last four digits of Social Security numbers, dates of birth, and secret questions/answers. While the breach did not involve full Social Security numbers or financial data, the compromised credentials and personal identifiers pose significant risks, including identity theft, phishing attacks, and account takeovers. The incident was publicly reported on December 18, 2023, highlighting delays in detection and disclosure. The breach’s scope suggests potential long-term reputational damage and regulatory scrutiny, particularly given the sensitivity of the leaked information and the scale of Xfinity’s customer base.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
usernameshashed passwordsnamescontact informationlast four digits of Social Security numbersdates of birthsecret questions and answersIdentity Theft Risk: High (PII exposed)
DATA BREACH
Personally Identifiable Information (PII)Authentication CredentialsSensitivity Of Data: HighData Exfiltration: Likely (unauthorized access confirmed)Data Encryption: Partially (hashed passwords)
JULY 2023
579Before Incident
Vulnerability
01 Jul 2023Citrix
Fortinet, Veeam and Citrix: INC Ransomware Uses LOLBins, RMM Tools, and rclone for Network Intrusion and Data Exfiltration

INC Ransomware Attack

575After Incident
CRITICAL-4
VEEFORCIT1781857680
INC Ransomware: A Rapidly Evolving Threat Targeting Global Organizations Since its emergence in mid-2023, the INC ransomware group has established itself as a formidable Ransomware-as-a-Service (RaaS) operation, claiming over 800 victims worldwide. The group employs aggressive double-extortion tactics, targeting high-profile organizations primarily in the U.S., with a focus on the legal, manufacturing, technology, and healthcare sectors. INC’s attack methods are both diverse and sophisticated. Initial access is often gained through spear-phishing, compromised credentials from access brokers, or exploitation of known vulnerabilities in public-facing systems, including Citrix NetScaler (CVE-2023-3519), Fortinet EMS (CVE-2023-48788), and Citrix Bleed 2 (CVE-2025-5777). Once inside, attackers use command-line tools and IP scanners to map the network before deploying a customized PowerShell script that extracts credentials from Veeam backup servers via salted DPAPI decryption. The group’s ransomware payloads, rewritten in Rust, enable cross-platform attacks on both Windows and Linux/ESXi environments. On Windows, the malware employs multithreading and partial encryption to accelerate data destruction while avoiding critical system files ensuring victims can still view ransom notes on desktops and network printers. On Linux and VMware ESXi servers, the payload shuts down virtual machines before encrypting them, maximizing disruption. INC’s encryption scheme combines Curve25519 Elliptic Curve Cryptography and AES-128, making recovery without the decryption key nearly impossible. The group operates a dual-site extortion model, using a private portal for negotiations and a public leak site to pressure non-compliant victims. Their rapid evolution and technical sophistication underscore the growing threat posed by modern ransomware operations.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (Ransomware-as-a-Service)
IMPACT
Data Compromised: Credentials, backup data, virtual machines, and sensitive filesWindowsLinux/ESXi environmentsOperational Impact: Shutdown of virtual machines, encryption of critical data, disruption of servicesBrand Reputation Impact: High (due to public leak site and double-extortion tactics)Identity Theft Risk: High (if personally identifiable information was compromised)
DATA BREACH
CredentialsBackup dataVirtual machine dataSensitive filesSensitivity Of Data: High (credentials, PII potential)Data Exfiltration: Yes (double-extortion tactic)Data Encryption: Yes (Curve25519 ECC and AES-128)
JUNE 2023
582Before Incident
Vulnerability
16 Jun 2023Citrix
Citrix

Critical Flaw in Citrix NetScaler Devices Echoes Infamous 2023 Security Breach

578After Incident
CRITICAL-4
CIT748070725
Citrix is facing a critical flaw in its NetScaler devices, known as 'CitrixBleed 2' (CVE-2025-5777), which allows attackers to steal sensitive information from device memory. This vulnerability, similar to the 2023 CitrixBleed attacks, has a CVSS severity score of 9.3 and has already been exploited in targeted attacks. The exploitation involves bypassing multi-factor authentication and hijacking user sessions, with evidence of session reuse and Active Directory reconnaissance. The vulnerability affects NetScaler ADC and NetScaler Gateway devices, potentially exposing session tokens and other sensitive data. Security experts urge immediate patching to prevent widespread exploitation, as the original CitrixBleed attacks continued to be exploited for months.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Data Theft, Session Hijacking
IMPACT
Session tokensSensitive informationNetScaler ADCNetScaler Gateway
DATA BREACH
Type Of Data Compromised: Session tokens, Sensitive informationSensitivity Of Data: High
JANUARY 2023
731Before Incident
Breach
01 Jan 2023Citrix
Comcast: Comcast’s $117.5M Data Breach Deal Nears Finish Line

Comcast 2023 Data Breach Settlement

560After Incident
CRITICAL-171
COM1769288328
Comcast Nears $117.5M Settlement Over 2023 Data Breach Affecting 30M Customers A federal judge in Pennsylvania’s Eastern District has granted preliminary approval for a $117.5 million settlement in a class-action lawsuit against Comcast, stemming from a 2023 cyber intrusion that potentially exposed sensitive data of over 30 million current and former customers. If finalized, the agreement would resolve two dozen lawsuits filed against the telecommunications giant. Affected customers would receive one of two remedies: - Three years of financial monitoring and identity theft protection, or - A choice between reimbursement for documented losses up to $10,000 or a $50 cash payment. The settlement structure allows for proof-based compensation for those who can demonstrate harm, while others may opt for a flat payout. Comcast, while not opposing the settlement, has denied liability for the breach, disputing the plaintiffs’ claims in court filings. The company has not commented publicly on the matter. The final court review will determine whether the agreement is approved.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $117.5M settlementData Compromised: Sensitive customer dataLegal Liabilities: Class-action lawsuitsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Sensitive customer dataNumber Of Records Exposed: 30 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
MAY 2019
676Before Incident
Cyber Attack
01 May 2019Citrix
Citrix

Citrix Server Breach

658After Incident
CRITICAL-18
CIT11910222
An international cybercriminals gang had accessed Citrix servers for about six months. The hackers were able to steal business documents, names, social security numbers, and financial information. The company notified all the impacted customers and secured their servers from any such future attack.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
business documentsnamessocial security numbersfinancial informationCitrix Servers
DATA BREACH
business documentsnamessocial security numbersfinancial informationSensitivity Of Data: Highnamessocial security numbers
MARCH 2019
729Before Incident
Breach
01 Mar 2019Citrix
Citrix

Citrix Security Breach

672After Incident
CRITICAL-57
CIT907323
American software company Citrix disclosed that they have been hit by a security breach during which hackers accessed the company's internal network. It was found that hackers accessed and downloaded business documents, but Citrix wasn't able to identify what specific documents had been stolen. According to the Citrix executive, there is no proof that hackers may have tampered with Citrix's official software or other goods.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
business documents
DATA BREACH
business documents
OCTOBER 2018
778Before Incident
Breach
13 Oct 2018Citrix
Citrix Systems, Inc.

Data Breach at Citrix Systems, Inc.

724After Incident
HIGH-54
CIT258072625
The California Office of the Attorney General reported a data breach involving Citrix Systems, Inc. on April 29, 2019. The breach occurred between October 13, 2018, and March 8, 2019, potentially affecting personal information of current and former employees, including names, Social Security numbers, and financial information. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security numbersfinancial information
DATA BREACH
namesSocial Security numbersfinancial informationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Citrix ?
?
What was Citrix's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Citrix's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Citrix ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Citrix's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?