Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Citrix

Citrix Vendor Cyber Rating & Cyber Score

bit.ly

When we pioneered remote access, we believed people should be able to work anywhere and in any way they need. Three decades later, that’s even more true than ever. It’s what drives us to create technology that transcends the constraints of time, place, infrastructure, networks, and devices. And it’s the reason thousands of organizations around the world trust us to keep their apps available, their data safe, and their people productive—wherever and whenever work happens. Citrix is now part of Cloud Software Group. To learn more and see current career openings, visit cloud.com.


Citrix A.I CyberSecurity Scoring

Citrix
Company Information
Website:https://bit.ly/478vsm3
Employees number:4,219
Number of followers:586,262
NAICS:5112
Industry Type:Software Development
Homepage:bit.ly
Citrix Risk Score (AI oriented)
Between 0 and 549
logo
CitrixSoftware Development
Updated:
04/08/2026
310/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Citrix Global Score (TPRM)
xxxx
logo
CitrixSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Citrix
CitrixCritical
Current Score
310C (CRITICAL)
01000
25 incidents
-28.09 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
314Before Incident
Vulnerability
04 Aug 2026Citrix
SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation

311After Incident
CRITICAL-3
SAPFORVBUCITSONSOPHIK1785846368
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries. ### Attack Methodology The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept (PoC) code, though some were modified for the operation. Once inside a network, the attacker: - Deployed web shells and network tunnels to move laterally. - Harvested NTLM password hashes, credential stores, and browser secrets. - Compromised Active Directory (AD), extracting Kerberos ticket-granting keys to forge long-term authentication tokens. - In some cases, achieved full domain control, enabling ransomware groups to later encrypt systems. ### Shift to Espionage: Ukraine in the Crosshairs While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker: - Deployed Sliver command-and-control (C2) tooling. - Accessed exposed source-code repositories. - Collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure. CloudSEK assessed with moderate-to-high confidence that this phase served Russian state-linked intelligence needs, though it remains unclear whether the actor was directly tasked or sold the data to a state customer. ### Shared Infrastructure and Defensive Recommendations The same VPS servers, tunnels, and tooling were used for both criminal and espionage activities, highlighting the blurred lines between cybercrime and state-sponsored operations. Organizations are advised to: - Remove administrative interfaces from direct internet exposure. - Patch vulnerable appliances immediately. - Rotate credentials and review unauthorized logins, SSH keys, and device settings. - Isolate IP cameras from public networks and replace default passwords. ### Indicators of Compromise (IoCs) CloudSEK provided key IoCs, including: - IPv4 addresses linked to operator VPS, jumpboxes, and C2 infrastructure. - SHA-256 hashes for Sliver Linux implants and malicious drivers used in credential theft. The case underscores the dual threat posed by initial access brokers facilitating both ransomware attacks and state-aligned espionage while reinforcing the risks of unpatched edge devices and exposed credentials.
INCIDENT DETAILS -
TYPE
CybercrimeEspionage
MOTIVATION
Financial gainState-aligned intelligence collection
IMPACT
Data Compromised: NTLM password hashes, credential stores, browser secrets, Kerberos ticket-granting keys, source-code repositories, images from IP cameras, remote desktop screenshotsSystems Affected: Networks across education, healthcare, financial services, telecommunications, government, defense, and aerospace sectorsOperational Impact: Full domain control achieved in some cases, enabling ransomware deploymentIdentity Theft Risk: High (due to credential harvesting)
DATA BREACH
NTLM password hashesCredential storesBrowser secretsKerberos ticket-granting keysSource-code repositoriesImages from IP camerasRemote desktop screenshotsSensitivity Of Data: High (personally identifiable information, authentication tokens, military logistics data)Data Exfiltration: Yes (data sold on dark web in some cases)ImagesSource codeScreenshotsPersonally Identifiable Information: Yes (credentials, authentication tokens)
JULY 2026
310Before Incident
Vulnerability
10 Jul 2026Citrix
Citrix and Progress Software: URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat

307After Incident
CRITICAL-3
CITPRO1783931784
Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat Progress Software has instructed customers to immediately take offline all Windows servers running ShareFile Storage Zone Controllers, citing a "credible external security threat." The company disabled access to affected accounts as a precautionary measure while collaborating with internal and external security experts to investigate the incident. The disruption came to light on July 10 after a customer shared Progress’s advisory on Reddit’s r/sysadmin. Progress later confirmed the issue on its status page, marking Storage Zone Controllers as "not operational" and the incident as under active investigation. The company has not disclosed the nature of the threat, its origin, or whether any data has been compromised though it stated there is no evidence of unauthorized access to ShareFile accounts or cloud-stored data. The Storage Zone Controller, a self-hosted component that allows organizations to retain files on their own infrastructure while using ShareFile’s cloud for management, is the sole affected system. Unlike standard cloud-only ShareFile accounts, these controllers are typically exposed to the internet, increasing their vulnerability. Progress’s decision to mandate a full shutdown rather than issuing a patch suggests the threat may involve an unpatched zero-day flaw, stolen credentials, or an issue within Progress’s own systems. Customers are advised to keep controllers offline until further notice and verify they are running ShareFile Storage Zones Controller version 5.12.4 or later (5.x line) or any 6.x release, which address previously disclosed vulnerabilities. However, Progress has not confirmed whether these updates mitigate the current threat. Organizations with internet-exposed controllers should treat the situation as a potential incident, preserve logs, and scan for unauthorized .aspx files in web directories and storage paths. This is not the first time the Storage Zone Controller has been targeted. In 2023, while under Citrix’s ownership, attackers exploited CVE-2023-24489, an unauthenticated flaw in the same component. The vulnerability was actively exploited, prompting Citrix to sever unpatched controllers from the ShareFile cloud a step Progress has now replicated. Progress itself faced a major breach last year via the MOVEit file-transfer zero-day, which the Clop ransomware group leveraged to compromise over 2,700 organizations. As of now, Progress has not provided a timeline for resolution or details on the threat’s specifics, leaving customers in limbo regarding when they can safely restore operations.
INCIDENT DETAILS -
TYPE
Security Threat
IMPACT
Systems Affected: ShareFile Storage Zone ControllersDowntime: Not operationalOperational Impact: Mandated shutdown of affected systems
DATA BREACH
File Types Exposed: .aspx files
JULY 2026
312Before Incident
Vulnerability
01 Jul 2026Citrix
Citrix: CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure

CitrixBleed-Class Vulnerability (CVE-2026-8451) Exploited Within Hours of Disclosure

308After Incident
CRITICAL-4
CIT1783016843
CitrixBleed-Class Vulnerability Exploited Within Hours of Disclosure A newly disclosed CitrixBleed-class vulnerability (CVE-2026-8451) in Citrix NetScaler appliances was actively exploited less than 24 hours after public disclosure, according to decoy infrastructure operator Lupovis. The flaw, part of a recurring series of memory-disclosure bugs in NetScaler’s SAML authentication parser, was targeted in a coordinated scanning campaign between 30 June and 1 July 2026. A threat actor operating from IP 146.70.139[.]154 hosted on M247 Europe SRL (AS9009) infrastructure in Frankfurt, Germany probed three Lupovis sensors over a five-hour window. After receiving a 200 response from one sensor, the attacker delivered a confirmed CVE-2026-8451 exploitation payload, mirroring tactics observed in prior CitrixBleed incidents. The vulnerability affects NetScaler ADC/Gateway versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18 when configured as a SAML Identity Provider (IdP). It stems from a flaw in NetScaler’s XML parser, which fails to properly terminate unquoted attribute values, leading to an out-of-bounds memory read that exposes session tokens via the NSC_TASS cookie. The exploit payload, sent to POST /saml/login, consisted of a malformed <samlp:AuthnRequest> tag padded with 476 spaces a pattern designed to force the parser to read beyond its buffer. This technique aligns with the Detection Artifact Generator released by watchTowr Labs alongside Citrix’s advisory (CTX696604). Notably, CVE-2026-8451 remains absent from CISA’s Known Exploited Vulnerabilities (KEV) catalog, despite active exploitation a repeat of past CitrixBleed incidents where in-the-wild attacks preceded formal KEV listings by weeks. Previous flaws in this family, such as CVE-2023-4966 (original CitrixBleed), led to high-profile breaches at Boeing, ICBC, and DP World within weeks of disclosure. The attacker’s tooling, identified by the python-requests/2.32.5 User-Agent, validated targets before deploying payloads, a behavior consistent with opportunistic mass exploitation. The rapid exploitation underscores the persistent risk posed by CitrixBleed-style vulnerabilities, particularly for organizations relying solely on KEV-driven patch prioritization.
INCIDENT DETAILS -
TYPE
Memory Disclosure Vulnerability Exploitation
MOTIVATION
Opportunistic mass exploitation
IMPACT
Data Compromised: Session tokens (NSC_TASS cookie)Systems Affected: Citrix NetScaler ADC/Gateway (SAML IdP configurations)Identity Theft Risk: High (session token exposure)
DATA BREACH
Type Of Data Compromised: Session tokensSensitivity Of Data: High (session hijacking risk)Personally Identifiable Information: Session tokens (indirect PII risk)
JUNE 2026
407Before Incident
Ransomware
01 Jun 2026Citrix
Fortinet, Check Point, Palo Alto and Citrix: Ransomware groups are hammering your vulnerable VPNs

Ransomware Groups Exploit VPNs and Edge Devices as Prime Entry Points into Corporate Networks

303After Incident
CRITICAL-104
CHEFORPALCIT1784881580
Ransomware Groups Exploit VPNs and Edge Devices as Prime Entry Points into Corporate Networks Cybercriminals, including ransomware-as-a-service (RaaS) operators and nation-state-backed advanced persistent threat (APT) groups, are increasingly targeting internet-facing VPNs and edge devices to breach corporate networks. According to cybersecurity experts, these systems often exposed to the internet provide attackers with a direct gateway into an organization’s infrastructure, bypassing endpoint security controls. Key Attack Vectors and Trends - Stolen Credentials Over Exploits: While unpatched vulnerabilities remain a concern, attackers more frequently abuse compromised credentials to access non-MFA-protected accounts. Huntress reports that VPNs account for 70% of initial access in advanced threat actor campaigns, with stolen credentials being the primary method. - Ransomware Operations: Groups like Qilin and Akira leverage VPN and firewall flaws particularly in products from Palo Alto, Fortinet, Citrix, and Check Point to deploy ransomware. Post-exploitation tactics vary, from rapid encryption to double-extortion schemes, suggesting multiple affiliates operate under RaaS models. - Zero-Day Exploits: Recent campaigns highlight the exploitation of CVE-2024-3400 in Palo Alto’s GlobalProtect VPN and vulnerabilities in FortiGate, Citrix NetScaler, and Check Point devices. Attackers prioritize internet-facing assets with known active exploits, leaving organizations with minimal time to patch. Industry Impact and Mitigation Challenges - Rising Threat Trajectory: Despite no significant spike in ransomware volume in Q2 2026, attacks continue to escalate, with VPNs and edge devices remaining high-value targets. NCC Group’s threat report ranks Qilin as the second-most active ransomware group (238 victims) and Akira fourth (127 victims) for the quarter. - Security Gaps: Edge devices are particularly vulnerable due to their continuous internet exposure and privileged access. Experts warn that delayed patching especially for critical updates creates a narrow window for attackers to strike before defenses are fortified. - Defensive Strategies: Recommended measures include zero-trust network segmentation, phishing-resistant MFA, aggressive patch management (applying updates within 24–48 hours), and monitoring for unusual authentication activity. However, the shift toward convenience over containment in enterprise networks exacerbates lateral movement risks. The trend underscores a persistent challenge: while vulnerabilities in perimeter devices are lucrative for attackers, the abuse of legitimate credentials remains the dominant and often overlooked threat vector.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial GainData ExfiltrationDouble Extortion
IMPACT
VPNsEdge DevicesFirewalls
DATA BREACH
Data Exfiltration: Yes (Double Extortion Schemes)Data Encryption: Yes (Ransomware Encryption)
Vulnerability
01 Jun 2026Citrix
Citrix, Kontron, The Gentlemen RaaS Victims and Anubis Ransomware Victims: Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors

303After Incident
CRITICAL-104
CITGUIKONARC1783031139
Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors Threat actors linked to the Anubis ransomware-as-a-service (RaaS) operation are actively exploiting CVE-2025-5777 (Citrix Bleed 2), a critical vulnerability in Citrix NetScaler ADC and Gateway, to gain initial access to victim networks. According to a report by Arctic Wolf, attackers leverage legitimate Remote Management and Monitoring (RMM) tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment to blend in with normal IT activity while maintaining persistent control. Anubis, a rebrand of the Sphinx ransomware, emerged in late 2024 and was formally announced on the RAMP underground forum in February 2025. Since then, the group has claimed 91 victims on its data leak site, with 11 reported in June 2026 alone. Targeted sectors include healthcare, business services, manufacturing, technology, and financial services, with over 50% of victims based in the U.S., followed by the U.K., Australia, France, and Canada. The group employs aggressive tactics, including an irreversible data-wiping feature that reduces files to 0 KB regardless of ransom payment, increasing pressure on victims. Affiliates receive 80% of ransom payments, a lucrative incentive that has fueled the operation’s growth. Beyond Citrix Bleed 2, Anubis actors have also used stolen VPN credentials potentially sourced from initial access brokers, credential stuffing, or info-stealer malware to breach networks via Cisco AnyConnect VPNs, particularly through hosting providers like AS20473 (The Constant Company) and AS55286 (ServerMania). Once inside, attackers move laterally using RDP and PsExec, deploy RMM tools for persistence, and exfiltrate data via Cloudflare Tunnels, S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. They also disable security defenses, including Windows Defender and Sophos, and manipulate logs to hinder forensic analysis. In some cases, the ransomware encryptor is deleted post-execution, further complicating detection. ### The Gentlemen RaaS and Zero-Day Exploits Separately, Kaspersky detailed The Gentlemen RaaS, which exploits known vulnerabilities and weak credentials to deploy a Go-based backdoor for remote command execution. The malware collects system data, exfiltrates it to 81.177.215[.]15:9443, and can establish a SOCKS proxy for network pivoting. The group has also weaponized a zero-day vulnerability in ktapi.sys, a Kontron driver, to bypass Windows security protections and terminate processes from Microsoft, ESET, Palo Alto Networks, and SentinelOne. ### VECT and TeamPCP’s Supply Chain-Ransomware Hybrid A Sophos investigation revealed a partnership between VECT and TeamPCP, announced in March 2026, combining supply chain credential theft with ransomware deployment. TeamPCP, previously operating as CipherForce, rebranded after listing six victims in February 2026. However, VECT’s encryptor contains critical flaws, destroying files larger than 128 KB instead of encrypting them a defect TeamPCP claims it never used in attacks. The alliance represents a shift toward industrialized ransomware deployment, lowering the barrier for cybercriminals by merging large-scale supply chain attacks with mature RaaS operations. Despite technical shortcomings, the model poses a growing threat to enterprises.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData exfiltrationExtortion
IMPACT
Citrix NetScaler ADC and GatewayVPN systems (Cisco AnyConnect)Windows systemsOperational Impact: Disruption of services, lateral movement within networks, disabling of security defenses
DATA BREACH
Personally identifiable informationPayment informationSensitive corporate dataSensitivity Of Data: High
MAY 2026
407Before Incident
Vulnerability
16 May 2026Citrix
Citrix and BlackCat: MSN

Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability

403After Incident
CRITICAL-4
CITBLA1778977440
Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability A recent cyberattack has disrupted operations across multiple U.S. healthcare providers, with the ransomware group BlackCat (ALPHV) exploiting a previously unknown zero-day vulnerability in Citrix NetScaler ADC and Gateway systems. The flaw, tracked as CVE-2023-4966 (dubbed "Citrix Bleed"), allows attackers to bypass authentication and gain unauthorized access to sensitive networks. The attack, detected in late October 2023, targeted hospitals, clinics, and medical billing firms, leading to delayed patient care, system outages, and data exposure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the vulnerability’s active exploitation, warning that threat actors could steal session tokens to maintain persistent access even after patches are applied. BlackCat, known for its double-extortion tactics, has demanded ransoms ranging from $1 million to $10 million per victim. While some organizations have restored systems from backups, others remain locked out of critical infrastructure. The incident underscores the growing risk of zero-day exploits in healthcare, where legacy systems and high-value data make providers prime targets. Citrix released emergency patches on October 10, 2023, urging all users to update immediately. However, CISA’s advisory notes that compromised credentials may still pose a threat, requiring additional mitigation steps, including credential resets and network segmentation. The full scope of affected entities remains unclear, though reports indicate at least dozens of organizations have been impacted.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware), Data exfiltration
IMPACT
Data Compromised: Session tokens, sensitive healthcare dataSystems Affected: Citrix NetScaler ADC and Gateway systemsDowntime: Delayed patient care, system outagesOperational Impact: Disrupted healthcare operationsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Session tokens, sensitive healthcare dataSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Likely
MAY 2026
407Before Incident
Vulnerability
01 May 2026Citrix
Citrix, Microsoft, Apache Software Foundation and Langflow: Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Chinese Threat Actor Leverages AI for Autonomous Cyberattacks

403After Incident
CRITICAL-4
MICTHESECCIT1785522270
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks Researchers at Palo Alto Networks’ Unit 42 have uncovered a campaign by a China-based threat actor using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks with minimal human oversight. The actor, operating under the aliases "knaithe" and "KnYuan," identifies as a "binary security researcher." The discovery stemmed from an accidental exposure of the attacker’s environment after Hermes created a misconfigured web server, revealing API keys, exploit scripts, target lists, shell history, and AI attack logs. While the observed attacks did not successfully compromise targets, they demonstrated a fully autonomous offensive AI workflow capable of identifying, evaluating, and exploiting vulnerabilities. ### AI-Powered Attack Workflow The threat actor deployed DeepSeek as the reasoning engine behind Hermes Agent, an AI framework that interacts with operating systems, executes commands, and connects to the internet. Hermes was configured to: - Receive instructions via Telegram - Use custom offensive-security tools - Query FOFA, an internet asset search engine - Operate in "Yolo" mode, executing commands without prior approval In a recovered session from May 2026, the agent autonomously: 1. Targeted Langflow servers vulnerable to CVE-2026-33017, scanning 84 exposed instances but failing to exploit them. 2. Switched to n8n workflow automation, identifying 647,000 exposed instances and attempting to exploit CVE-2026-21858 and CVE-2025-68613 though authentication requirements prevented successful breaches. 3. Analyzed public exploit repositories and executed hundreds of hours of manual targeting analysis in minutes, managing its own compute resources. ### Manual Attacks & Successful Compromises While the AI-driven attacks were largely unsuccessful, the threat actor also conducted manual attacks on 460+ systems, exploiting vulnerabilities in: - Citrix NetScaler (CVE-2026-3055) – Used in three confirmed breaches to extract memory and harvest authentication cookies. - Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others. Additional AI platforms (Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) were configured but rarely used. ### Previous Hermes Incident in Thailand This campaign follows a separate incident where poorly secured Hermes infrastructure exposed details of an alleged cyberattack on Thailand’s Ministry of Finance. Logs revealed Hermes operating in unattended "YOLO" mode, automating post-exploitation tasks such as: - Privilege escalation checks - Service enumeration - File system traversal - Document cataloging Unlike the autonomous attacks observed by Unit 42, the Thailand incident involved human-directed targeting, with Hermes only automating post-compromise activity. ### Significance of the Campaign Unit 42 highlights the evolution of AI-driven cyber threats, where autonomous agents can: - Research vulnerabilities independently - Prioritize targets - Download and execute exploits - Adapt attack strategies in real time While this campaign had limited success, it underscores the growing sophistication of offensive AI in cyber operations.
INCIDENT DETAILS -
TYPE
AI-driven cyberattackManual exploitation
IMPACT
Authentication cookies (Citrix NetScaler breaches)Systems Affected: 460+ systems (including Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN)
DATA BREACH
Authentication cookiesSensitivity Of Data: High (authentication credentials)
APRIL 2026
405Before Incident
MARCH 2026
402Before Incident
Vulnerability
23 Mar 2026Citrix
Cloud Software Group: Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group

398After Incident
CRITICAL-4
CLO1774312166
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group Cloud Software Group has released emergency security updates for NetScaler ADC and NetScaler Gateway, addressing two high-severity vulnerabilities that could enable unauthenticated remote attacks on affected systems. The most critical flaw, CVE-2026-3055 (CVSS 9.3), is an out-of-bounds read vulnerability in SAML Identity Provider (IDP) configurations. Exploitable without authentication or user interaction, it allows attackers to trigger memory overreads, potentially leading to system compromise. The issue was discovered internally, with no evidence of active exploitation at the time of disclosure. Administrators can check for exposure by verifying SAML IDP configurations in NetScaler settings. The second vulnerability, CVE-2026-4368 (CVSS 7.7), involves a race condition causing session mixups in appliances configured as Gateways (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual servers. While exploitation requires low-privilege authentication and precise timing, successful attacks could fully compromise session confidentiality and integrity. Affected Versions & Patches: - CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and FIPS/NDcPP before 13.1-37.262. - CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54. Fixed releases include 14.1-66.59 or later, 13.1-62.23 or later, and 13.1-FIPS/NDcPP 13.1.37.262 or later. The patches apply only to customer-managed deployments, as Citrix-managed cloud services and Adaptive Authentication instances have already been updated. Given NetScaler’s widespread use in enterprise VPN and application delivery, unpatched systems pose a significant risk. Security teams are advised to prioritize updates, particularly for SAML IDP-configured appliances.
INCIDENT DETAILS -
TYPE
Vulnerability Disclosure
IMPACT
Systems Affected: NetScaler ADC and NetScaler Gateway appliancesOperational Impact: Potential system compromise, session confidentiality and integrity risks
FEBRUARY 2026
393Before Incident
Vulnerability
01 Feb 2026Citrix
Citrix: Threat Actors Conduct Widespread Scanning for Exposed Citrix NetScaler Login Pages

Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered

389After Incident
CRITICAL-4
CIT1770201552
Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered A sophisticated reconnaissance campaign targeting Citrix ADC (NetScaler) Gateway infrastructure has been detected, involving over 63,000 residential proxy IPs and AWS cloud instances to map login panels and enumerate software versions. The operation, which generated 111,834 scanning sessions, was highly targeted 79% of traffic focused on Citrix Gateway honeypots indicating deliberate pre-exploitation preparation rather than random scanning. The campaign unfolded in two phases: 1. Login Panel Discovery (Primary Phase) - 109,942 sessions from 63,189 unique IPs probed the `/logon/LogonPoint/index.html` authentication interface. - 64% of traffic originated from residential proxies across Vietnam, Argentina, Mexico, Algeria, and Iraq, while a single Microsoft Azure IP in Canada accounted for 36%. - Threat actors used unique browser fingerprints and residential proxies to evade geographic and reputation-based blocking. 2. Version Disclosure Sprint (AWS Phase) - On February 1, 2026, 10 AWS instances in us-west-1/us-west-2 executed a six-hour scan, sending 1,892 requests to `/epa/scripts/win/nsepa_setup.exe` to identify Citrix Endpoint Analysis (EPA) versions. - Activity peaked at 362 sessions around 02:00 UTC before tapering off by 05:00 UTC. - All requests used an outdated Chrome 50 user agent (2016) and uniform HTTP fingerprints, suggesting a coordinated effort to exploit known vulnerabilities. Researchers from GreyNoise noted the focus on the EPA setup file path indicates potential interest in version-specific exploits, particularly given recent critical Citrix vulnerabilities: - CVE-2025-5777 ("CitrixBleed 2") - CVE-2025-5775 (remote code execution, exploited as a zero-day). Detection and Indicators of Compromise (IOCs) - User agents: `blackbox-exporter` (unauthorized sources), Chrome 50 (2016) - Targeted paths: `/logon/LogonPoint/`, `/epa/scripts/win/nsepa_setup.exe` - AWS IPs (Version Disclosure): `44.251.121.190, 13.57.253.3, 50.18.232.85, 52.36.139.223, 54.201.20.56, 54.153.0.164, 54.176.178.13, 18.237.26.188, 54.219.42.163, 18.246.164.162` - Azure IP (Login Panel Discovery): `52.139.3.76` The campaign’s scale and precision suggest threat actors are actively preparing for potential exploitation, likely targeting unpatched or misconfigured Citrix ADC deployments.
INCIDENT DETAILS -
TYPE
Reconnaissance
MOTIVATION
Pre-exploitation preparation
IMPACT
Systems Affected: Citrix ADC (NetScaler) Gateway infrastructure
JANUARY 2026
393Before Incident
DECEMBER 2025
379Before Incident
NOVEMBER 2025
372Before Incident
Vulnerability
01 Nov 2025Citrix
Citrix and VMware: Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware

Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft

368After Incident
CRITICAL-4
CITVMW1776702564
Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft Cybercriminals are increasingly abusing QEMU, a legitimate open-source virtualization tool, to bypass endpoint security and deploy ransomware or steal credentials undetected. By running malicious operations inside hidden virtual machines (VMs), attackers exploit a critical blind spot security tools on the host system cannot inspect activity within the VM, leaving minimal forensic traces. Sophos researchers have identified two active campaigns leveraging this technique since late 2025: 1. STAC4713 (November 2025) – Linked to the PayoutsKing ransomware group (GOLD ENCOUNTER), which operates independently (not as a ransomware-as-a-service). The group targets VMware and ESXi hypervisors, using QEMU to execute attacks. The infection chain begins with a scheduled task ("TPMProfiler") running QEMU under the SYSTEM account, booting from a disguised virtual disk (initially vault.db, later bisrv.dll). The VM establishes a reverse SSH tunnel via custom ports (32567, 22022) to port 22, creating a persistent backdoor. Tools inside the VM include AdaptixC2, Linker2, and a WireGuard obfuscator (wg-obfuscator). 2. STAC3725 (February 2026) – Exploits the CitrixBleed2 vulnerability (CVE-2025-5777) for initial access, then deploys a malicious ScreenConnect client for persistence. Attackers manually compile a toolkit inside the QEMU VM, including Impacket, KrbRelayX, BloodHound.py, NetExec, and Metasploit, to harvest credentials, enumerate Active Directory, and stage payloads via FTP. Both campaigns demonstrate a growing trend of virtualization-based evasion, where trusted tools like QEMU are repurposed to conceal malicious activity. The technique’s stealth and lack of detectable artifacts make it particularly challenging for defenders to identify and mitigate in real time.
INCIDENT DETAILS -
TYPE
ransomwarecredential theft
MOTIVATION
financial gaincredential harvesting
IMPACT
credentialsActive Directory enumeration dataVMware and ESXi hypervisorsWindows systems with QEMUIdentity Theft Risk: high
DATA BREACH
credentialsActive Directory dataSensitivity Of Data: highData Encryption: yes (ransomware)
OCTOBER 2025
540Before Incident
Breach
19 Oct 2025Citrix
F5

Oracle E-Business Suite Remotely Exploitable Vulnerability (CVE-2025-61884)Microsoft Zero-Day Exploits (CVE-2025-24990, CVE-2025-59230, CVE-2025-47827)F5 Data Breach: Nation-State Attackers Stole BIG-IP Source CodeAdobe Experience Manager 'Perfect' Vulnerability (CVE-2025-54253)Microsoft Revokes 200 Certificates Used for Malicious Teams Installers (Vanilla Tempest Ransomware)Cisco Zero-Day Rootkit Deployment on Network Switches (CVE-2025-20352)U.S. Seizes $15B in Bitcoin Linked to Forced-Labor Crypto ScamUnitree G1 Humanoid Robot Bluetooth Vulnerability (Espionage Risk)Healthcare Cybersecurity Breakdown: 93% of U.S. Organizations Attacked (Patient Care Disruptions)

369After Incident
CRITICAL-171
F50032500101925
US tech company F5 confirmed a data breach in which nation-state attackers stole the source code and vulnerability information related to its BIG-IP family of networking and security products. BIG-IP is a critical infrastructure component used by enterprises for traffic management, load balancing, and security, making this breach particularly severe. The stolen data could enable adversaries to identify and exploit undiscovered flaws in BIG-IP systems, potentially leading to supply-chain attacks, unauthorized network access, or large-scale disruptions in organizations relying on F5’s solutions. The breach underscores the escalating risks of state-sponsored cyber espionage targeting foundational IT infrastructure, with implications for global cybersecurity resilience. F5 has not disclosed whether customer data was compromised, but the theft of proprietary code and vulnerability details poses a long-term threat to its product ecosystem and the broader digital supply chain.
INCIDENT DETAILS -
TYPE
VulnerabilityZero-Day ExploitsData BreachVulnerabilityMalware Distribution (Ransomware)Zero-Day Exploit (Rootkit)Cryptocurrency FraudHardware Vulnerability (Espionage)Cyberattack Campaign (Healthcare)
MOTIVATION
Cyber Espionage (Source Code Theft)Financial Gain (Ransomware)Financial Gain (Crypto Fraud)Espionage/Data Theft
IMPACT
$15 billion (Seized)BIG-IP Source Code & Vulnerability InfoRobot Sensor/Data LeaksOracle E-Business SuiteMicrosoft Products (Multiple)F5 BIG-IP Networking/Security ProductsAdobe Experience Manager (JEE)Microsoft Teams (Malicious Installers)Cisco Network Switches (IOS/IOS XE)Cryptocurrency Wallets/ExchangesUnitree G1 Humanoid RobotsPatient Care Disruptions (72% of Incidents)Source Code Integrity RiskMalware Distribution InfrastructureNetwork Compromise (Rootkits)Fraud Operation ShutdownEspionage Risk (China-Linked)High (Healthcare)High (F5)High (Microsoft)High (Cisco)Severe (Crypto Scam)High (Unitree/Alias Robotics)Severe (Healthcare Sector)Criminal Charges (Forced Labor)HIPAA/Regulatory ViolationsHigh (Patient Data)High
DATA BREACH
Source Code & Vulnerability DetailsRobot Sensor DataHigh (Proprietary Code)High (Espionage Risk)High (PHI/PII)Yes (Source Code)Yes (China-Linked)Likely (Ransomware)Yes (Patient Data)
SEPTEMBER 2025
537Before Incident
AUGUST 2025
535Before Incident
Vulnerability
26 Aug 2025Citrix
Citrix (Cloud Software Group)

Critical Remote Code Execution Flaw (CVE-2025-7775) in Citrix NetScaler ADC and Gateway

531After Incident
CRITICAL-4
CIT806082725
Citrix disclosed a critical zero-day vulnerability (CVE-2025-7775) in its NetScaler ADC and NetScaler Gateway products, actively exploited in the wild as of August 26, 2025. The flaw—a memory overflow bug—enables unauthenticated remote code execution (RCE) on unpatched devices, posing severe risks to organizations relying on these appliances for secure access. While Citrix did not provide indicators of compromise (IoCs), they confirmed exploitation on systems configured as Gateway (VPN, ICA Proxy, RDP Proxy), AAA virtual servers, or specific load-balancing (LB) setups with IPv6 bindings. No mitigations exist, forcing immediate patching to versions 14.1-47.48, 13.1-59.22, or later.The vulnerability’s exploitation could allow attackers to gain full control over affected systems, potentially leading to lateral movement, data exfiltration, or deployment of malware/ransomware. Citrix also patched two other flaws: a DoS vulnerability (CVE-2025-7776) and an improper access control issue (CVE-2025-8424), further compounding risks. Historical context—such as the prior Citrix Bleed 2 (CVE-2025-5777) exploit—highlights the company’s recurring exposure to high-severity attacks targeting memory corruption. Failure to patch could result in widespread breaches, operational disruptions, or supply-chain attacks given NetScaler’s role in enterprise networks.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationZero-Day AttackRemote Code Execution (RCE)Denial of Service (DoS)Improper Access Control
IMPACT
NetScaler ADC (versions 12.1, 13.1, 14.1)NetScaler Gateway (versions 13.1, 14.1)NetScaler ADC 13.1-FIPS and NDcPPNetScaler ADC 12.1-FIPS and NDcPPPotential unauthorized remote code executionDenial of Service (DoS) risksUnauthorized access to management interfacesPotential reputational damage due to zero-day exploitation
JUNE 2025
527Before Incident
Vulnerability
16 Jun 2025Citrix
Citrix

Exploitation of Citrix Vulnerabilities via HexStrike-AI Red Teaming Tool

522After Incident
CRITICAL-5
CIT1555015090425
Cybercriminals are leveraging HexStrike-AI, a legitimate red teaming tool, to automate exploits against Citrix NetScaler ADC and Gateway using recently disclosed vulnerabilities (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424). The tool enables unauthenticated remote code execution (RCE), allowing attackers to deploy webshells and maintain persistent access. While no confirmed breaches are reported yet, the exploitation window has shrunk from days to minutes, drastically reducing the time administrators have to patch systems. The CVE-2025-7775 flaw is already being exploited in the wild, and the use of HexStrike-AI is expected to escalate attack volumes, increasing the risk of unauthorized system takeovers, data exposure, or operational disruptions for organizations relying on Citrix infrastructure. The automation capability of the tool makes manual patch management nearly impossible without dedicated platforms, heightening the urgency for immediate mitigation.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationAutomated AttackUnauthorized Access
MOTIVATION
Financial GainUnauthorized AccessPersistenceData Theft
IMPACT
Citrix NetScaler ADCCitrix NetScaler GatewayReduced Patching WindowIncreased Attack VolumeAutomated ExploitationPotential Reputation Damage for CitrixTrust Erosion in Patch Management
MAY 2025
537Before Incident
Cyber Attack
01 May 2025Citrix
Citrix

Sophisticated Cyberattacks Targeting Critical Infrastructure via Citrix NetScaler Zero-Day Vulnerability

519After Incident
CRITICAL-18
CIT211081225
The Dutch National Cyber Security Centre (NCSC-NL) has issued an urgent warning about sophisticated cyberattacks targeting critical infrastructure through a zero-day vulnerability in Citrix NetScaler devices. The vulnerability, designated CVE-2025-6543, has been actively exploited since early May 2025, compromising several critical organizations across the Netherlands. Attackers gained access to perimeter defenses, demonstrating advanced capabilities by erasing forensic traces and deploying malicious web shells for persistent remote access. The exploitation involved placing suspicious PHP files in system directories, making detection and remediation challenging. The NCSC emphasizes that patching alone is insufficient, as compromised systems may retain attacker access, requiring comprehensive forensic investigation.
INCIDENT DETAILS -
TYPE
Zero-day exploitation
IMPACT
Systems Affected: Citrix NetScaler ADC and Gateway systemsOperational Impact: Significant security breach, access to perimeter defenses
FEBRUARY 2025
586Before Incident
Breach
01 Feb 2025Citrix
Anthropic: Anthropic leaks its own AI coding tool’s source code in second major security breach

Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems

522After Incident
CRITICAL-64
ANT1774981746
Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems Anthropic has inadvertently leaked the source code for Claude Code, its widely adopted AI-powered coding assistant, exposing roughly 500,000 lines of code across 1,900 files. The incident, confirmed by the company as a "release packaging issue" caused by human error, occurred when internal code was mistakenly uploaded to NPM a platform for software distribution instead of the final, compiled version. The leak follows a separate accidental disclosure earlier this month, in which a draft blog post revealed details about Mythos (also referred to as Capybara), an upcoming AI model described as more powerful and potentially more dangerous than Anthropic’s current flagship, Opus. While the latest breach did not expose model weights or customer data, cybersecurity experts warn it could allow competitors to reverse-engineer Claude Code’s underlying "agentic harness" the software layer that governs the AI’s behavior, tool integration, and safety guardrails. This could enable the creation of open-source alternatives or help rivals refine their own AI systems. Security researcher Roy Paz of LayerX Security noted that the leaked code also provided further evidence of Capybara, Anthropic’s next-generation model, which is expected to surpass Opus in capability and cost. The draft blog post previously described it as a new tier, with "fast" and "slow" variants likely replacing Opus as the company’s most advanced offering. Paz highlighted concerns that the exposed code may reveal vulnerabilities in how Claude Code interacts with Anthropic’s internal systems, potentially allowing malicious actors including nation-states to exploit the AI for cyberattacks or bypass existing safeguards. Anthropic’s Opus model is already classified as a high-risk tool due to its ability to autonomously identify zero-day vulnerabilities, a capability that could be weaponized by threat actors. This is not the first time the company has faced such an exposure; in February 2025, an early version of Claude Code was similarly leaked, revealing internal workings and system connections before being removed. The company has stated it is implementing measures to prevent future incidents but has not disclosed further details. The leak underscores the challenges of securing proprietary AI systems as adoption and scrutiny of advanced models continues to grow.
INCIDENT DETAILS -
TYPE
Data Leak
IMPACT
Data Compromised: 500,000 lines of source code across 1,900 filesSystems Affected: Claude Code AI-powered coding assistant, internal AI systemsOperational Impact: Potential reverse-engineering of AI systems by competitors or malicious actorsBrand Reputation Impact: Yes
DATA BREACH
Type Of Data Compromised: Source code, internal AI system detailsNumber Of Records Exposed: 1,900 filesSensitivity Of Data: High (proprietary AI code, agentic harness, internal system connections)File Types Exposed: Source code filesPersonally Identifiable Information: No
JANUARY 2025
591Before Incident
Vulnerability
01 Jan 2025Citrix
F5, Lloyds Banking Group, Citrix, Dutch Ministry of Finance and European Commission: Lloyds Banking Group - Security Affairs

Cybersecurity Roundup: Major Incidents and Emerging Threats

582After Incident
CRITICAL-9
EURF5LLOCITMIN1774989406
Cybersecurity Roundup: Major Incidents and Emerging Threats Recent weeks have seen a surge in high-profile cybersecurity incidents, vulnerabilities, and state-linked attacks targeting governments, financial institutions, and critical infrastructure. Financial Sector Breaches Lloyds Banking Group confirmed a security incident affecting nearly 500,000 mobile customers, though details on the nature of the breach remain undisclosed. Meanwhile, the Dutch Ministry of Finance took treasury systems offline following a cyber incident under investigation. Critical Vulnerabilities Exploited The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw (CVE-2026-3055) to its Known Exploited Vulnerabilities catalog after reports of active exploitation, with attackers probing the bug for potential data leaks. CISA also flagged a critical F5 BIG-IP AMP vulnerability under active attack. Additionally, security agencies warned of a severe flaw in PTC Windchill and FlexPLM, urging organizations to apply patches immediately. State-Sponsored Threats Russia-linked APT TA446 deployed the DarkSword exploit in a phishing campaign targeting iPhone users. China-associated groups launched advanced malware attacks against a Southeast Asian government in early 2025. Meanwhile, an Iran-linked group, Handala, compromised the personal email account of FBI Director Kash Patel, marking a significant escalation in espionage efforts. Ransomware and Supply Chain Attacks The Qilin ransomware group claimed responsibility for breaching Dow Inc., a major chemical manufacturer. Attackers also hijacked the Axios npm account, using it to distribute remote access trojan (RAT) malware to unsuspecting developers. In a separate incident, ShinyHunters asserted responsibility for hacking the European Commission, though the full impact remains unclear. Emerging Threats Apple issued urgent lock screen warnings for unpatched iPhones and iPads, highlighting ongoing risks to mobile security. A new macOS malware, Infinity Stealer, was discovered leveraging Nuitka Python payloads and ClickFix techniques to evade detection. Additionally, a new adversary-in-the-middle (AITM) phishing wave targeted TikTok Business accounts, demonstrating evolving social engineering tactics. Government and Institutional Targets The European Commission confirmed a cyberattack affecting part of its cloud infrastructure, though specifics on the attack vector and scope were not disclosed. These incidents underscore the persistent and evolving nature of cyber threats across sectors.
INCIDENT DETAILS -
TYPE
data_breachransomwarephishingmalwaresupply_chain_attackstate-sponsored_attack
MOTIVATION
espionagefinancial_gaindata_exfiltrationdisruption
IMPACT
mobile banking systemstreasury systemscloud infrastructurenpm accountiPhone devicesmacOS systemssystems taken offlinedisrupted services
Vulnerability
01 Jan 2025Citrix
Citrix and F5: Vulnerability affecting F5 BIG-IP APM

Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations

582After Incident
CRITICAL-9
F5CIT1774873786
Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations The UK’s National Cyber Security Centre (NCSC) has issued urgent guidance for organizations to mitigate active exploitation of severe vulnerabilities in F5 BIG-IP Access Policy Manager (APM) and Citrix NetScaler ADC/Gateway. Both flaws enable unauthenticated remote code execution (RCE), posing significant risks to enterprise networks. ### F5 BIG-IP APM (CVE-2025-53521) - Impact: Affects all organizations using BIG-IP APM, particularly large enterprises. Exploitation occurs when a malicious actor sends crafted traffic to a virtual server configured with an APM access policy. - Active Exploitation: F5 has confirmed in-the-wild attacks targeting this vulnerability. - Recommended Actions: - Isolate affected systems immediately to prevent further compromise. - Update to the latest patched version or rebuild systems from scratch if updates are not feasible. - Investigate for compromise, even if systems were recently updated, as exploitation may have occurred prior to patching. - Report incidents to F5 and UK authorities if a breach is suspected. ### Citrix NetScaler ADC/Gateway Vulnerabilities - Impact: Two recently disclosed flaws in Citrix NetScaler products could allow attackers to execute arbitrary code without authentication. - Recommended Actions: - Apply vendor patches without delay. - Monitor for signs of compromise, including unusual network activity or unauthorized access. - Consider engaging an assured Cyber Incident Response provider for forensic analysis if exploitation is suspected. ### Broader Context & NCSC Support The NCSC is actively assessing the UK impact of these vulnerabilities and collaborating with industry partners to track exploitation. Organizations are advised to: - Enable continuous threat hunting to detect post-exploitation activity. - Follow NCSC’s hardening guidance to reduce attack surfaces. - Leverage the NCSC Early Warning service for real-time threat notifications. Both F5 BIG-IP APM and Citrix NetScaler are widely deployed in critical infrastructure, making these vulnerabilities high-priority targets for threat actors. Immediate remediation is essential to prevent potential breaches.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: Enterprise networks, critical infrastructureOperational Impact: Potential unauthorized access, arbitrary code execution
DECEMBER 2023
591Before Incident
Breach
01 Dec 2023Citrix
Comcast

Xfinity by Comcast Data Breach

534After Incident
HIGH-57
COM152251223
Xfinity by Comcast reports a data breach following a cyberattack that took use of the CitrixBleed vulnerability. By taking use of this vulnerability, threat actors were able to take over active authenticated connections and get around multifactor authentication and other stringent authentication regulations. The security company Mandiant saw threat actors taking control of sessions in which the threat actor used session data that had been taken prior to the patch being deployed. The business discovered that hashed passwords and usernames are among the different client data that is exposed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Hashed passwordsUsernames
DATA BREACH
Hashed passwordsUsernames
OCTOBER 2023
589Before Incident
Vulnerability
16 Oct 2023Citrix
Comcast Cable Communications

Xfinity Data Breach via Citrix Software Vulnerability

585After Incident
CRITICAL-4
COM020090625
The Vermont Office of the Attorney General disclosed that Xfinity suffered a data breach stemming from a vulnerability in Citrix’s software, enabling unauthorized access between October 16–19, 2023. The exposed data included usernames, hashed passwords, full names, contact details, the last four digits of Social Security numbers, dates of birth, and secret questions/answers. While the breach did not involve full Social Security numbers or financial data, the compromised credentials and personal identifiers pose significant risks, including identity theft, phishing attacks, and account takeovers. The incident was publicly reported on December 18, 2023, highlighting delays in detection and disclosure. The breach’s scope suggests potential long-term reputational damage and regulatory scrutiny, particularly given the sensitivity of the leaked information and the scale of Xfinity’s customer base.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
usernameshashed passwordsnamescontact informationlast four digits of Social Security numbersdates of birthsecret questions and answersIdentity Theft Risk: High (PII exposed)
DATA BREACH
Personally Identifiable Information (PII)Authentication CredentialsSensitivity Of Data: HighData Exfiltration: Likely (unauthorized access confirmed)Data Encryption: Partially (hashed passwords)
JULY 2023
579Before Incident
Vulnerability
01 Jul 2023Citrix
Fortinet, Veeam and Citrix: INC Ransomware Uses LOLBins, RMM Tools, and rclone for Network Intrusion and Data Exfiltration

INC Ransomware Attack

575After Incident
CRITICAL-4
VEEFORCIT1781857680
INC Ransomware: A Rapidly Evolving Threat Targeting Global Organizations Since its emergence in mid-2023, the INC ransomware group has established itself as a formidable Ransomware-as-a-Service (RaaS) operation, claiming over 800 victims worldwide. The group employs aggressive double-extortion tactics, targeting high-profile organizations primarily in the U.S., with a focus on the legal, manufacturing, technology, and healthcare sectors. INC’s attack methods are both diverse and sophisticated. Initial access is often gained through spear-phishing, compromised credentials from access brokers, or exploitation of known vulnerabilities in public-facing systems, including Citrix NetScaler (CVE-2023-3519), Fortinet EMS (CVE-2023-48788), and Citrix Bleed 2 (CVE-2025-5777). Once inside, attackers use command-line tools and IP scanners to map the network before deploying a customized PowerShell script that extracts credentials from Veeam backup servers via salted DPAPI decryption. The group’s ransomware payloads, rewritten in Rust, enable cross-platform attacks on both Windows and Linux/ESXi environments. On Windows, the malware employs multithreading and partial encryption to accelerate data destruction while avoiding critical system files ensuring victims can still view ransom notes on desktops and network printers. On Linux and VMware ESXi servers, the payload shuts down virtual machines before encrypting them, maximizing disruption. INC’s encryption scheme combines Curve25519 Elliptic Curve Cryptography and AES-128, making recovery without the decryption key nearly impossible. The group operates a dual-site extortion model, using a private portal for negotiations and a public leak site to pressure non-compliant victims. Their rapid evolution and technical sophistication underscore the growing threat posed by modern ransomware operations.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (Ransomware-as-a-Service)
IMPACT
Data Compromised: Credentials, backup data, virtual machines, and sensitive filesWindowsLinux/ESXi environmentsOperational Impact: Shutdown of virtual machines, encryption of critical data, disruption of servicesBrand Reputation Impact: High (due to public leak site and double-extortion tactics)Identity Theft Risk: High (if personally identifiable information was compromised)
DATA BREACH
CredentialsBackup dataVirtual machine dataSensitive filesSensitivity Of Data: High (credentials, PII potential)Data Exfiltration: Yes (double-extortion tactic)Data Encryption: Yes (Curve25519 ECC and AES-128)
JUNE 2023
582Before Incident
Vulnerability
16 Jun 2023Citrix
Citrix

Critical Flaw in Citrix NetScaler Devices Echoes Infamous 2023 Security Breach

578After Incident
CRITICAL-4
CIT748070725
Citrix is facing a critical flaw in its NetScaler devices, known as 'CitrixBleed 2' (CVE-2025-5777), which allows attackers to steal sensitive information from device memory. This vulnerability, similar to the 2023 CitrixBleed attacks, has a CVSS severity score of 9.3 and has already been exploited in targeted attacks. The exploitation involves bypassing multi-factor authentication and hijacking user sessions, with evidence of session reuse and Active Directory reconnaissance. The vulnerability affects NetScaler ADC and NetScaler Gateway devices, potentially exposing session tokens and other sensitive data. Security experts urge immediate patching to prevent widespread exploitation, as the original CitrixBleed attacks continued to be exploited for months.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Data Theft, Session Hijacking
IMPACT
Session tokensSensitive informationNetScaler ADCNetScaler Gateway
DATA BREACH
Type Of Data Compromised: Session tokens, Sensitive informationSensitivity Of Data: High
JANUARY 2023
731Before Incident
Breach
01 Jan 2023Citrix
Comcast: Comcast’s $117.5M Data Breach Deal Nears Finish Line

Comcast 2023 Data Breach Settlement

560After Incident
CRITICAL-171
COM1769288328
Comcast Nears $117.5M Settlement Over 2023 Data Breach Affecting 30M Customers A federal judge in Pennsylvania’s Eastern District has granted preliminary approval for a $117.5 million settlement in a class-action lawsuit against Comcast, stemming from a 2023 cyber intrusion that potentially exposed sensitive data of over 30 million current and former customers. If finalized, the agreement would resolve two dozen lawsuits filed against the telecommunications giant. Affected customers would receive one of two remedies: - Three years of financial monitoring and identity theft protection, or - A choice between reimbursement for documented losses up to $10,000 or a $50 cash payment. The settlement structure allows for proof-based compensation for those who can demonstrate harm, while others may opt for a flat payout. Comcast, while not opposing the settlement, has denied liability for the breach, disputing the plaintiffs’ claims in court filings. The company has not commented publicly on the matter. The final court review will determine whether the agreement is approved.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $117.5M settlementData Compromised: Sensitive customer dataLegal Liabilities: Class-action lawsuitsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Sensitive customer dataNumber Of Records Exposed: 30 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
MAY 2019
676Before Incident
Cyber Attack
01 May 2019Citrix
Citrix

Citrix Server Breach

658After Incident
CRITICAL-18
CIT11910222
An international cybercriminals gang had accessed Citrix servers for about six months. The hackers were able to steal business documents, names, social security numbers, and financial information. The company notified all the impacted customers and secured their servers from any such future attack.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
business documentsnamessocial security numbersfinancial informationCitrix Servers
DATA BREACH
business documentsnamessocial security numbersfinancial informationSensitivity Of Data: Highnamessocial security numbers
MARCH 2019
729Before Incident
Breach
01 Mar 2019Citrix
Citrix

Citrix Security Breach

672After Incident
CRITICAL-57
CIT907323
American software company Citrix disclosed that they have been hit by a security breach during which hackers accessed the company's internal network. It was found that hackers accessed and downloaded business documents, but Citrix wasn't able to identify what specific documents had been stolen. According to the Citrix executive, there is no proof that hackers may have tampered with Citrix's official software or other goods.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
business documents
DATA BREACH
business documents
OCTOBER 2018
778Before Incident
Breach
13 Oct 2018Citrix
Citrix Systems, Inc.

Data Breach at Citrix Systems, Inc.

724After Incident
HIGH-54
CIT258072625
The California Office of the Attorney General reported a data breach involving Citrix Systems, Inc. on April 29, 2019. The breach occurred between October 13, 2018, and March 8, 2019, potentially affecting personal information of current and former employees, including names, Social Security numbers, and financial information. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security numbersfinancial information
DATA BREACH
namesSocial Security numbersfinancial informationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Citrix ?
?
What was Citrix's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Citrix's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Citrix's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Citrix's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Citrix ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Citrix's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Citrix Cyber Scoring History | Rankiteo