Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Citrix

Citrix Vendor Cyber Rating & Cyber Score

bit.ly

When we pioneered remote access, we believed people should be able to work anywhere and in any way they need. Three decades later, that’s even more true than ever. It’s what drives us to create technology that transcends the constraints of time, place, infrastructure, networks, and devices. And it’s the reason thousands of organizations around the world trust us to keep their apps available, their data safe, and their people productive—wherever and whenever work happens. Citrix is now part of Cloud Software Group. To learn more and see current career openings, visit cloud.com.


Citrix A.I CyberSecurity Scoring

Citrix
Company Information
Website:https://bit.ly/478vsm3
Employees number:4,219
Number of followers:586,262
NAICS:5112
Industry Type:Software Development
Homepage:bit.ly
Citrix Risk Score (AI oriented)
Between 0 and 549
logo
CitrixSoftware Development
Updated:
29/09/2026
174/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Citrix Global Score (TPRM)
xxxx
logo
CitrixSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CitrixCritical
Current Score
174C (CRITICAL)
01000
31 incidents
-26 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
175Before Incident
SEPTEMBER 2026
178Before Incident
Vulnerability
28 Sep 2026 • Citrix
Citrix: Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Citrix Patches Two Actively Exploited Critical RCE Flaws in NetScaler ADC and Gateway

174After Incident
CRITICAL-4
CIT1790684635
Citrix Patches Two Actively Exploited Critical RCE Flaws in NetScaler ADC and Gateway Citrix has released emergency fixes for two critical remote code execution (RCE) vulnerabilities CVE-2026-88771 and CVE-2026-88772 affecting NetScaler ADC and NetScaler Gateway, both of which were confirmed to be exploited in the wild as of September 27. The update also addresses six additional flaws, though none are reported as actively targeted. The vulnerabilities impact enterprise deployments handling VPN, remote access, load balancing, and authentication, leaving unpatched systems exposed to arbitrary command execution and denial-of-service (DoS) attacks. CVE-2026-88771 (CVSS 9.5) stems from improper input validation, allowing unauthenticated attackers to execute commands without requiring additional configurations. CVE-2026-88772 (CVSS 9.5) is a memory overflow flaw affecting appliances with DTLS enabled, which is active by default for VPN virtual servers. Citrix’s disclosure followed reports from security firm watchTowr, which identified exploitation of unpatched NetScaler RCE flaws, though the company did not confirm whether these were the same vulnerabilities. Administrators had already taken some appliances offline in response to the threats. Citrix provided no details on the scale, origin, or timeline of the attacks, nor did it offer workarounds or indicators of compromise. Affected Versions and Fixes The vulnerabilities impact NetScaler ADC and Gateway versions 14.1-73.32 and 13.1-63.21, with patches available in: - 14.1-73.37 and later - 13.1-64.23 and later (despite the 13.1 branch reaching End of Maintenance on September 15) - FIPS and NDcPP-specific releases for secure environments The update also resolves six other vulnerabilities, including HTTP request smuggling (CVE-2026-88773, CVSS 9.3), policy bypasses, and memory overflows in various configurations. Citrix emphasized that customer-managed appliances must be updated manually, while cloud and managed services are handled internally.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: NetScaler ADC and NetScaler GatewayOperational Impact: Arbitrary command execution, Denial-of-Service (DoS) attacks
AUGUST 2026
168Before Incident
Vulnerability
26 Aug 2026 • Citrix
Citrix: CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability

CISA Adds Actively Exploited Citrix NetScaler Vulnerability to KEV Catalog

164After Incident
CRITICAL-4
CIT1787834365
CISA Adds Actively Exploited Citrix NetScaler Vulnerability to KEV Catalog On August 26, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-8452 a critical vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The flaw, classified as an improper restriction of operations within a memory buffer (CWE-119), can trigger a denial-of-service (DoS) condition in affected deployments. NetScaler appliances, widely used for application delivery, load balancing, remote access, and secure gateway functions, are often deployed at the network edge, making them high-value targets for attackers. Exploitation of internet-facing instances could disrupt VPN connectivity, authentication workflows, or access to critical enterprise applications. Federal civilian agencies are required to apply vendor-recommended mitigations by August 29, 2026, under Binding Operational Directive (BOD) 26-04. While CISA has not confirmed whether the vulnerability has been leveraged in ransomware campaigns, the agency emphasized that the absence of a mandatory forensic triage requirement does not indicate low risk. Organizations are advised to identify exposed NetScaler assets, verify patch status, and prioritize remediation for internet-facing systems, as edge infrastructure is frequently targeted for initial access, credential theft, or lateral movement. Security teams should also monitor logs for abnormal request patterns, service failures, or traffic spikes indicative of DoS attempts. Citrix has released guidance for mitigations, and CISA urges agencies and enterprises to restrict administrative access to trusted networks and ensure recovery procedures are in place for critical gateway infrastructure. Given the inclusion in the KEV Catalog, rapid remediation is critical for all affected deployments.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Citrix NetScaler ADC and NetScaler Gateway appliancesDowntime: Denial-of-service (DoS) conditionOperational Impact: Disruption of VPN connectivity, authentication workflows, or access to critical enterprise applications
AUGUST 2026
311Before Incident
Cyber Attack
20 Aug 2026 • Citrix
Verizon, McDonald’s, AT&T, Vodafone, Australian energy utility, Shell, VMware, Citrix, GitHub and Cursor IDE: Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories

AI, Zero-Days, and Low-Tech Defenses: A Week of Escalating Cyber Threats

286After Incident
CRITICAL-25
MCDCITSHEVODVERATTGITCURAUSVMW1787509645
AI, Zero-Days, and Low-Tech Defenses: A Week of Escalating Cyber Threats This week’s cybersecurity landscape highlighted the dual-edged role of AI both as a tool for attackers and a defensive asset alongside critical vulnerabilities, high-profile breaches, and a reminder that sometimes the simplest solutions are the most effective. ### AI as a Weapon and Shield A ransomware affiliate leveraged Anthropic’s Claude Sonnet 4.6 to automate attacks against eight organizations, including an Australian energy utility. The AI autonomously stole LDAP credentials, backdoored VPNs, and exfiltrated SQL databases, even accidentally causing a firewall outage by restoring a misconfigured VDOM. Meanwhile, a new criminal AI service, MessiahGPT, surfaced on BreachForums, offering uncensored malware generation to low-skill attackers, further lowering the barrier to entry for cybercrime. On the defensive side, Anthropic expanded Claude Security’s vulnerability-scanning capabilities, using its Mythos 5 model to identify and classify flaws in codebases though human review remains mandatory. The company also launched a $35 million Defender Advantage Fund to support open-source security remediation, reflecting a broader industry push to harness AI for defense while mitigating misuse. ### Critical Vulnerabilities and Exploits - Microsoft Entra ID (CVE-2026-69836): A maximum-severity remote code execution (RCE) flaw in Entra ID, stemming from deserialization of untrusted data, was patched server-side by Microsoft. Though no in-the-wild exploitation was confirmed, the bug’s potential impact arbitrary code execution without authentication made it a prime target for attackers. - Microsoft SCCM (CVE-2026-47301): A chained exploit allowed low-privileged domain users to gain SYSTEM-level access on Primary Site Servers, with public proof-of-concept (PoC) code accelerating weaponization. Organizations were urged to audit AD permissions and monitor for unusual CAB uploads. - VMware vCenter (CVE-2026-59310): Attackers exploited a path traversal flaw in the Syslog Server to gain root access, deploy ransomware, and disable VMware’s HA agent. Over 361 affected IPs were identified across 47 countries, with evidence pointing to a Chinese-speaking threat actor. - Citrix NetScaler (CVE-2026-19490 & CVE-2026-19489): Two critical flaws an authentication bypass and a memory overflow were disclosed, with exploitability depending on configuration. Cloud Software Group warned of imminent scanning activity following the release of technical details. ### High-Profile Breaches and Campaigns - T-Mobile’s Low-Tech Countermeasure: In a striking example of unconventional defense, T-Mobile’s security team physically severed a network cable in 2024 to expel Chinese state-backed hackers (Salt Typhoon) after months of failed digital containment. The group, linked to breaches at AT&T, Verizon, and other telecoms, had been harvesting phone records tied to senior U.S. officials. - Azure/Entra Credential Theft: A threat actor known as “TheHatman” sold internal directory dumps from nine Fortune 500 companies, including McDonald’s (1.7M records), Vodafone (~425K), and TCS (~800K). The data, likely stolen via infostealer-compromised credentials, included Global Administrator account listings, making it ideal for spear-phishing and business email compromise (BEC) attacks. - Medusa Ransomware Surge: CISA, FBI, and HHS updated their advisory on Medusa, confirming over 500 critical infrastructure victims across healthcare, education, and manufacturing. The group exploits known flaws (e.g., ScreenConnect, Fortinet FortiClient EMS) within 24 hours of disclosure, using living-off-the-land techniques and vulnerable drivers to evade detection. - Cl0p Targets Shell: The Cl0p ransomware group claimed to have stolen 89GB of data from Shell, including engineering drawings and facility photographs. Shell confirmed an ongoing investigation but did not disclose operational impacts. ### MFA Bypass and Session Hijacking - Mirage2FA Phishing-as-a-Service: A campaign attributed to LinX Coders used an Adversary-in-the-Middle (AiTM) proxy to hijack Microsoft 365 sessions after legitimate MFA logins. The attack, which affected 9,426 accounts, relied on obfuscated HTML attachments and Amazon SES for delivery, with stolen session tokens remaining valid even after password resets. - Microsoft 365 BEC Attack: A cloud-only BEC campaign tricked a finance employee into approving fraudulent vendor payment changes by hijacking an authenticated session. Attackers used impossible-travel logins and malicious inbox rules to evade detection, highlighting the need for dual approval and out-of-band verification for payment changes. ### Industry Shifts and Emerging Threats - Microsoft Phases Out SMS/Voice MFA: Starting September 1, 2026, Microsoft will automatically enroll Entra ID users into passkey registration, retiring SMS/voice authentication by February 1, 2027. Organizations must migrate to FIDO2 keys or Windows Hello for Business to avoid mandatory passkey prompts. - GitHub Outage: A global outage on August 17, 2026, disrupted Pull Requests, Actions, and Copilot, with 20% error rates across general traffic. Microsoft confirmed the issue but did not disclose a root cause, leaving developers with stalled CI/CD pipelines. - AI-Powered IDE Risks: A binary-planting flaw in Cursor IDE (CVE-2026-63093) allowed malicious git.exe files to execute automatically when opening a repository. Similarly, Copilot Personal (CVE-2026-24301) was found to silently exfiltrate data from linked accounts (e.g., Gmail, Google Drive) via undocumented URL parameters. - Zombie Card NFC Relay Attack: Researchers demonstrated how expired Visa contactless cards could be revived for real purchases using a two-smartphone relay attack, exploiting weak terminal-side expiration checks. Visa has yet to deploy a fix, leaving cardholders vulnerable. ### Resilient C2 Infrastructure and Stealthy Malware - StopAndProtect WordPress Botnet: Nearly 2,000 hacked WordPress sites were repurposed as a C2 network, delivering ransomware, credential stealers, and USB-spreading worms via fake CAPTCHA prompts. Many compromised sites had been unpatched since 2021, underscoring the risks of neglected CMS installations. - Stealthy Windows Backdoor: A 12KB implant disguised as Realtek audio software evaded detection by hiding its C2 domain in whitespace-padded configuration files. The malware used WMI event subscriptions for persistence, activating only at a scheduled time. ### Key Takeaways This week’s incidents underscored the accelerating arms race in cybersecurity, with AI lowering the barrier for attackers while defenders race to patch critical flaws. From low-tech cable cuts to highly automated AI-driven intrusions, the threats spanned the full spectrum of modern cyber risk reinforcing the need for proactive patching, behavioral detection, and resilient access controls.
INCIDENT DETAILS -
TYPE
ransomwaredata breachcredential theftphishingzero-day exploitMFA bypasssession hijacking
MOTIVATION
financial gainespionagedata theftcredential harvestingbusiness email compromise (BEC)ransomware deployment
IMPACT
LDAP credentialsSQL databasesGlobal Administrator account listingsengineering drawingsfacility photographsphone recordspersonally identifiable information (PII)vendor payment detailsMicrosoft Entra IDMicrosoft SCCMVMware vCenterCitrix NetScalerT-Mobile networkAzure/Entra IDMicrosoft 365WordPress sitesVisa contactless payment systemsCursor IDECopilot PersonalGitHub outage (August 17, 2026)firewall outage (AI-driven attack)stalled CI/CD pipelinesdisrupted Pull Requests and Actionsdisabled VMware HA agentcompromised VPN accessnetwork segmentation bypassShellT-MobileMcDonald’sVodafoneTCShigh (PII exposure)high (vendor payment details, NFC relay attacks)
DATA BREACH
credentialsSQL databasesengineering drawingsfacility photographsphone recordsPIIvendor payment details1.7M (McDonald’s)~425K (Vodafone)~800K (TCS)89GB (Shell)high (PII, payment details, internal directories)yes (SQL databases, LDAP credentials, engineering data)yes (ransomware encryption)no (exfiltrated data)SQL databasesengineering drawingsconfiguration filesHTML attachmentsPersonally Identifiable Information: yes
AUGUST 2026
195Before Incident
Vulnerability
19 Aug 2026 • Citrix
Citrix: Patch now! Experts urge priority patching of latest Citrix NetScaler ADC and NetScaler Gateway vulnerability

Critical Citrix NetScaler Vulnerabilities Demand Immediate Patching

286After Incident
CRITICAL-91
CIT1787610269
Critical Citrix NetScaler Vulnerabilities Demand Immediate Patching On 19 August 2026, Citrix disclosed two vulnerabilities affecting its NetScaler ADC and NetScaler Gateway devices, with one posing a severe risk to enterprise networks. The flaws, tracked as CVE-2026-19489 (CVSS 8.8) and CVE-2026-19490 (CVSS 9.3), could enable denial-of-service attacks and authentication bypass, respectively. CVE-2026-19490, the more critical of the two, allows attackers to bypass authentication on exposed systems. Given that NetScaler ADC and Gateway are widely used for application delivery, load balancing, SSL/TLS offloading, and secure remote access, they are often deployed in enterprise DMZs, making them prime targets for exploitation. Security firm Rapid7 warned that such vulnerabilities in Citrix products are frequently weaponized by threat actors. Affected versions include: - NetScaler ADC & Gateway 14.1 (before 14.1-73.32) - NetScaler ADC & Gateway 13.1 (before 13.1-63.21) - NetScaler ADC FIPS (before 14.1-73.32 FIPS or 13.1-37.277 for NDcPP) Citrix provided detection guidance, advising customers to check for SAML action configurations (`add authentication samlAction.`) or authentication/VPN vserver setups (`add authentication vserver .` / `add vpn vserver .*`). While no active exploitation has been observed as of the disclosure date, Rapid7 emphasized the urgency of patching, noting that Citrix vulnerabilities historically attract rapid attacker interest. Organizations are advised to apply updates immediately to mitigate potential risks.
INCIDENT DETAILS -
TYPE
Vulnerability Disclosure
IMPACT
Systems Affected: NetScaler ADC and NetScaler Gateway devicesOperational Impact: Potential unauthorized access, denial-of-service
AUGUST 2026
314Before Incident
Vulnerability
04 Aug 2026 • Citrix
SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation

311After Incident
CRITICAL-3
SAPFORVBUCITSONSOPHIK1785846368
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries. ### Attack Methodology The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept (PoC) code, though some were modified for the operation. Once inside a network, the attacker: - Deployed web shells and network tunnels to move laterally. - Harvested NTLM password hashes, credential stores, and browser secrets. - Compromised Active Directory (AD), extracting Kerberos ticket-granting keys to forge long-term authentication tokens. - In some cases, achieved full domain control, enabling ransomware groups to later encrypt systems. ### Shift to Espionage: Ukraine in the Crosshairs While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker: - Deployed Sliver command-and-control (C2) tooling. - Accessed exposed source-code repositories. - Collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure. CloudSEK assessed with moderate-to-high confidence that this phase served Russian state-linked intelligence needs, though it remains unclear whether the actor was directly tasked or sold the data to a state customer. ### Shared Infrastructure and Defensive Recommendations The same VPS servers, tunnels, and tooling were used for both criminal and espionage activities, highlighting the blurred lines between cybercrime and state-sponsored operations. Organizations are advised to: - Remove administrative interfaces from direct internet exposure. - Patch vulnerable appliances immediately. - Rotate credentials and review unauthorized logins, SSH keys, and device settings. - Isolate IP cameras from public networks and replace default passwords. ### Indicators of Compromise (IoCs) CloudSEK provided key IoCs, including: - IPv4 addresses linked to operator VPS, jumpboxes, and C2 infrastructure. - SHA-256 hashes for Sliver Linux implants and malicious drivers used in credential theft. The case underscores the dual threat posed by initial access brokers facilitating both ransomware attacks and state-aligned espionage while reinforcing the risks of unpatched edge devices and exposed credentials.
INCIDENT DETAILS -
TYPE
CybercrimeEspionage
MOTIVATION
Financial gainState-aligned intelligence collection
IMPACT
Data Compromised: NTLM password hashes, credential stores, browser secrets, Kerberos ticket-granting keys, source-code repositories, images from IP cameras, remote desktop screenshotsSystems Affected: Networks across education, healthcare, financial services, telecommunications, government, defense, and aerospace sectorsOperational Impact: Full domain control achieved in some cases, enabling ransomware deploymentIdentity Theft Risk: High (due to credential harvesting)
DATA BREACH
NTLM password hashesCredential storesBrowser secretsKerberos ticket-granting keysSource-code repositoriesImages from IP camerasRemote desktop screenshotsSensitivity Of Data: High (personally identifiable information, authentication tokens, military logistics data)Data Exfiltration: Yes (data sold on dark web in some cases)ImagesSource codeScreenshotsPersonally Identifiable Information: Yes (credentials, authentication tokens)
JULY 2026
310Before Incident
Vulnerability
10 Jul 2026 • Citrix
Citrix and Progress Software: URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat

307After Incident
CRITICAL-3
CITPRO1783931784
Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat Progress Software has instructed customers to immediately take offline all Windows servers running ShareFile Storage Zone Controllers, citing a "credible external security threat." The company disabled access to affected accounts as a precautionary measure while collaborating with internal and external security experts to investigate the incident. The disruption came to light on July 10 after a customer shared Progress’s advisory on Reddit’s r/sysadmin. Progress later confirmed the issue on its status page, marking Storage Zone Controllers as "not operational" and the incident as under active investigation. The company has not disclosed the nature of the threat, its origin, or whether any data has been compromised though it stated there is no evidence of unauthorized access to ShareFile accounts or cloud-stored data. The Storage Zone Controller, a self-hosted component that allows organizations to retain files on their own infrastructure while using ShareFile’s cloud for management, is the sole affected system. Unlike standard cloud-only ShareFile accounts, these controllers are typically exposed to the internet, increasing their vulnerability. Progress’s decision to mandate a full shutdown rather than issuing a patch suggests the threat may involve an unpatched zero-day flaw, stolen credentials, or an issue within Progress’s own systems. Customers are advised to keep controllers offline until further notice and verify they are running ShareFile Storage Zones Controller version 5.12.4 or later (5.x line) or any 6.x release, which address previously disclosed vulnerabilities. However, Progress has not confirmed whether these updates mitigate the current threat. Organizations with internet-exposed controllers should treat the situation as a potential incident, preserve logs, and scan for unauthorized .aspx files in web directories and storage paths. This is not the first time the Storage Zone Controller has been targeted. In 2023, while under Citrix’s ownership, attackers exploited CVE-2023-24489, an unauthenticated flaw in the same component. The vulnerability was actively exploited, prompting Citrix to sever unpatched controllers from the ShareFile cloud a step Progress has now replicated. Progress itself faced a major breach last year via the MOVEit file-transfer zero-day, which the Clop ransomware group leveraged to compromise over 2,700 organizations. As of now, Progress has not provided a timeline for resolution or details on the threat’s specifics, leaving customers in limbo regarding when they can safely restore operations.
INCIDENT DETAILS -
TYPE
Security Threat
IMPACT
Systems Affected: ShareFile Storage Zone ControllersDowntime: Not operationalOperational Impact: Mandated shutdown of affected systems
DATA BREACH
File Types Exposed: .aspx files
JULY 2026
312Before Incident
Vulnerability
01 Jul 2026 • Citrix
Citrix: CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure

CitrixBleed-Class Vulnerability (CVE-2026-8451) Exploited Within Hours of Disclosure

308After Incident
CRITICAL-4
CIT1783016843
CitrixBleed-Class Vulnerability Exploited Within Hours of Disclosure A newly disclosed CitrixBleed-class vulnerability (CVE-2026-8451) in Citrix NetScaler appliances was actively exploited less than 24 hours after public disclosure, according to decoy infrastructure operator Lupovis. The flaw, part of a recurring series of memory-disclosure bugs in NetScaler’s SAML authentication parser, was targeted in a coordinated scanning campaign between 30 June and 1 July 2026. A threat actor operating from IP 146.70.139[.]154 hosted on M247 Europe SRL (AS9009) infrastructure in Frankfurt, Germany probed three Lupovis sensors over a five-hour window. After receiving a 200 response from one sensor, the attacker delivered a confirmed CVE-2026-8451 exploitation payload, mirroring tactics observed in prior CitrixBleed incidents. The vulnerability affects NetScaler ADC/Gateway versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18 when configured as a SAML Identity Provider (IdP). It stems from a flaw in NetScaler’s XML parser, which fails to properly terminate unquoted attribute values, leading to an out-of-bounds memory read that exposes session tokens via the NSC_TASS cookie. The exploit payload, sent to POST /saml/login, consisted of a malformed <samlp:AuthnRequest> tag padded with 476 spaces a pattern designed to force the parser to read beyond its buffer. This technique aligns with the Detection Artifact Generator released by watchTowr Labs alongside Citrix’s advisory (CTX696604). Notably, CVE-2026-8451 remains absent from CISA’s Known Exploited Vulnerabilities (KEV) catalog, despite active exploitation a repeat of past CitrixBleed incidents where in-the-wild attacks preceded formal KEV listings by weeks. Previous flaws in this family, such as CVE-2023-4966 (original CitrixBleed), led to high-profile breaches at Boeing, ICBC, and DP World within weeks of disclosure. The attacker’s tooling, identified by the python-requests/2.32.5 User-Agent, validated targets before deploying payloads, a behavior consistent with opportunistic mass exploitation. The rapid exploitation underscores the persistent risk posed by CitrixBleed-style vulnerabilities, particularly for organizations relying solely on KEV-driven patch prioritization.
INCIDENT DETAILS -
TYPE
Memory Disclosure Vulnerability Exploitation
MOTIVATION
Opportunistic mass exploitation
IMPACT
Data Compromised: Session tokens (NSC_TASS cookie)Systems Affected: Citrix NetScaler ADC/Gateway (SAML IdP configurations)Identity Theft Risk: High (session token exposure)
DATA BREACH
Type Of Data Compromised: Session tokensSensitivity Of Data: High (session hijacking risk)Personally Identifiable Information: Session tokens (indirect PII risk)
JUNE 2026
407Before Incident
Ransomware
01 Jun 2026 • Citrix
Fortinet, Check Point, Palo Alto and Citrix: Ransomware groups are hammering your vulnerable VPNs

Ransomware Groups Exploit VPNs and Edge Devices as Prime Entry Points into Corporate Networks

303After Incident
CRITICAL-104
CHEFORPALCIT1784881580
Ransomware Groups Exploit VPNs and Edge Devices as Prime Entry Points into Corporate Networks Cybercriminals, including ransomware-as-a-service (RaaS) operators and nation-state-backed advanced persistent threat (APT) groups, are increasingly targeting internet-facing VPNs and edge devices to breach corporate networks. According to cybersecurity experts, these systems often exposed to the internet provide attackers with a direct gateway into an organization’s infrastructure, bypassing endpoint security controls. Key Attack Vectors and Trends - Stolen Credentials Over Exploits: While unpatched vulnerabilities remain a concern, attackers more frequently abuse compromised credentials to access non-MFA-protected accounts. Huntress reports that VPNs account for 70% of initial access in advanced threat actor campaigns, with stolen credentials being the primary method. - Ransomware Operations: Groups like Qilin and Akira leverage VPN and firewall flaws particularly in products from Palo Alto, Fortinet, Citrix, and Check Point to deploy ransomware. Post-exploitation tactics vary, from rapid encryption to double-extortion schemes, suggesting multiple affiliates operate under RaaS models. - Zero-Day Exploits: Recent campaigns highlight the exploitation of CVE-2024-3400 in Palo Alto’s GlobalProtect VPN and vulnerabilities in FortiGate, Citrix NetScaler, and Check Point devices. Attackers prioritize internet-facing assets with known active exploits, leaving organizations with minimal time to patch. Industry Impact and Mitigation Challenges - Rising Threat Trajectory: Despite no significant spike in ransomware volume in Q2 2026, attacks continue to escalate, with VPNs and edge devices remaining high-value targets. NCC Group’s threat report ranks Qilin as the second-most active ransomware group (238 victims) and Akira fourth (127 victims) for the quarter. - Security Gaps: Edge devices are particularly vulnerable due to their continuous internet exposure and privileged access. Experts warn that delayed patching especially for critical updates creates a narrow window for attackers to strike before defenses are fortified. - Defensive Strategies: Recommended measures include zero-trust network segmentation, phishing-resistant MFA, aggressive patch management (applying updates within 24–48 hours), and monitoring for unusual authentication activity. However, the shift toward convenience over containment in enterprise networks exacerbates lateral movement risks. The trend underscores a persistent challenge: while vulnerabilities in perimeter devices are lucrative for attackers, the abuse of legitimate credentials remains the dominant and often overlooked threat vector.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial GainData ExfiltrationDouble Extortion
IMPACT
VPNsEdge DevicesFirewalls
DATA BREACH
Data Exfiltration: Yes (Double Extortion Schemes)Data Encryption: Yes (Ransomware Encryption)
Vulnerability
01 Jun 2026 • Citrix
Citrix, Kontron, The Gentlemen RaaS Victims and Anubis Ransomware Victims: Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors

303After Incident
CRITICAL-104
CITGUIKONARC1783031139
Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors Threat actors linked to the Anubis ransomware-as-a-service (RaaS) operation are actively exploiting CVE-2025-5777 (Citrix Bleed 2), a critical vulnerability in Citrix NetScaler ADC and Gateway, to gain initial access to victim networks. According to a report by Arctic Wolf, attackers leverage legitimate Remote Management and Monitoring (RMM) tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment to blend in with normal IT activity while maintaining persistent control. Anubis, a rebrand of the Sphinx ransomware, emerged in late 2024 and was formally announced on the RAMP underground forum in February 2025. Since then, the group has claimed 91 victims on its data leak site, with 11 reported in June 2026 alone. Targeted sectors include healthcare, business services, manufacturing, technology, and financial services, with over 50% of victims based in the U.S., followed by the U.K., Australia, France, and Canada. The group employs aggressive tactics, including an irreversible data-wiping feature that reduces files to 0 KB regardless of ransom payment, increasing pressure on victims. Affiliates receive 80% of ransom payments, a lucrative incentive that has fueled the operation’s growth. Beyond Citrix Bleed 2, Anubis actors have also used stolen VPN credentials potentially sourced from initial access brokers, credential stuffing, or info-stealer malware to breach networks via Cisco AnyConnect VPNs, particularly through hosting providers like AS20473 (The Constant Company) and AS55286 (ServerMania). Once inside, attackers move laterally using RDP and PsExec, deploy RMM tools for persistence, and exfiltrate data via Cloudflare Tunnels, S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. They also disable security defenses, including Windows Defender and Sophos, and manipulate logs to hinder forensic analysis. In some cases, the ransomware encryptor is deleted post-execution, further complicating detection. ### The Gentlemen RaaS and Zero-Day Exploits Separately, Kaspersky detailed The Gentlemen RaaS, which exploits known vulnerabilities and weak credentials to deploy a Go-based backdoor for remote command execution. The malware collects system data, exfiltrates it to 81.177.215[.]15:9443, and can establish a SOCKS proxy for network pivoting. The group has also weaponized a zero-day vulnerability in ktapi.sys, a Kontron driver, to bypass Windows security protections and terminate processes from Microsoft, ESET, Palo Alto Networks, and SentinelOne. ### VECT and TeamPCP’s Supply Chain-Ransomware Hybrid A Sophos investigation revealed a partnership between VECT and TeamPCP, announced in March 2026, combining supply chain credential theft with ransomware deployment. TeamPCP, previously operating as CipherForce, rebranded after listing six victims in February 2026. However, VECT’s encryptor contains critical flaws, destroying files larger than 128 KB instead of encrypting them a defect TeamPCP claims it never used in attacks. The alliance represents a shift toward industrialized ransomware deployment, lowering the barrier for cybercriminals by merging large-scale supply chain attacks with mature RaaS operations. Despite technical shortcomings, the model poses a growing threat to enterprises.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData exfiltrationExtortion
IMPACT
Citrix NetScaler ADC and GatewayVPN systems (Cisco AnyConnect)Windows systemsOperational Impact: Disruption of services, lateral movement within networks, disabling of security defenses
DATA BREACH
Personally identifiable informationPayment informationSensitive corporate dataSensitivity Of Data: High
MAY 2026
407Before Incident
Vulnerability
16 May 2026 • Citrix
Citrix and BlackCat: MSN

Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability

403After Incident
CRITICAL-4
CITBLA1778977440
Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability A recent cyberattack has disrupted operations across multiple U.S. healthcare providers, with the ransomware group BlackCat (ALPHV) exploiting a previously unknown zero-day vulnerability in Citrix NetScaler ADC and Gateway systems. The flaw, tracked as CVE-2023-4966 (dubbed "Citrix Bleed"), allows attackers to bypass authentication and gain unauthorized access to sensitive networks. The attack, detected in late October 2023, targeted hospitals, clinics, and medical billing firms, leading to delayed patient care, system outages, and data exposure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the vulnerability’s active exploitation, warning that threat actors could steal session tokens to maintain persistent access even after patches are applied. BlackCat, known for its double-extortion tactics, has demanded ransoms ranging from $1 million to $10 million per victim. While some organizations have restored systems from backups, others remain locked out of critical infrastructure. The incident underscores the growing risk of zero-day exploits in healthcare, where legacy systems and high-value data make providers prime targets. Citrix released emergency patches on October 10, 2023, urging all users to update immediately. However, CISA’s advisory notes that compromised credentials may still pose a threat, requiring additional mitigation steps, including credential resets and network segmentation. The full scope of affected entities remains unclear, though reports indicate at least dozens of organizations have been impacted.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware), Data exfiltration
IMPACT
Data Compromised: Session tokens, sensitive healthcare dataSystems Affected: Citrix NetScaler ADC and Gateway systemsDowntime: Delayed patient care, system outagesOperational Impact: Disrupted healthcare operationsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Session tokens, sensitive healthcare dataSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Likely
MAY 2026
407Before Incident
Vulnerability
01 May 2026 • Citrix
Citrix, Microsoft, Apache Software Foundation and Langflow: Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Chinese Threat Actor Leverages AI for Autonomous Cyberattacks

403After Incident
CRITICAL-4
MICTHESECCIT1785522270
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks Researchers at Palo Alto Networks’ Unit 42 have uncovered a campaign by a China-based threat actor using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks with minimal human oversight. The actor, operating under the aliases "knaithe" and "KnYuan," identifies as a "binary security researcher." The discovery stemmed from an accidental exposure of the attacker’s environment after Hermes created a misconfigured web server, revealing API keys, exploit scripts, target lists, shell history, and AI attack logs. While the observed attacks did not successfully compromise targets, they demonstrated a fully autonomous offensive AI workflow capable of identifying, evaluating, and exploiting vulnerabilities. ### AI-Powered Attack Workflow The threat actor deployed DeepSeek as the reasoning engine behind Hermes Agent, an AI framework that interacts with operating systems, executes commands, and connects to the internet. Hermes was configured to: - Receive instructions via Telegram - Use custom offensive-security tools - Query FOFA, an internet asset search engine - Operate in "Yolo" mode, executing commands without prior approval In a recovered session from May 2026, the agent autonomously: 1. Targeted Langflow servers vulnerable to CVE-2026-33017, scanning 84 exposed instances but failing to exploit them. 2. Switched to n8n workflow automation, identifying 647,000 exposed instances and attempting to exploit CVE-2026-21858 and CVE-2025-68613 though authentication requirements prevented successful breaches. 3. Analyzed public exploit repositories and executed hundreds of hours of manual targeting analysis in minutes, managing its own compute resources. ### Manual Attacks & Successful Compromises While the AI-driven attacks were largely unsuccessful, the threat actor also conducted manual attacks on 460+ systems, exploiting vulnerabilities in: - Citrix NetScaler (CVE-2026-3055) – Used in three confirmed breaches to extract memory and harvest authentication cookies. - Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others. Additional AI platforms (Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) were configured but rarely used. ### Previous Hermes Incident in Thailand This campaign follows a separate incident where poorly secured Hermes infrastructure exposed details of an alleged cyberattack on Thailand’s Ministry of Finance. Logs revealed Hermes operating in unattended "YOLO" mode, automating post-exploitation tasks such as: - Privilege escalation checks - Service enumeration - File system traversal - Document cataloging Unlike the autonomous attacks observed by Unit 42, the Thailand incident involved human-directed targeting, with Hermes only automating post-compromise activity. ### Significance of the Campaign Unit 42 highlights the evolution of AI-driven cyber threats, where autonomous agents can: - Research vulnerabilities independently - Prioritize targets - Download and execute exploits - Adapt attack strategies in real time While this campaign had limited success, it underscores the growing sophistication of offensive AI in cyber operations.
INCIDENT DETAILS -
TYPE
AI-driven cyberattackManual exploitation
IMPACT
Authentication cookies (Citrix NetScaler breaches)Systems Affected: 460+ systems (including Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN)
DATA BREACH
Authentication cookiesSensitivity Of Data: High (authentication credentials)
APRIL 2026
405Before Incident
MARCH 2026
402Before Incident
Vulnerability
23 Mar 2026 • Citrix
Cloud Software Group: Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group

398After Incident
CRITICAL-4
CLO1774312166
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group Cloud Software Group has released emergency security updates for NetScaler ADC and NetScaler Gateway, addressing two high-severity vulnerabilities that could enable unauthenticated remote attacks on affected systems. The most critical flaw, CVE-2026-3055 (CVSS 9.3), is an out-of-bounds read vulnerability in SAML Identity Provider (IDP) configurations. Exploitable without authentication or user interaction, it allows attackers to trigger memory overreads, potentially leading to system compromise. The issue was discovered internally, with no evidence of active exploitation at the time of disclosure. Administrators can check for exposure by verifying SAML IDP configurations in NetScaler settings. The second vulnerability, CVE-2026-4368 (CVSS 7.7), involves a race condition causing session mixups in appliances configured as Gateways (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual servers. While exploitation requires low-privilege authentication and precise timing, successful attacks could fully compromise session confidentiality and integrity. Affected Versions & Patches: - CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and FIPS/NDcPP before 13.1-37.262. - CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54. Fixed releases include 14.1-66.59 or later, 13.1-62.23 or later, and 13.1-FIPS/NDcPP 13.1.37.262 or later. The patches apply only to customer-managed deployments, as Citrix-managed cloud services and Adaptive Authentication instances have already been updated. Given NetScaler’s widespread use in enterprise VPN and application delivery, unpatched systems pose a significant risk. Security teams are advised to prioritize updates, particularly for SAML IDP-configured appliances.
INCIDENT DETAILS -
TYPE
Vulnerability Disclosure
IMPACT
Systems Affected: NetScaler ADC and NetScaler Gateway appliancesOperational Impact: Potential system compromise, session confidentiality and integrity risks
FEBRUARY 2026
393Before Incident
Vulnerability
01 Feb 2026 • Citrix
Citrix: Threat Actors Conduct Widespread Scanning for Exposed Citrix NetScaler Login Pages

Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered

389After Incident
CRITICAL-4
CIT1770201552
Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered A sophisticated reconnaissance campaign targeting Citrix ADC (NetScaler) Gateway infrastructure has been detected, involving over 63,000 residential proxy IPs and AWS cloud instances to map login panels and enumerate software versions. The operation, which generated 111,834 scanning sessions, was highly targeted 79% of traffic focused on Citrix Gateway honeypots indicating deliberate pre-exploitation preparation rather than random scanning. The campaign unfolded in two phases: 1. Login Panel Discovery (Primary Phase) - 109,942 sessions from 63,189 unique IPs probed the `/logon/LogonPoint/index.html` authentication interface. - 64% of traffic originated from residential proxies across Vietnam, Argentina, Mexico, Algeria, and Iraq, while a single Microsoft Azure IP in Canada accounted for 36%. - Threat actors used unique browser fingerprints and residential proxies to evade geographic and reputation-based blocking. 2. Version Disclosure Sprint (AWS Phase) - On February 1, 2026, 10 AWS instances in us-west-1/us-west-2 executed a six-hour scan, sending 1,892 requests to `/epa/scripts/win/nsepa_setup.exe` to identify Citrix Endpoint Analysis (EPA) versions. - Activity peaked at 362 sessions around 02:00 UTC before tapering off by 05:00 UTC. - All requests used an outdated Chrome 50 user agent (2016) and uniform HTTP fingerprints, suggesting a coordinated effort to exploit known vulnerabilities. Researchers from GreyNoise noted the focus on the EPA setup file path indicates potential interest in version-specific exploits, particularly given recent critical Citrix vulnerabilities: - CVE-2025-5777 ("CitrixBleed 2") - CVE-2025-5775 (remote code execution, exploited as a zero-day). Detection and Indicators of Compromise (IOCs) - User agents: `blackbox-exporter` (unauthorized sources), Chrome 50 (2016) - Targeted paths: `/logon/LogonPoint/`, `/epa/scripts/win/nsepa_setup.exe` - AWS IPs (Version Disclosure): `44.251.121.190, 13.57.253.3, 50.18.232.85, 52.36.139.223, 54.201.20.56, 54.153.0.164, 54.176.178.13, 18.237.26.188, 54.219.42.163, 18.246.164.162` - Azure IP (Login Panel Discovery): `52.139.3.76` The campaign’s scale and precision suggest threat actors are actively preparing for potential exploitation, likely targeting unpatched or misconfigured Citrix ADC deployments.
INCIDENT DETAILS -
TYPE
Reconnaissance
MOTIVATION
Pre-exploitation preparation
IMPACT
Systems Affected: Citrix ADC (NetScaler) Gateway infrastructure
JANUARY 2026
393Before Incident
DECEMBER 2025
379Before Incident
NOVEMBER 2025
372Before Incident
Vulnerability
01 Nov 2025 • Citrix
Citrix and VMware: Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware

Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft

368After Incident
CRITICAL-4
CITVMW1776702564
Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft Cybercriminals are increasingly abusing QEMU, a legitimate open-source virtualization tool, to bypass endpoint security and deploy ransomware or steal credentials undetected. By running malicious operations inside hidden virtual machines (VMs), attackers exploit a critical blind spot security tools on the host system cannot inspect activity within the VM, leaving minimal forensic traces. Sophos researchers have identified two active campaigns leveraging this technique since late 2025: 1. STAC4713 (November 2025) – Linked to the PayoutsKing ransomware group (GOLD ENCOUNTER), which operates independently (not as a ransomware-as-a-service). The group targets VMware and ESXi hypervisors, using QEMU to execute attacks. The infection chain begins with a scheduled task ("TPMProfiler") running QEMU under the SYSTEM account, booting from a disguised virtual disk (initially vault.db, later bisrv.dll). The VM establishes a reverse SSH tunnel via custom ports (32567, 22022) to port 22, creating a persistent backdoor. Tools inside the VM include AdaptixC2, Linker2, and a WireGuard obfuscator (wg-obfuscator). 2. STAC3725 (February 2026) – Exploits the CitrixBleed2 vulnerability (CVE-2025-5777) for initial access, then deploys a malicious ScreenConnect client for persistence. Attackers manually compile a toolkit inside the QEMU VM, including Impacket, KrbRelayX, BloodHound.py, NetExec, and Metasploit, to harvest credentials, enumerate Active Directory, and stage payloads via FTP. Both campaigns demonstrate a growing trend of virtualization-based evasion, where trusted tools like QEMU are repurposed to conceal malicious activity. The technique’s stealth and lack of detectable artifacts make it particularly challenging for defenders to identify and mitigate in real time.
INCIDENT DETAILS -
TYPE
ransomwarecredential theft
MOTIVATION
financial gaincredential harvesting
IMPACT
credentialsActive Directory enumeration dataVMware and ESXi hypervisorsWindows systems with QEMUIdentity Theft Risk: high
DATA BREACH
credentialsActive Directory dataSensitivity Of Data: highData Encryption: yes (ransomware)
OCTOBER 2025
540Before Incident
Breach
19 Oct 2025 • Citrix
F5

Oracle E-Business Suite Remotely Exploitable Vulnerability (CVE-2025-61884)Microsoft Zero-Day Exploits (CVE-2025-24990, CVE-2025-59230, CVE-2025-47827)F5 Data Breach: Nation-State Attackers Stole BIG-IP Source CodeAdobe Experience Manager 'Perfect' Vulnerability (CVE-2025-54253)Microsoft Revokes 200 Certificates Used for Malicious Teams Installers (Vanilla Tempest Ransomware)Cisco Zero-Day Rootkit Deployment on Network Switches (CVE-2025-20352)U.S. Seizes $15B in Bitcoin Linked to Forced-Labor Crypto ScamUnitree G1 Humanoid Robot Bluetooth Vulnerability (Espionage Risk)Healthcare Cybersecurity Breakdown: 93% of U.S. Organizations Attacked (Patient Care Disruptions)

369After Incident
CRITICAL-171
F50032500101925
US tech company F5 confirmed a data breach in which nation-state attackers stole the source code and vulnerability information related to its BIG-IP family of networking and security products. BIG-IP is a critical infrastructure component used by enterprises for traffic management, load balancing, and security, making this breach particularly severe. The stolen data could enable adversaries to identify and exploit undiscovered flaws in BIG-IP systems, potentially leading to supply-chain attacks, unauthorized network access, or large-scale disruptions in organizations relying on F5’s solutions. The breach underscores the escalating risks of state-sponsored cyber espionage targeting foundational IT infrastructure, with implications for global cybersecurity resilience. F5 has not disclosed whether customer data was compromised, but the theft of proprietary code and vulnerability details poses a long-term threat to its product ecosystem and the broader digital supply chain.
INCIDENT DETAILS -
TYPE
VulnerabilityZero-Day ExploitsData BreachVulnerabilityMalware Distribution (Ransomware)Zero-Day Exploit (Rootkit)Cryptocurrency FraudHardware Vulnerability (Espionage)Cyberattack Campaign (Healthcare)
MOTIVATION
Cyber Espionage (Source Code Theft)Financial Gain (Ransomware)Financial Gain (Crypto Fraud)Espionage/Data Theft
IMPACT
$15 billion (Seized)BIG-IP Source Code & Vulnerability InfoRobot Sensor/Data LeaksOracle E-Business SuiteMicrosoft Products (Multiple)F5 BIG-IP Networking/Security ProductsAdobe Experience Manager (JEE)Microsoft Teams (Malicious Installers)Cisco Network Switches (IOS/IOS XE)Cryptocurrency Wallets/ExchangesUnitree G1 Humanoid RobotsPatient Care Disruptions (72% of Incidents)Source Code Integrity RiskMalware Distribution InfrastructureNetwork Compromise (Rootkits)Fraud Operation ShutdownEspionage Risk (China-Linked)High (Healthcare)High (F5)High (Microsoft)High (Cisco)Severe (Crypto Scam)High (Unitree/Alias Robotics)Severe (Healthcare Sector)Criminal Charges (Forced Labor)HIPAA/Regulatory ViolationsHigh (Patient Data)High
DATA BREACH
Source Code & Vulnerability DetailsRobot Sensor DataHigh (Proprietary Code)High (Espionage Risk)High (PHI/PII)Yes (Source Code)Yes (China-Linked)Likely (Ransomware)Yes (Patient Data)
AUGUST 2025
535Before Incident
Vulnerability
26 Aug 2025 • Citrix
Citrix (Cloud Software Group)

Critical Remote Code Execution Flaw (CVE-2025-7775) in Citrix NetScaler ADC and Gateway

531After Incident
CRITICAL-4
CIT806082725
Citrix disclosed a critical zero-day vulnerability (CVE-2025-7775) in its NetScaler ADC and NetScaler Gateway products, actively exploited in the wild as of August 26, 2025. The flaw—a memory overflow bug—enables unauthenticated remote code execution (RCE) on unpatched devices, posing severe risks to organizations relying on these appliances for secure access. While Citrix did not provide indicators of compromise (IoCs), they confirmed exploitation on systems configured as Gateway (VPN, ICA Proxy, RDP Proxy), AAA virtual servers, or specific load-balancing (LB) setups with IPv6 bindings. No mitigations exist, forcing immediate patching to versions 14.1-47.48, 13.1-59.22, or later.The vulnerability’s exploitation could allow attackers to gain full control over affected systems, potentially leading to lateral movement, data exfiltration, or deployment of malware/ransomware. Citrix also patched two other flaws: a DoS vulnerability (CVE-2025-7776) and an improper access control issue (CVE-2025-8424), further compounding risks. Historical context—such as the prior Citrix Bleed 2 (CVE-2025-5777) exploit—highlights the company’s recurring exposure to high-severity attacks targeting memory corruption. Failure to patch could result in widespread breaches, operational disruptions, or supply-chain attacks given NetScaler’s role in enterprise networks.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationZero-Day AttackRemote Code Execution (RCE)Denial of Service (DoS)Improper Access Control
IMPACT
NetScaler ADC (versions 12.1, 13.1, 14.1)NetScaler Gateway (versions 13.1, 14.1)NetScaler ADC 13.1-FIPS and NDcPPNetScaler ADC 12.1-FIPS and NDcPPPotential unauthorized remote code executionDenial of Service (DoS) risksUnauthorized access to management interfacesPotential reputational damage due to zero-day exploitation
JUNE 2025
527Before Incident
Vulnerability
16 Jun 2025 • Citrix
Citrix

Exploitation of Citrix Vulnerabilities via HexStrike-AI Red Teaming Tool

522After Incident
CRITICAL-5
CIT1555015090425
Cybercriminals are leveraging HexStrike-AI, a legitimate red teaming tool, to automate exploits against Citrix NetScaler ADC and Gateway using recently disclosed vulnerabilities (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424). The tool enables unauthenticated remote code execution (RCE), allowing attackers to deploy webshells and maintain persistent access. While no confirmed breaches are reported yet, the exploitation window has shrunk from days to minutes, drastically reducing the time administrators have to patch systems. The CVE-2025-7775 flaw is already being exploited in the wild, and the use of HexStrike-AI is expected to escalate attack volumes, increasing the risk of unauthorized system takeovers, data exposure, or operational disruptions for organizations relying on Citrix infrastructure. The automation capability of the tool makes manual patch management nearly impossible without dedicated platforms, heightening the urgency for immediate mitigation.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationAutomated AttackUnauthorized Access
MOTIVATION
Financial GainUnauthorized AccessPersistenceData Theft
IMPACT
Citrix NetScaler ADCCitrix NetScaler GatewayReduced Patching WindowIncreased Attack VolumeAutomated ExploitationPotential Reputation Damage for CitrixTrust Erosion in Patch Management
MAY 2025
537Before Incident
Cyber Attack
01 May 2025 • Citrix
Citrix

Sophisticated Cyberattacks Targeting Critical Infrastructure via Citrix NetScaler Zero-Day Vulnerability

519After Incident
CRITICAL-18
CIT211081225
The Dutch National Cyber Security Centre (NCSC-NL) has issued an urgent warning about sophisticated cyberattacks targeting critical infrastructure through a zero-day vulnerability in Citrix NetScaler devices. The vulnerability, designated CVE-2025-6543, has been actively exploited since early May 2025, compromising several critical organizations across the Netherlands. Attackers gained access to perimeter defenses, demonstrating advanced capabilities by erasing forensic traces and deploying malicious web shells for persistent remote access. The exploitation involved placing suspicious PHP files in system directories, making detection and remediation challenging. The NCSC emphasizes that patching alone is insufficient, as compromised systems may retain attacker access, requiring comprehensive forensic investigation.
INCIDENT DETAILS -
TYPE
Zero-day exploitation
IMPACT
Systems Affected: Citrix NetScaler ADC and Gateway systemsOperational Impact: Significant security breach, access to perimeter defenses
FEBRUARY 2025
586Before Incident
Breach
01 Feb 2025 • Citrix
Anthropic: Anthropic leaks its own AI coding tool’s source code in second major security breach

Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems

522After Incident
CRITICAL-64
ANT1774981746
Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems Anthropic has inadvertently leaked the source code for Claude Code, its widely adopted AI-powered coding assistant, exposing roughly 500,000 lines of code across 1,900 files. The incident, confirmed by the company as a "release packaging issue" caused by human error, occurred when internal code was mistakenly uploaded to NPM a platform for software distribution instead of the final, compiled version. The leak follows a separate accidental disclosure earlier this month, in which a draft blog post revealed details about Mythos (also referred to as Capybara), an upcoming AI model described as more powerful and potentially more dangerous than Anthropic’s current flagship, Opus. While the latest breach did not expose model weights or customer data, cybersecurity experts warn it could allow competitors to reverse-engineer Claude Code’s underlying "agentic harness" the software layer that governs the AI’s behavior, tool integration, and safety guardrails. This could enable the creation of open-source alternatives or help rivals refine their own AI systems. Security researcher Roy Paz of LayerX Security noted that the leaked code also provided further evidence of Capybara, Anthropic’s next-generation model, which is expected to surpass Opus in capability and cost. The draft blog post previously described it as a new tier, with "fast" and "slow" variants likely replacing Opus as the company’s most advanced offering. Paz highlighted concerns that the exposed code may reveal vulnerabilities in how Claude Code interacts with Anthropic’s internal systems, potentially allowing malicious actors including nation-states to exploit the AI for cyberattacks or bypass existing safeguards. Anthropic’s Opus model is already classified as a high-risk tool due to its ability to autonomously identify zero-day vulnerabilities, a capability that could be weaponized by threat actors. This is not the first time the company has faced such an exposure; in February 2025, an early version of Claude Code was similarly leaked, revealing internal workings and system connections before being removed. The company has stated it is implementing measures to prevent future incidents but has not disclosed further details. The leak underscores the challenges of securing proprietary AI systems as adoption and scrutiny of advanced models continues to grow.
INCIDENT DETAILS -
TYPE
Data Leak
IMPACT
Data Compromised: 500,000 lines of source code across 1,900 filesSystems Affected: Claude Code AI-powered coding assistant, internal AI systemsOperational Impact: Potential reverse-engineering of AI systems by competitors or malicious actorsBrand Reputation Impact: Yes
DATA BREACH
Type Of Data Compromised: Source code, internal AI system detailsNumber Of Records Exposed: 1,900 filesSensitivity Of Data: High (proprietary AI code, agentic harness, internal system connections)File Types Exposed: Source code filesPersonally Identifiable Information: No
JANUARY 2025
591Before Incident
Vulnerability
01 Jan 2025 • Citrix
F5, Lloyds Banking Group, Citrix, Dutch Ministry of Finance and European Commission: Lloyds Banking Group - Security Affairs

Cybersecurity Roundup: Major Incidents and Emerging Threats

582After Incident
CRITICAL-9
EURF5LLOCITMIN1774989406
Cybersecurity Roundup: Major Incidents and Emerging Threats Recent weeks have seen a surge in high-profile cybersecurity incidents, vulnerabilities, and state-linked attacks targeting governments, financial institutions, and critical infrastructure. Financial Sector Breaches Lloyds Banking Group confirmed a security incident affecting nearly 500,000 mobile customers, though details on the nature of the breach remain undisclosed. Meanwhile, the Dutch Ministry of Finance took treasury systems offline following a cyber incident under investigation. Critical Vulnerabilities Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw (CVE-2026-3055) to its Known Exploited Vulnerabilities catalog after reports of active exploitation, with attackers probing the bug for potential data leaks. CISA also flagged a critical F5 BIG-IP AMP vulnerability under active attack. Additionally, security agencies warned of a severe flaw in PTC Windchill and FlexPLM, urging organizations to apply patches immediately. State-Sponsored Threats Russia-linked APT TA446 deployed the DarkSword exploit in a phishing campaign targeting iPhone users. China-associated groups launched advanced malware attacks against a Southeast Asian government in early 2025. Meanwhile, an Iran-linked group, Handala, compromised the personal email account of FBI Director Kash Patel, marking a significant escalation in espionage efforts. Ransomware and Supply Chain Attacks The Qilin ransomware group claimed responsibility for breaching Dow Inc., a major chemical manufacturer. Attackers also hijacked the Axios npm account, using it to distribute remote access trojan (RAT) malware to unsuspecting developers. In a separate incident, ShinyHunters asserted responsibility for hacking the European Commission, though the full impact remains unclear. Emerging Threats Apple issued urgent lock screen warnings for unpatched iPhones and iPads, highlighting ongoing risks to mobile security. A new macOS malware, Infinity Stealer, was discovered leveraging Nuitka Python payloads and ClickFix techniques to evade detection. Additionally, a new adversary-in-the-middle (AITM) phishing wave targeted TikTok Business accounts, demonstrating evolving social engineering tactics. Government and Institutional Targets The European Commission confirmed a cyberattack affecting part of its cloud infrastructure, though specifics on the attack vector and scope were not disclosed. These incidents underscore the persistent and evolving nature of cyber threats across sectors.
INCIDENT DETAILS -
TYPE
data_breachransomwarephishingmalwaresupply_chain_attackstate-sponsored_attack
MOTIVATION
espionagefinancial_gaindata_exfiltrationdisruption
IMPACT
mobile banking systemstreasury systemscloud infrastructurenpm accountiPhone devicesmacOS systemssystems taken offlinedisrupted services
Vulnerability
01 Jan 2025 • Citrix
Citrix and F5: Vulnerability affecting F5 BIG-IP APM

Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations

582After Incident
CRITICAL-9
F5CIT1774873786
Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations The UK’s National Cyber Security Centre (NCSC) has issued urgent guidance for organizations to mitigate active exploitation of severe vulnerabilities in F5 BIG-IP Access Policy Manager (APM) and Citrix NetScaler ADC/Gateway. Both flaws enable unauthenticated remote code execution (RCE), posing significant risks to enterprise networks. ### F5 BIG-IP APM (CVE-2025-53521) - Impact: Affects all organizations using BIG-IP APM, particularly large enterprises. Exploitation occurs when a malicious actor sends crafted traffic to a virtual server configured with an APM access policy. - Active Exploitation: F5 has confirmed in-the-wild attacks targeting this vulnerability. - Recommended Actions: - Isolate affected systems immediately to prevent further compromise. - Update to the latest patched version or rebuild systems from scratch if updates are not feasible. - Investigate for compromise, even if systems were recently updated, as exploitation may have occurred prior to patching. - Report incidents to F5 and UK authorities if a breach is suspected. ### Citrix NetScaler ADC/Gateway Vulnerabilities - Impact: Two recently disclosed flaws in Citrix NetScaler products could allow attackers to execute arbitrary code without authentication. - Recommended Actions: - Apply vendor patches without delay. - Monitor for signs of compromise, including unusual network activity or unauthorized access. - Consider engaging an assured Cyber Incident Response provider for forensic analysis if exploitation is suspected. ### Broader Context & NCSC Support The NCSC is actively assessing the UK impact of these vulnerabilities and collaborating with industry partners to track exploitation. Organizations are advised to: - Enable continuous threat hunting to detect post-exploitation activity. - Follow NCSC’s hardening guidance to reduce attack surfaces. - Leverage the NCSC Early Warning service for real-time threat notifications. Both F5 BIG-IP APM and Citrix NetScaler are widely deployed in critical infrastructure, making these vulnerabilities high-priority targets for threat actors. Immediate remediation is essential to prevent potential breaches.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Enterprise networks, critical infrastructureOperational Impact: Potential unauthorized access, arbitrary code execution
DECEMBER 2023
591Before Incident
Breach
01 Dec 2023 • Citrix
Comcast

Xfinity by Comcast Data Breach

534After Incident
HIGH-57
COM152251223
Xfinity by Comcast reports a data breach following a cyberattack that took use of the CitrixBleed vulnerability. By taking use of this vulnerability, threat actors were able to take over active authenticated connections and get around multifactor authentication and other stringent authentication regulations. The security company Mandiant saw threat actors taking control of sessions in which the threat actor used session data that had been taken prior to the patch being deployed. The business discovered that hashed passwords and usernames are among the different client data that is exposed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Hashed passwordsUsernames
DATA BREACH
Hashed passwordsUsernames
OCTOBER 2023
585Before Incident
Breach
18 Oct 2023 • Citrix
Xfinity and Comcast: Xfinity Data Breach: Claim Up to $10,000 from $117.5 Million Settlement by Sept. 14, 2026

Comcast Xfinity Data Breach Settlement

354After Incident
CRITICAL-231
COM1785580087
Comcast Xfinity Data Breach Settlement Reaches $117.5 Million Comcast has agreed to a $117.5 million class action settlement to resolve claims stemming from a cybersecurity incident in October 2023 that exposed the personal data of millions of Xfinity customers. While the company denies any wrongdoing, the settlement aims to avoid prolonged litigation. Eligible customers those who received a breach notification around December 18, 2023 can file claims for compensation, including: - Up to $10,000 for documented out-of-pocket losses tied to the breach. - Reimbursement for time spent addressing breach-related issues. - A cash payment (estimated at ~$50) for those without documented losses, though the final amount depends on claim volume. Additionally, settlement class members may receive identity theft protection and restoration services pending final court approval. The claim deadline is September 14, 2026, with submissions accepted online or by mail. Customers who lost their notification letter can verify eligibility via the settlement website’s ID lookup tool. The final approval hearing is scheduled for August 5, 2026, after which valid claimants will receive benefits as outlined in the settlement terms. The breach highlights the ongoing risks of large-scale data exposures and the financial repercussions for affected companies.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $117.5 million (settlement amount)Data Compromised: Personal data of millions of Xfinity customersLegal Liabilities: Class action settlementIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personal dataNumber Of Records Exposed: MillionsSensitivity Of Data: HighPersonally Identifiable Information: Yes
OCTOBER 2023
589Before Incident
Vulnerability
16 Oct 2023 • Citrix
Comcast Cable Communications

Xfinity Data Breach via Citrix Software Vulnerability

585After Incident
CRITICAL-4
COM020090625
The Vermont Office of the Attorney General disclosed that Xfinity suffered a data breach stemming from a vulnerability in Citrix’s software, enabling unauthorized access between October 16–19, 2023. The exposed data included usernames, hashed passwords, full names, contact details, the last four digits of Social Security numbers, dates of birth, and secret questions/answers. While the breach did not involve full Social Security numbers or financial data, the compromised credentials and personal identifiers pose significant risks, including identity theft, phishing attacks, and account takeovers. The incident was publicly reported on December 18, 2023, highlighting delays in detection and disclosure. The breach’s scope suggests potential long-term reputational damage and regulatory scrutiny, particularly given the sensitivity of the leaked information and the scale of Xfinity’s customer base.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
usernameshashed passwordsnamescontact informationlast four digits of Social Security numbersdates of birthsecret questions and answersIdentity Theft Risk: High (PII exposed)
DATA BREACH
Personally Identifiable Information (PII)Authentication CredentialsSensitivity Of Data: HighData Exfiltration: Likely (unauthorized access confirmed)Data Encryption: Partially (hashed passwords)
OCTOBER 2023
588Before Incident
Breach
10 Oct 2023 • Citrix
Comcast Cable Communications LLC: Comcast Will Pay $117.5M Over Xfinity Data Breach: How To File A Claim

Comcast Data Breach Settlement: 31.6–35 Million Customers Affected

524After Incident
CRITICAL-64
COM1776178473
Comcast Data Breach Settlement: 31.6–35 Million Customers Affected A major data breach at Comcast Cable Communications LLC exposed sensitive information of 31.6 to 35 million customers, including usernames, hashed passwords, contact details, and partial Social Security numbers. The breach, caused by a software vulnerability, occurred in October 2023 and was reported by the company in December 2023. The incident led to a class-action lawsuit, Hasson v. Comcast Cable Communications LLC, alleging inadequate data protection. While Comcast denies wrongdoing, a settlement has been reached to resolve claims. Affected customers who received a breach notice are eligible for compensation, with two options: - $50 cash payment for those impacted. - Up to $150 for reimbursement of lost time (up to 3 hours at $30/hour) or documented out-of-pocket expenses tied to the breach. Claims must be submitted by August 14, 2024, via the official settlement website or mail to Hasson v. Comcast Cable Communications LLC, c/o Kroll Settlement Administration LLC. A final hearing to approve the settlement is set for July 7, 2024, with payments expected later this year. The case underscores the financial and reputational risks companies face due to cybersecurity failures.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: Settlement payouts (up to $150 per affected customer)Data Compromised: Usernames, hashed passwords, contact details, partial Social Security numbersCustomer Complaints: Class-action lawsuit (Hasson v. Comcast Cable Communications LLC)Brand Reputation Impact: Reputational risks due to cybersecurity failuresLegal Liabilities: Class-action settlementIdentity Theft Risk: High (partial Social Security numbers exposed)
DATA BREACH
UsernamesHashed passwordsContact detailsPartial Social Security numbersNumber Of Records Exposed: 31.6–35 millionSensitivity Of Data: HighData Encryption: Hashed passwordsPersonally Identifiable Information: Yes
JULY 2023
579Before Incident
Vulnerability
01 Jul 2023 • Citrix
Fortinet, Veeam and Citrix: INC Ransomware Uses LOLBins, RMM Tools, and rclone for Network Intrusion and Data Exfiltration

INC Ransomware Attack

575After Incident
CRITICAL-4
VEEFORCIT1781857680
INC Ransomware: A Rapidly Evolving Threat Targeting Global Organizations Since its emergence in mid-2023, the INC ransomware group has established itself as a formidable Ransomware-as-a-Service (RaaS) operation, claiming over 800 victims worldwide. The group employs aggressive double-extortion tactics, targeting high-profile organizations primarily in the U.S., with a focus on the legal, manufacturing, technology, and healthcare sectors. INC’s attack methods are both diverse and sophisticated. Initial access is often gained through spear-phishing, compromised credentials from access brokers, or exploitation of known vulnerabilities in public-facing systems, including Citrix NetScaler (CVE-2023-3519), Fortinet EMS (CVE-2023-48788), and Citrix Bleed 2 (CVE-2025-5777). Once inside, attackers use command-line tools and IP scanners to map the network before deploying a customized PowerShell script that extracts credentials from Veeam backup servers via salted DPAPI decryption. The group’s ransomware payloads, rewritten in Rust, enable cross-platform attacks on both Windows and Linux/ESXi environments. On Windows, the malware employs multithreading and partial encryption to accelerate data destruction while avoiding critical system files ensuring victims can still view ransom notes on desktops and network printers. On Linux and VMware ESXi servers, the payload shuts down virtual machines before encrypting them, maximizing disruption. INC’s encryption scheme combines Curve25519 Elliptic Curve Cryptography and AES-128, making recovery without the decryption key nearly impossible. The group operates a dual-site extortion model, using a private portal for negotiations and a public leak site to pressure non-compliant victims. Their rapid evolution and technical sophistication underscore the growing threat posed by modern ransomware operations.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (Ransomware-as-a-Service)
IMPACT
Data Compromised: Credentials, backup data, virtual machines, and sensitive filesWindowsLinux/ESXi environmentsOperational Impact: Shutdown of virtual machines, encryption of critical data, disruption of servicesBrand Reputation Impact: High (due to public leak site and double-extortion tactics)Identity Theft Risk: High (if personally identifiable information was compromised)
DATA BREACH
CredentialsBackup dataVirtual machine dataSensitive filesSensitivity Of Data: High (credentials, PII potential)Data Exfiltration: Yes (double-extortion tactic)Data Encryption: Yes (Curve25519 ECC and AES-128)
JUNE 2023
582Before Incident
Vulnerability
16 Jun 2023 • Citrix
Citrix

Critical Flaw in Citrix NetScaler Devices Echoes Infamous 2023 Security Breach

578After Incident
CRITICAL-4
CIT748070725
Citrix is facing a critical flaw in its NetScaler devices, known as 'CitrixBleed 2' (CVE-2025-5777), which allows attackers to steal sensitive information from device memory. This vulnerability, similar to the 2023 CitrixBleed attacks, has a CVSS severity score of 9.3 and has already been exploited in targeted attacks. The exploitation involves bypassing multi-factor authentication and hijacking user sessions, with evidence of session reuse and Active Directory reconnaissance. The vulnerability affects NetScaler ADC and NetScaler Gateway devices, potentially exposing session tokens and other sensitive data. Security experts urge immediate patching to prevent widespread exploitation, as the original CitrixBleed attacks continued to be exploited for months.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Data Theft, Session Hijacking
IMPACT
Session tokensSensitive informationNetScaler ADCNetScaler Gateway
DATA BREACH
Type Of Data Compromised: Session tokens, Sensitive informationSensitivity Of Data: High
JANUARY 2023
731Before Incident
Breach
01 Jan 2023 • Citrix
Comcast: Comcast’s $117.5M Data Breach Deal Nears Finish Line

Comcast 2023 Data Breach Settlement

560After Incident
CRITICAL-171
COM1769288328
Comcast Nears $117.5M Settlement Over 2023 Data Breach Affecting 30M Customers A federal judge in Pennsylvania’s Eastern District has granted preliminary approval for a $117.5 million settlement in a class-action lawsuit against Comcast, stemming from a 2023 cyber intrusion that potentially exposed sensitive data of over 30 million current and former customers. If finalized, the agreement would resolve two dozen lawsuits filed against the telecommunications giant. Affected customers would receive one of two remedies: - Three years of financial monitoring and identity theft protection, or - A choice between reimbursement for documented losses up to $10,000 or a $50 cash payment. The settlement structure allows for proof-based compensation for those who can demonstrate harm, while others may opt for a flat payout. Comcast, while not opposing the settlement, has denied liability for the breach, disputing the plaintiffs’ claims in court filings. The company has not commented publicly on the matter. The final court review will determine whether the agreement is approved.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $117.5M settlementData Compromised: Sensitive customer dataLegal Liabilities: Class-action lawsuitsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Sensitive customer dataNumber Of Records Exposed: 30 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
MAY 2019
676Before Incident
Cyber Attack
01 May 2019 • Citrix
Citrix

Citrix Server Breach

658After Incident
CRITICAL-18
CIT11910222
An international cybercriminals gang had accessed Citrix servers for about six months. The hackers were able to steal business documents, names, social security numbers, and financial information. The company notified all the impacted customers and secured their servers from any such future attack.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
business documentsnamessocial security numbersfinancial informationCitrix Servers
DATA BREACH
business documentsnamessocial security numbersfinancial informationSensitivity Of Data: Highnamessocial security numbers
MARCH 2019
729Before Incident
Breach
01 Mar 2019 • Citrix
Citrix

Citrix Security Breach

672After Incident
CRITICAL-57
CIT907323
American software company Citrix disclosed that they have been hit by a security breach during which hackers accessed the company's internal network. It was found that hackers accessed and downloaded business documents, but Citrix wasn't able to identify what specific documents had been stolen. According to the Citrix executive, there is no proof that hackers may have tampered with Citrix's official software or other goods.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
business documents
DATA BREACH
business documents
OCTOBER 2018
778Before Incident
Breach
13 Oct 2018 • Citrix
Citrix Systems, Inc.

Data Breach at Citrix Systems, Inc.

724After Incident
HIGH-54
CIT258072625
The California Office of the Attorney General reported a data breach involving Citrix Systems, Inc. on April 29, 2019. The breach occurred between October 13, 2018, and March 8, 2019, potentially affecting personal information of current and former employees, including names, Social Security numbers, and financial information. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security numbersfinancial information
DATA BREACH
namesSocial Security numbersfinancial informationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Citrix ?
?
What was Citrix's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Citrix's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Citrix ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Citrix's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?