Citrix A.I CyberSecurity Scoring
Citrix
Company Information
Website:https://bit.ly/478vsm3
Employees number:4,219
Number of followers:586,262
NAICS:5112
Industry Type:Software Development
Homepage:bit.ly
Citrix Risk Score (AI oriented)
Between 0 and 549
CitrixSoftware Development
Updated:
04/08/2026
04/08/2026
310/1000
Critical
C
Citrix Global Score (TPRM)
xxxx
CitrixSoftware Development
Score locked

CitrixCritical
Current Score
310C (CRITICAL)
01000
25 incidents
-28.09 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
314
Vulnerability
04 Aug 2026 • Citrix
SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation
311
CRITICAL-3
SAPFORVBUCITSONSOPHIK1785846368
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation
A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries.
### Attack Methodology
The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept (PoC) code, though some were modified for the operation.
Once inside a network, the attacker:
- Deployed web shells and network tunnels to move laterally.
- Harvested NTLM password hashes, credential stores, and browser secrets.
- Compromised Active Directory (AD), extracting Kerberos ticket-granting keys to forge long-term authentication tokens.
- In some cases, achieved full domain control, enabling ransomware groups to later encrypt systems.
### Shift to Espionage: Ukraine in the Crosshairs
While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker:
- Deployed Sliver command-and-control (C2) tooling.
- Accessed exposed source-code repositories.
- Collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure.
CloudSEK assessed with moderate-to-high confidence that this phase served Russian state-linked intelligence needs, though it remains unclear whether the actor was directly tasked or sold the data to a state customer.
### Shared Infrastructure and Defensive Recommendations
The same VPS servers, tunnels, and tooling were used for both criminal and espionage activities, highlighting the blurred lines between cybercrime and state-sponsored operations. Organizations are advised to:
- Remove administrative interfaces from direct internet exposure.
- Patch vulnerable appliances immediately.
- Rotate credentials and review unauthorized logins, SSH keys, and device settings.
- Isolate IP cameras from public networks and replace default passwords.
### Indicators of Compromise (IoCs)
CloudSEK provided key IoCs, including:
- IPv4 addresses linked to operator VPS, jumpboxes, and C2 infrastructure.
- SHA-256 hashes for Sliver Linux implants and malicious drivers used in credential theft.
The case underscores the dual threat posed by initial access brokers facilitating both ransomware attacks and state-aligned espionage while reinforcing the risks of unpatched edge devices and exposed credentials.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
310
Vulnerability
10 Jul 2026 • Citrix
Citrix and Progress Software: URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat
307
CRITICAL-3
CITPRO1783931784
Progress Software Orders Emergency Shutdown of ShareFile Storage Zone Controllers Amid Security Threat
Progress Software has instructed customers to immediately take offline all Windows servers running ShareFile Storage Zone Controllers, citing a "credible external security threat." The company disabled access to affected accounts as a precautionary measure while collaborating with internal and external security experts to investigate the incident.
The disruption came to light on July 10 after a customer shared Progress’s advisory on Reddit’s r/sysadmin. Progress later confirmed the issue on its status page, marking Storage Zone Controllers as "not operational" and the incident as under active investigation. The company has not disclosed the nature of the threat, its origin, or whether any data has been compromised though it stated there is no evidence of unauthorized access to ShareFile accounts or cloud-stored data.
The Storage Zone Controller, a self-hosted component that allows organizations to retain files on their own infrastructure while using ShareFile’s cloud for management, is the sole affected system. Unlike standard cloud-only ShareFile accounts, these controllers are typically exposed to the internet, increasing their vulnerability. Progress’s decision to mandate a full shutdown rather than issuing a patch suggests the threat may involve an unpatched zero-day flaw, stolen credentials, or an issue within Progress’s own systems.
Customers are advised to keep controllers offline until further notice and verify they are running ShareFile Storage Zones Controller version 5.12.4 or later (5.x line) or any 6.x release, which address previously disclosed vulnerabilities. However, Progress has not confirmed whether these updates mitigate the current threat. Organizations with internet-exposed controllers should treat the situation as a potential incident, preserve logs, and scan for unauthorized .aspx files in web directories and storage paths.
This is not the first time the Storage Zone Controller has been targeted. In 2023, while under Citrix’s ownership, attackers exploited CVE-2023-24489, an unauthenticated flaw in the same component. The vulnerability was actively exploited, prompting Citrix to sever unpatched controllers from the ShareFile cloud a step Progress has now replicated. Progress itself faced a major breach last year via the MOVEit file-transfer zero-day, which the Clop ransomware group leveraged to compromise over 2,700 organizations.
As of now, Progress has not provided a timeline for resolution or details on the threat’s specifics, leaving customers in limbo regarding when they can safely restore operations.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
312
Vulnerability
01 Jul 2026 • Citrix
Citrix: CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure
CitrixBleed-Class Vulnerability (CVE-2026-8451) Exploited Within Hours of Disclosure
308
CRITICAL-4
CIT1783016843
CitrixBleed-Class Vulnerability Exploited Within Hours of Disclosure
A newly disclosed CitrixBleed-class vulnerability (CVE-2026-8451) in Citrix NetScaler appliances was actively exploited less than 24 hours after public disclosure, according to decoy infrastructure operator Lupovis. The flaw, part of a recurring series of memory-disclosure bugs in NetScaler’s SAML authentication parser, was targeted in a coordinated scanning campaign between 30 June and 1 July 2026.
A threat actor operating from IP 146.70.139[.]154 hosted on M247 Europe SRL (AS9009) infrastructure in Frankfurt, Germany probed three Lupovis sensors over a five-hour window. After receiving a 200 response from one sensor, the attacker delivered a confirmed CVE-2026-8451 exploitation payload, mirroring tactics observed in prior CitrixBleed incidents.
The vulnerability affects NetScaler ADC/Gateway versions 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18 when configured as a SAML Identity Provider (IdP). It stems from a flaw in NetScaler’s XML parser, which fails to properly terminate unquoted attribute values, leading to an out-of-bounds memory read that exposes session tokens via the NSC_TASS cookie.
The exploit payload, sent to POST /saml/login, consisted of a malformed <samlp:AuthnRequest> tag padded with 476 spaces a pattern designed to force the parser to read beyond its buffer. This technique aligns with the Detection Artifact Generator released by watchTowr Labs alongside Citrix’s advisory (CTX696604).
Notably, CVE-2026-8451 remains absent from CISA’s Known Exploited Vulnerabilities (KEV) catalog, despite active exploitation a repeat of past CitrixBleed incidents where in-the-wild attacks preceded formal KEV listings by weeks. Previous flaws in this family, such as CVE-2023-4966 (original CitrixBleed), led to high-profile breaches at Boeing, ICBC, and DP World within weeks of disclosure.
The attacker’s tooling, identified by the python-requests/2.32.5 User-Agent, validated targets before deploying payloads, a behavior consistent with opportunistic mass exploitation. The rapid exploitation underscores the persistent risk posed by CitrixBleed-style vulnerabilities, particularly for organizations relying solely on KEV-driven patch prioritization.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
407
Ransomware
01 Jun 2026 • Citrix
Fortinet, Check Point, Palo Alto and Citrix: Ransomware groups are hammering your vulnerable VPNs
Ransomware Groups Exploit VPNs and Edge Devices as Prime Entry Points into Corporate Networks
303
CRITICAL-104
CHEFORPALCIT1784881580
Ransomware Groups Exploit VPNs and Edge Devices as Prime Entry Points into Corporate Networks
Cybercriminals, including ransomware-as-a-service (RaaS) operators and nation-state-backed advanced persistent threat (APT) groups, are increasingly targeting internet-facing VPNs and edge devices to breach corporate networks. According to cybersecurity experts, these systems often exposed to the internet provide attackers with a direct gateway into an organization’s infrastructure, bypassing endpoint security controls.
Key Attack Vectors and Trends
- Stolen Credentials Over Exploits: While unpatched vulnerabilities remain a concern, attackers more frequently abuse compromised credentials to access non-MFA-protected accounts. Huntress reports that VPNs account for 70% of initial access in advanced threat actor campaigns, with stolen credentials being the primary method.
- Ransomware Operations: Groups like Qilin and Akira leverage VPN and firewall flaws particularly in products from Palo Alto, Fortinet, Citrix, and Check Point to deploy ransomware. Post-exploitation tactics vary, from rapid encryption to double-extortion schemes, suggesting multiple affiliates operate under RaaS models.
- Zero-Day Exploits: Recent campaigns highlight the exploitation of CVE-2024-3400 in Palo Alto’s GlobalProtect VPN and vulnerabilities in FortiGate, Citrix NetScaler, and Check Point devices. Attackers prioritize internet-facing assets with known active exploits, leaving organizations with minimal time to patch.
Industry Impact and Mitigation Challenges
- Rising Threat Trajectory: Despite no significant spike in ransomware volume in Q2 2026, attacks continue to escalate, with VPNs and edge devices remaining high-value targets. NCC Group’s threat report ranks Qilin as the second-most active ransomware group (238 victims) and Akira fourth (127 victims) for the quarter.
- Security Gaps: Edge devices are particularly vulnerable due to their continuous internet exposure and privileged access. Experts warn that delayed patching especially for critical updates creates a narrow window for attackers to strike before defenses are fortified.
- Defensive Strategies: Recommended measures include zero-trust network segmentation, phishing-resistant MFA, aggressive patch management (applying updates within 24–48 hours), and monitoring for unusual authentication activity. However, the shift toward convenience over containment in enterprise networks exacerbates lateral movement risks.
The trend underscores a persistent challenge: while vulnerabilities in perimeter devices are lucrative for attackers, the abuse of legitimate credentials remains the dominant and often overlooked threat vector.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Vulnerability
01 Jun 2026 • Citrix
Citrix, Kontron, The Gentlemen RaaS Victims and Anubis Ransomware Victims: Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors
303
CRITICAL-104
CITGUIKONARC1783031139
Anubis Ransomware Exploits Citrix Bleed 2 in Targeted Attacks Across Critical Sectors
Threat actors linked to the Anubis ransomware-as-a-service (RaaS) operation are actively exploiting CVE-2025-5777 (Citrix Bleed 2), a critical vulnerability in Citrix NetScaler ADC and Gateway, to gain initial access to victim networks. According to a report by Arctic Wolf, attackers leverage legitimate Remote Management and Monitoring (RMM) tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment to blend in with normal IT activity while maintaining persistent control.
Anubis, a rebrand of the Sphinx ransomware, emerged in late 2024 and was formally announced on the RAMP underground forum in February 2025. Since then, the group has claimed 91 victims on its data leak site, with 11 reported in June 2026 alone. Targeted sectors include healthcare, business services, manufacturing, technology, and financial services, with over 50% of victims based in the U.S., followed by the U.K., Australia, France, and Canada.
The group employs aggressive tactics, including an irreversible data-wiping feature that reduces files to 0 KB regardless of ransom payment, increasing pressure on victims. Affiliates receive 80% of ransom payments, a lucrative incentive that has fueled the operation’s growth. Beyond Citrix Bleed 2, Anubis actors have also used stolen VPN credentials potentially sourced from initial access brokers, credential stuffing, or info-stealer malware to breach networks via Cisco AnyConnect VPNs, particularly through hosting providers like AS20473 (The Constant Company) and AS55286 (ServerMania).
Once inside, attackers move laterally using RDP and PsExec, deploy RMM tools for persistence, and exfiltrate data via Cloudflare Tunnels, S3 Browser, rclone, s5cmd, WinSCP, and PuTTY. They also disable security defenses, including Windows Defender and Sophos, and manipulate logs to hinder forensic analysis. In some cases, the ransomware encryptor is deleted post-execution, further complicating detection.
### The Gentlemen RaaS and Zero-Day Exploits
Separately, Kaspersky detailed The Gentlemen RaaS, which exploits known vulnerabilities and weak credentials to deploy a Go-based backdoor for remote command execution. The malware collects system data, exfiltrates it to 81.177.215[.]15:9443, and can establish a SOCKS proxy for network pivoting. The group has also weaponized a zero-day vulnerability in ktapi.sys, a Kontron driver, to bypass Windows security protections and terminate processes from Microsoft, ESET, Palo Alto Networks, and SentinelOne.
### VECT and TeamPCP’s Supply Chain-Ransomware Hybrid
A Sophos investigation revealed a partnership between VECT and TeamPCP, announced in March 2026, combining supply chain credential theft with ransomware deployment. TeamPCP, previously operating as CipherForce, rebranded after listing six victims in February 2026. However, VECT’s encryptor contains critical flaws, destroying files larger than 128 KB instead of encrypting them a defect TeamPCP claims it never used in attacks.
The alliance represents a shift toward industrialized ransomware deployment, lowering the barrier for cybercriminals by merging large-scale supply chain attacks with mature RaaS operations. Despite technical shortcomings, the model poses a growing threat to enterprises.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
407
Vulnerability
16 May 2026 • Citrix
Citrix and BlackCat: MSN
Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability
403
CRITICAL-4
CITBLA1778977440
Cyberattack Targets U.S. Healthcare Sector: Ransomware Group Exploits Zero-Day Vulnerability
A recent cyberattack has disrupted operations across multiple U.S. healthcare providers, with the ransomware group BlackCat (ALPHV) exploiting a previously unknown zero-day vulnerability in Citrix NetScaler ADC and Gateway systems. The flaw, tracked as CVE-2023-4966 (dubbed "Citrix Bleed"), allows attackers to bypass authentication and gain unauthorized access to sensitive networks.
The attack, detected in late October 2023, targeted hospitals, clinics, and medical billing firms, leading to delayed patient care, system outages, and data exposure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed the vulnerability’s active exploitation, warning that threat actors could steal session tokens to maintain persistent access even after patches are applied.
BlackCat, known for its double-extortion tactics, has demanded ransoms ranging from $1 million to $10 million per victim. While some organizations have restored systems from backups, others remain locked out of critical infrastructure. The incident underscores the growing risk of zero-day exploits in healthcare, where legacy systems and high-value data make providers prime targets.
Citrix released emergency patches on October 10, 2023, urging all users to update immediately. However, CISA’s advisory notes that compromised credentials may still pose a threat, requiring additional mitigation steps, including credential resets and network segmentation. The full scope of affected entities remains unclear, though reports indicate at least dozens of organizations have been impacted.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
407
Vulnerability
01 May 2026 • Citrix
Citrix, Microsoft, Apache Software Foundation and Langflow: Hacker uses DeepSeek AI to autonomously attack vulnerable servers
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
403
CRITICAL-4
MICTHESECCIT1785522270
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
Researchers at Palo Alto Networks’ Unit 42 have uncovered a campaign by a China-based threat actor using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks with minimal human oversight. The actor, operating under the aliases "knaithe" and "KnYuan," identifies as a "binary security researcher."
The discovery stemmed from an accidental exposure of the attacker’s environment after Hermes created a misconfigured web server, revealing API keys, exploit scripts, target lists, shell history, and AI attack logs. While the observed attacks did not successfully compromise targets, they demonstrated a fully autonomous offensive AI workflow capable of identifying, evaluating, and exploiting vulnerabilities.
### AI-Powered Attack Workflow
The threat actor deployed DeepSeek as the reasoning engine behind Hermes Agent, an AI framework that interacts with operating systems, executes commands, and connects to the internet. Hermes was configured to:
- Receive instructions via Telegram
- Use custom offensive-security tools
- Query FOFA, an internet asset search engine
- Operate in "Yolo" mode, executing commands without prior approval
In a recovered session from May 2026, the agent autonomously:
1. Targeted Langflow servers vulnerable to CVE-2026-33017, scanning 84 exposed instances but failing to exploit them.
2. Switched to n8n workflow automation, identifying 647,000 exposed instances and attempting to exploit CVE-2026-21858 and CVE-2025-68613 though authentication requirements prevented successful breaches.
3. Analyzed public exploit repositories and executed hundreds of hours of manual targeting analysis in minutes, managing its own compute resources.
### Manual Attacks & Successful Compromises
While the AI-driven attacks were largely unsuccessful, the threat actor also conducted manual attacks on 460+ systems, exploiting vulnerabilities in:
- Citrix NetScaler (CVE-2026-3055) – Used in three confirmed breaches to extract memory and harvest authentication cookies.
- Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others.
Additional AI platforms (Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) were configured but rarely used.
### Previous Hermes Incident in Thailand
This campaign follows a separate incident where poorly secured Hermes infrastructure exposed details of an alleged cyberattack on Thailand’s Ministry of Finance. Logs revealed Hermes operating in unattended "YOLO" mode, automating post-exploitation tasks such as:
- Privilege escalation checks
- Service enumeration
- File system traversal
- Document cataloging
Unlike the autonomous attacks observed by Unit 42, the Thailand incident involved human-directed targeting, with Hermes only automating post-compromise activity.
### Significance of the Campaign
Unit 42 highlights the evolution of AI-driven cyber threats, where autonomous agents can:
- Research vulnerabilities independently
- Prioritize targets
- Download and execute exploits
- Adapt attack strategies in real time
While this campaign had limited success, it underscores the growing sophistication of offensive AI in cyber operations.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
405
MARCH 2026
402
Vulnerability
23 Mar 2026 • Citrix
Cloud Software Group: Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group
398
CRITICAL-4
CLO1774312166
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group
Cloud Software Group has released emergency security updates for NetScaler ADC and NetScaler Gateway, addressing two high-severity vulnerabilities that could enable unauthenticated remote attacks on affected systems.
The most critical flaw, CVE-2026-3055 (CVSS 9.3), is an out-of-bounds read vulnerability in SAML Identity Provider (IDP) configurations. Exploitable without authentication or user interaction, it allows attackers to trigger memory overreads, potentially leading to system compromise. The issue was discovered internally, with no evidence of active exploitation at the time of disclosure. Administrators can check for exposure by verifying SAML IDP configurations in NetScaler settings.
The second vulnerability, CVE-2026-4368 (CVSS 7.7), involves a race condition causing session mixups in appliances configured as Gateways (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual servers. While exploitation requires low-privilege authentication and precise timing, successful attacks could fully compromise session confidentiality and integrity.
Affected Versions & Patches:
- CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and FIPS/NDcPP before 13.1-37.262.
- CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54.
Fixed releases include 14.1-66.59 or later, 13.1-62.23 or later, and 13.1-FIPS/NDcPP 13.1.37.262 or later. The patches apply only to customer-managed deployments, as Citrix-managed cloud services and Adaptive Authentication instances have already been updated.
Given NetScaler’s widespread use in enterprise VPN and application delivery, unpatched systems pose a significant risk. Security teams are advised to prioritize updates, particularly for SAML IDP-configured appliances.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
FEBRUARY 2026
393
Vulnerability
01 Feb 2026 • Citrix
Citrix: Threat Actors Conduct Widespread Scanning for Exposed Citrix NetScaler Login Pages
Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered
389
CRITICAL-4
CIT1770201552
Large-Scale Citrix ADC Gateway Reconnaissance Campaign Uncovered
A sophisticated reconnaissance campaign targeting Citrix ADC (NetScaler) Gateway infrastructure has been detected, involving over 63,000 residential proxy IPs and AWS cloud instances to map login panels and enumerate software versions. The operation, which generated 111,834 scanning sessions, was highly targeted 79% of traffic focused on Citrix Gateway honeypots indicating deliberate pre-exploitation preparation rather than random scanning.
The campaign unfolded in two phases:
1. Login Panel Discovery (Primary Phase)
- 109,942 sessions from 63,189 unique IPs probed the `/logon/LogonPoint/index.html` authentication interface.
- 64% of traffic originated from residential proxies across Vietnam, Argentina, Mexico, Algeria, and Iraq, while a single Microsoft Azure IP in Canada accounted for 36%.
- Threat actors used unique browser fingerprints and residential proxies to evade geographic and reputation-based blocking.
2. Version Disclosure Sprint (AWS Phase)
- On February 1, 2026, 10 AWS instances in us-west-1/us-west-2 executed a six-hour scan, sending 1,892 requests to `/epa/scripts/win/nsepa_setup.exe` to identify Citrix Endpoint Analysis (EPA) versions.
- Activity peaked at 362 sessions around 02:00 UTC before tapering off by 05:00 UTC.
- All requests used an outdated Chrome 50 user agent (2016) and uniform HTTP fingerprints, suggesting a coordinated effort to exploit known vulnerabilities.
Researchers from GreyNoise noted the focus on the EPA setup file path indicates potential interest in version-specific exploits, particularly given recent critical Citrix vulnerabilities:
- CVE-2025-5777 ("CitrixBleed 2")
- CVE-2025-5775 (remote code execution, exploited as a zero-day).
Detection and Indicators of Compromise (IOCs)
- User agents: `blackbox-exporter` (unauthorized sources), Chrome 50 (2016)
- Targeted paths: `/logon/LogonPoint/`, `/epa/scripts/win/nsepa_setup.exe`
- AWS IPs (Version Disclosure):
`44.251.121.190, 13.57.253.3, 50.18.232.85, 52.36.139.223, 54.201.20.56, 54.153.0.164, 54.176.178.13, 18.237.26.188, 54.219.42.163, 18.246.164.162`
- Azure IP (Login Panel Discovery): `52.139.3.76`
The campaign’s scale and precision suggest threat actors are actively preparing for potential exploitation, likely targeting unpatched or misconfigured Citrix ADC deployments.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2026
393
DECEMBER 2025
379
NOVEMBER 2025
372
Vulnerability
01 Nov 2025 • Citrix
Citrix and VMware: Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware
Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft
368
CRITICAL-4
CITVMW1776702564
Threat Actors Weaponize QEMU as Covert Backdoor for Ransomware and Credential Theft
Cybercriminals are increasingly abusing QEMU, a legitimate open-source virtualization tool, to bypass endpoint security and deploy ransomware or steal credentials undetected. By running malicious operations inside hidden virtual machines (VMs), attackers exploit a critical blind spot security tools on the host system cannot inspect activity within the VM, leaving minimal forensic traces.
Sophos researchers have identified two active campaigns leveraging this technique since late 2025:
1. STAC4713 (November 2025) – Linked to the PayoutsKing ransomware group (GOLD ENCOUNTER), which operates independently (not as a ransomware-as-a-service). The group targets VMware and ESXi hypervisors, using QEMU to execute attacks. The infection chain begins with a scheduled task ("TPMProfiler") running QEMU under the SYSTEM account, booting from a disguised virtual disk (initially vault.db, later bisrv.dll). The VM establishes a reverse SSH tunnel via custom ports (32567, 22022) to port 22, creating a persistent backdoor. Tools inside the VM include AdaptixC2, Linker2, and a WireGuard obfuscator (wg-obfuscator).
2. STAC3725 (February 2026) – Exploits the CitrixBleed2 vulnerability (CVE-2025-5777) for initial access, then deploys a malicious ScreenConnect client for persistence. Attackers manually compile a toolkit inside the QEMU VM, including Impacket, KrbRelayX, BloodHound.py, NetExec, and Metasploit, to harvest credentials, enumerate Active Directory, and stage payloads via FTP.
Both campaigns demonstrate a growing trend of virtualization-based evasion, where trusted tools like QEMU are repurposed to conceal malicious activity. The technique’s stealth and lack of detectable artifacts make it particularly challenging for defenders to identify and mitigate in real time.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
540
Breach
19 Oct 2025 • Citrix
F5
Oracle E-Business Suite Remotely Exploitable Vulnerability (CVE-2025-61884)Microsoft Zero-Day Exploits (CVE-2025-24990, CVE-2025-59230, CVE-2025-47827)F5 Data Breach: Nation-State Attackers Stole BIG-IP Source CodeAdobe Experience Manager 'Perfect' Vulnerability (CVE-2025-54253)Microsoft Revokes 200 Certificates Used for Malicious Teams Installers (Vanilla Tempest Ransomware)Cisco Zero-Day Rootkit Deployment on Network Switches (CVE-2025-20352)U.S. Seizes $15B in Bitcoin Linked to Forced-Labor Crypto ScamUnitree G1 Humanoid Robot Bluetooth Vulnerability (Espionage Risk)Healthcare Cybersecurity Breakdown: 93% of U.S. Organizations Attacked (Patient Care Disruptions)
369
CRITICAL-171
F50032500101925
US tech company F5 confirmed a data breach in which nation-state attackers stole the source code and vulnerability information related to its BIG-IP family of networking and security products. BIG-IP is a critical infrastructure component used by enterprises for traffic management, load balancing, and security, making this breach particularly severe. The stolen data could enable adversaries to identify and exploit undiscovered flaws in BIG-IP systems, potentially leading to supply-chain attacks, unauthorized network access, or large-scale disruptions in organizations relying on F5’s solutions. The breach underscores the escalating risks of state-sponsored cyber espionage targeting foundational IT infrastructure, with implications for global cybersecurity resilience. F5 has not disclosed whether customer data was compromised, but the theft of proprietary code and vulnerability details poses a long-term threat to its product ecosystem and the broader digital supply chain.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
537
AUGUST 2025
535
Vulnerability
26 Aug 2025 • Citrix
Citrix (Cloud Software Group)
Critical Remote Code Execution Flaw (CVE-2025-7775) in Citrix NetScaler ADC and Gateway
531
CRITICAL-4
CIT806082725
Citrix disclosed a critical zero-day vulnerability (CVE-2025-7775) in its NetScaler ADC and NetScaler Gateway products, actively exploited in the wild as of August 26, 2025. The flaw—a memory overflow bug—enables unauthenticated remote code execution (RCE) on unpatched devices, posing severe risks to organizations relying on these appliances for secure access. While Citrix did not provide indicators of compromise (IoCs), they confirmed exploitation on systems configured as Gateway (VPN, ICA Proxy, RDP Proxy), AAA virtual servers, or specific load-balancing (LB) setups with IPv6 bindings. No mitigations exist, forcing immediate patching to versions 14.1-47.48, 13.1-59.22, or later.The vulnerability’s exploitation could allow attackers to gain full control over affected systems, potentially leading to lateral movement, data exfiltration, or deployment of malware/ransomware. Citrix also patched two other flaws: a DoS vulnerability (CVE-2025-7776) and an improper access control issue (CVE-2025-8424), further compounding risks. Historical context—such as the prior Citrix Bleed 2 (CVE-2025-5777) exploit—highlights the company’s recurring exposure to high-severity attacks targeting memory corruption. Failure to patch could result in widespread breaches, operational disruptions, or supply-chain attacks given NetScaler’s role in enterprise networks.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2025
527
Vulnerability
16 Jun 2025 • Citrix
Citrix
Exploitation of Citrix Vulnerabilities via HexStrike-AI Red Teaming Tool
522
CRITICAL-5
CIT1555015090425
Cybercriminals are leveraging HexStrike-AI, a legitimate red teaming tool, to automate exploits against Citrix NetScaler ADC and Gateway using recently disclosed vulnerabilities (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424). The tool enables unauthenticated remote code execution (RCE), allowing attackers to deploy webshells and maintain persistent access. While no confirmed breaches are reported yet, the exploitation window has shrunk from days to minutes, drastically reducing the time administrators have to patch systems. The CVE-2025-7775 flaw is already being exploited in the wild, and the use of HexStrike-AI is expected to escalate attack volumes, increasing the risk of unauthorized system takeovers, data exposure, or operational disruptions for organizations relying on Citrix infrastructure. The automation capability of the tool makes manual patch management nearly impossible without dedicated platforms, heightening the urgency for immediate mitigation.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MAY 2025
537
Cyber Attack
01 May 2025 • Citrix
Citrix
Sophisticated Cyberattacks Targeting Critical Infrastructure via Citrix NetScaler Zero-Day Vulnerability
519
CRITICAL-18
CIT211081225
The Dutch National Cyber Security Centre (NCSC-NL) has issued an urgent warning about sophisticated cyberattacks targeting critical infrastructure through a zero-day vulnerability in Citrix NetScaler devices. The vulnerability, designated CVE-2025-6543, has been actively exploited since early May 2025, compromising several critical organizations across the Netherlands. Attackers gained access to perimeter defenses, demonstrating advanced capabilities by erasing forensic traces and deploying malicious web shells for persistent remote access. The exploitation involved placing suspicious PHP files in system directories, making detection and remediation challenging. The NCSC emphasizes that patching alone is insufficient, as compromised systems may retain attacker access, requiring comprehensive forensic investigation.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
FEBRUARY 2025
586
Breach
01 Feb 2025 • Citrix
Anthropic: Anthropic leaks its own AI coding tool’s source code in second major security breach
Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems
522
CRITICAL-64
ANT1774981746
Anthropic Accidentally Leaks Claude Code Source, Exposing Internal AI Systems
Anthropic has inadvertently leaked the source code for Claude Code, its widely adopted AI-powered coding assistant, exposing roughly 500,000 lines of code across 1,900 files. The incident, confirmed by the company as a "release packaging issue" caused by human error, occurred when internal code was mistakenly uploaded to NPM a platform for software distribution instead of the final, compiled version.
The leak follows a separate accidental disclosure earlier this month, in which a draft blog post revealed details about Mythos (also referred to as Capybara), an upcoming AI model described as more powerful and potentially more dangerous than Anthropic’s current flagship, Opus. While the latest breach did not expose model weights or customer data, cybersecurity experts warn it could allow competitors to reverse-engineer Claude Code’s underlying "agentic harness" the software layer that governs the AI’s behavior, tool integration, and safety guardrails. This could enable the creation of open-source alternatives or help rivals refine their own AI systems.
Security researcher Roy Paz of LayerX Security noted that the leaked code also provided further evidence of Capybara, Anthropic’s next-generation model, which is expected to surpass Opus in capability and cost. The draft blog post previously described it as a new tier, with "fast" and "slow" variants likely replacing Opus as the company’s most advanced offering. Paz highlighted concerns that the exposed code may reveal vulnerabilities in how Claude Code interacts with Anthropic’s internal systems, potentially allowing malicious actors including nation-states to exploit the AI for cyberattacks or bypass existing safeguards.
Anthropic’s Opus model is already classified as a high-risk tool due to its ability to autonomously identify zero-day vulnerabilities, a capability that could be weaponized by threat actors. This is not the first time the company has faced such an exposure; in February 2025, an early version of Claude Code was similarly leaked, revealing internal workings and system connections before being removed.
The company has stated it is implementing measures to prevent future incidents but has not disclosed further details. The leak underscores the challenges of securing proprietary AI systems as adoption and scrutiny of advanced models continues to grow.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2025
591
Vulnerability
01 Jan 2025 • Citrix
F5, Lloyds Banking Group, Citrix, Dutch Ministry of Finance and European Commission: Lloyds Banking Group - Security Affairs
Cybersecurity Roundup: Major Incidents and Emerging Threats
582
CRITICAL-9
EURF5LLOCITMIN1774989406
Cybersecurity Roundup: Major Incidents and Emerging Threats
Recent weeks have seen a surge in high-profile cybersecurity incidents, vulnerabilities, and state-linked attacks targeting governments, financial institutions, and critical infrastructure.
Financial Sector Breaches
Lloyds Banking Group confirmed a security incident affecting nearly 500,000 mobile customers, though details on the nature of the breach remain undisclosed. Meanwhile, the Dutch Ministry of Finance took treasury systems offline following a cyber incident under investigation.
Critical Vulnerabilities Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Citrix NetScaler flaw (CVE-2026-3055) to its Known Exploited Vulnerabilities catalog after reports of active exploitation, with attackers probing the bug for potential data leaks. CISA also flagged a critical F5 BIG-IP AMP vulnerability under active attack. Additionally, security agencies warned of a severe flaw in PTC Windchill and FlexPLM, urging organizations to apply patches immediately.
State-Sponsored Threats
Russia-linked APT TA446 deployed the DarkSword exploit in a phishing campaign targeting iPhone users. China-associated groups launched advanced malware attacks against a Southeast Asian government in early 2025. Meanwhile, an Iran-linked group, Handala, compromised the personal email account of FBI Director Kash Patel, marking a significant escalation in espionage efforts.
Ransomware and Supply Chain Attacks
The Qilin ransomware group claimed responsibility for breaching Dow Inc., a major chemical manufacturer. Attackers also hijacked the Axios npm account, using it to distribute remote access trojan (RAT) malware to unsuspecting developers. In a separate incident, ShinyHunters asserted responsibility for hacking the European Commission, though the full impact remains unclear.
Emerging Threats
Apple issued urgent lock screen warnings for unpatched iPhones and iPads, highlighting ongoing risks to mobile security. A new macOS malware, Infinity Stealer, was discovered leveraging Nuitka Python payloads and ClickFix techniques to evade detection. Additionally, a new adversary-in-the-middle (AITM) phishing wave targeted TikTok Business accounts, demonstrating evolving social engineering tactics.
Government and Institutional Targets
The European Commission confirmed a cyberattack affecting part of its cloud infrastructure, though specifics on the attack vector and scope were not disclosed. These incidents underscore the persistent and evolving nature of cyber threats across sectors.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Vulnerability
01 Jan 2025 • Citrix
Citrix and F5: Vulnerability affecting F5 BIG-IP APM
Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations
582
CRITICAL-9
F5CIT1774873786
Critical Vulnerabilities in F5 BIG-IP and Citrix NetScaler Demand Immediate Action from UK Organizations
The UK’s National Cyber Security Centre (NCSC) has issued urgent guidance for organizations to mitigate active exploitation of severe vulnerabilities in F5 BIG-IP Access Policy Manager (APM) and Citrix NetScaler ADC/Gateway. Both flaws enable unauthenticated remote code execution (RCE), posing significant risks to enterprise networks.
### F5 BIG-IP APM (CVE-2025-53521)
- Impact: Affects all organizations using BIG-IP APM, particularly large enterprises. Exploitation occurs when a malicious actor sends crafted traffic to a virtual server configured with an APM access policy.
- Active Exploitation: F5 has confirmed in-the-wild attacks targeting this vulnerability.
- Recommended Actions:
- Isolate affected systems immediately to prevent further compromise.
- Update to the latest patched version or rebuild systems from scratch if updates are not feasible.
- Investigate for compromise, even if systems were recently updated, as exploitation may have occurred prior to patching.
- Report incidents to F5 and UK authorities if a breach is suspected.
### Citrix NetScaler ADC/Gateway Vulnerabilities
- Impact: Two recently disclosed flaws in Citrix NetScaler products could allow attackers to execute arbitrary code without authentication.
- Recommended Actions:
- Apply vendor patches without delay.
- Monitor for signs of compromise, including unusual network activity or unauthorized access.
- Consider engaging an assured Cyber Incident Response provider for forensic analysis if exploitation is suspected.
### Broader Context & NCSC Support
The NCSC is actively assessing the UK impact of these vulnerabilities and collaborating with industry partners to track exploitation. Organizations are advised to:
- Enable continuous threat hunting to detect post-exploitation activity.
- Follow NCSC’s hardening guidance to reduce attack surfaces.
- Leverage the NCSC Early Warning service for real-time threat notifications.
Both F5 BIG-IP APM and Citrix NetScaler are widely deployed in critical infrastructure, making these vulnerabilities high-priority targets for threat actors. Immediate remediation is essential to prevent potential breaches.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
DECEMBER 2023
591
Breach
01 Dec 2023 • Citrix
Comcast
Xfinity by Comcast Data Breach
534
HIGH-57
COM152251223
Xfinity by Comcast reports a data breach following a cyberattack that took use of the CitrixBleed vulnerability.
By taking use of this vulnerability, threat actors were able to take over active authenticated connections and get around multifactor authentication and other stringent authentication regulations.
The security company Mandiant saw threat actors taking control of sessions in which the threat actor used session data that had been taken prior to the patch being deployed.
The business discovered that hashed passwords and usernames are among the different client data that is exposed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2023
589
Vulnerability
16 Oct 2023 • Citrix
Comcast Cable Communications
Xfinity Data Breach via Citrix Software Vulnerability
585
CRITICAL-4
COM020090625
The Vermont Office of the Attorney General disclosed that Xfinity suffered a data breach stemming from a vulnerability in Citrix’s software, enabling unauthorized access between October 16–19, 2023. The exposed data included usernames, hashed passwords, full names, contact details, the last four digits of Social Security numbers, dates of birth, and secret questions/answers. While the breach did not involve full Social Security numbers or financial data, the compromised credentials and personal identifiers pose significant risks, including identity theft, phishing attacks, and account takeovers. The incident was publicly reported on December 18, 2023, highlighting delays in detection and disclosure. The breach’s scope suggests potential long-term reputational damage and regulatory scrutiny, particularly given the sensitivity of the leaked information and the scale of Xfinity’s customer base.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2023
579
Vulnerability
01 Jul 2023 • Citrix
Fortinet, Veeam and Citrix: INC Ransomware Uses LOLBins, RMM Tools, and rclone for Network Intrusion and Data Exfiltration
INC Ransomware Attack
575
CRITICAL-4
VEEFORCIT1781857680
INC Ransomware: A Rapidly Evolving Threat Targeting Global Organizations
Since its emergence in mid-2023, the INC ransomware group has established itself as a formidable Ransomware-as-a-Service (RaaS) operation, claiming over 800 victims worldwide. The group employs aggressive double-extortion tactics, targeting high-profile organizations primarily in the U.S., with a focus on the legal, manufacturing, technology, and healthcare sectors.
INC’s attack methods are both diverse and sophisticated. Initial access is often gained through spear-phishing, compromised credentials from access brokers, or exploitation of known vulnerabilities in public-facing systems, including Citrix NetScaler (CVE-2023-3519), Fortinet EMS (CVE-2023-48788), and Citrix Bleed 2 (CVE-2025-5777). Once inside, attackers use command-line tools and IP scanners to map the network before deploying a customized PowerShell script that extracts credentials from Veeam backup servers via salted DPAPI decryption.
The group’s ransomware payloads, rewritten in Rust, enable cross-platform attacks on both Windows and Linux/ESXi environments. On Windows, the malware employs multithreading and partial encryption to accelerate data destruction while avoiding critical system files ensuring victims can still view ransom notes on desktops and network printers. On Linux and VMware ESXi servers, the payload shuts down virtual machines before encrypting them, maximizing disruption.
INC’s encryption scheme combines Curve25519 Elliptic Curve Cryptography and AES-128, making recovery without the decryption key nearly impossible. The group operates a dual-site extortion model, using a private portal for negotiations and a public leak site to pressure non-compliant victims. Their rapid evolution and technical sophistication underscore the growing threat posed by modern ransomware operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2023
582
Vulnerability
16 Jun 2023 • Citrix
Citrix
Critical Flaw in Citrix NetScaler Devices Echoes Infamous 2023 Security Breach
578
CRITICAL-4
CIT748070725
Citrix is facing a critical flaw in its NetScaler devices, known as 'CitrixBleed 2' (CVE-2025-5777), which allows attackers to steal sensitive information from device memory. This vulnerability, similar to the 2023 CitrixBleed attacks, has a CVSS severity score of 9.3 and has already been exploited in targeted attacks. The exploitation involves bypassing multi-factor authentication and hijacking user sessions, with evidence of session reuse and Active Directory reconnaissance. The vulnerability affects NetScaler ADC and NetScaler Gateway devices, potentially exposing session tokens and other sensitive data. Security experts urge immediate patching to prevent widespread exploitation, as the original CitrixBleed attacks continued to be exploited for months.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2023
731
Breach
01 Jan 2023 • Citrix
Comcast: Comcast’s $117.5M Data Breach Deal Nears Finish Line
Comcast 2023 Data Breach Settlement
560
CRITICAL-171
COM1769288328
Comcast Nears $117.5M Settlement Over 2023 Data Breach Affecting 30M Customers
A federal judge in Pennsylvania’s Eastern District has granted preliminary approval for a $117.5 million settlement in a class-action lawsuit against Comcast, stemming from a 2023 cyber intrusion that potentially exposed sensitive data of over 30 million current and former customers.
If finalized, the agreement would resolve two dozen lawsuits filed against the telecommunications giant. Affected customers would receive one of two remedies:
- Three years of financial monitoring and identity theft protection, or
- A choice between reimbursement for documented losses up to $10,000 or a $50 cash payment.
The settlement structure allows for proof-based compensation for those who can demonstrate harm, while others may opt for a flat payout.
Comcast, while not opposing the settlement, has denied liability for the breach, disputing the plaintiffs’ claims in court filings. The company has not commented publicly on the matter. The final court review will determine whether the agreement is approved.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2019
676
Cyber Attack
01 May 2019 • Citrix
Citrix
Citrix Server Breach
658
CRITICAL-18
CIT11910222
An international cybercriminals gang had accessed Citrix servers for about six months.
The hackers were able to steal business documents, names, social security numbers, and financial information.
The company notified all the impacted customers and secured their servers from any such future attack.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2019
729
Breach
01 Mar 2019 • Citrix
Citrix
Citrix Security Breach
672
CRITICAL-57
CIT907323
American software company Citrix disclosed that they have been hit by a security breach during which hackers accessed the company's internal network.
It was found that hackers accessed and downloaded business documents, but Citrix wasn't able to identify what specific documents had been stolen.
According to the Citrix executive, there is no proof that hackers may have tampered with Citrix's official software or other goods.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2018
778
Breach
13 Oct 2018 • Citrix
Citrix Systems, Inc.
Data Breach at Citrix Systems, Inc.
724
HIGH-54
CIT258072625
The California Office of the Attorney General reported a data breach involving Citrix Systems, Inc. on April 29, 2019. The breach occurred between October 13, 2018, and March 8, 2019, potentially affecting personal information of current and former employees, including names, Social Security numbers, and financial information. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Citrix ??
What was Citrix's A.I Rankiteo Cyber Score in July 2026 ??
What was Citrix's A.I Rankiteo Cyber Score in June 2026 ??
What was Citrix's A.I Rankiteo Cyber Score in May 2026 ??
What was Citrix's A.I Rankiteo Cyber Score in April 2026 ??
What was Citrix's A.I Rankiteo Cyber Score in March 2026 ??
What was Citrix's A.I Rankiteo Cyber Score in February 2026 ??
What was Citrix's A.I Rankiteo Cyber Score in January 2026 ??
What was Citrix's A.I Rankiteo Cyber Score in December 2025 ??
What was Citrix's A.I Rankiteo Cyber Score in November 2025 ??
What was Citrix's A.I Rankiteo Cyber Score in October 2025 ??
What was Citrix's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Citrix's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Citrix ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Citrix's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?