Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cloud Software Group

Cloud Software Group Vendor Cyber Rating & Cyber Score

cloud.com

Cloud Software Group enables our customers to evolve, compete and succeed leveraging our software franchises for and across data, automation, insight, and collaboration.


CSG A.I CyberSecurity Scoring

CSG
Company Information
Website:https://www.cloud.com/
Employees number:9,661
Number of followers:37,383
NAICS:5112
Industry Type:Software Development
Homepage:cloud.com
CSG Risk Score (AI oriented)
Between 750 and 799
logo
CSGSoftware Development
Updated:
19/06/2026
765/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CSG Global Score (TPRM)
xxxx
logo
CSGSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CSG
CSGFair
Current Score
765Baa (FAIR)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
765Before Incident
MAY 2026
764Before Incident
APRIL 2026
764Before Incident
MARCH 2026
769Before Incident
Vulnerability
23 Mar 2026CSG
Cloud Software Group: Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group

764After Incident
CRITICAL-5
CLO1774312166
Critical NetScaler ADC and Gateway Vulnerabilities Patched by Cloud Software Group Cloud Software Group has released emergency security updates for NetScaler ADC and NetScaler Gateway, addressing two high-severity vulnerabilities that could enable unauthenticated remote attacks on affected systems. The most critical flaw, CVE-2026-3055 (CVSS 9.3), is an out-of-bounds read vulnerability in SAML Identity Provider (IDP) configurations. Exploitable without authentication or user interaction, it allows attackers to trigger memory overreads, potentially leading to system compromise. The issue was discovered internally, with no evidence of active exploitation at the time of disclosure. Administrators can check for exposure by verifying SAML IDP configurations in NetScaler settings. The second vulnerability, CVE-2026-4368 (CVSS 7.7), involves a race condition causing session mixups in appliances configured as Gateways (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual servers. While exploitation requires low-privilege authentication and precise timing, successful attacks could fully compromise session confidentiality and integrity. Affected Versions & Patches: - CVE-2026-3055: NetScaler ADC/Gateway 14.1 before 14.1-66.59, 13.1 before 13.1-62.23, and FIPS/NDcPP before 13.1-37.262. - CVE-2026-4368: NetScaler ADC/Gateway 14.1-66.54. Fixed releases include 14.1-66.59 or later, 13.1-62.23 or later, and 13.1-FIPS/NDcPP 13.1.37.262 or later. The patches apply only to customer-managed deployments, as Citrix-managed cloud services and Adaptive Authentication instances have already been updated. Given NetScaler’s widespread use in enterprise VPN and application delivery, unpatched systems pose a significant risk. Security teams are advised to prioritize updates, particularly for SAML IDP-configured appliances.
INCIDENT DETAILS -
TYPE
Vulnerability Disclosure
IMPACT
Systems Affected: NetScaler ADC and NetScaler Gateway appliancesOperational Impact: Potential system compromise, session confidentiality and integrity risks
FEBRUARY 2026
769Before Incident
JANUARY 2026
769Before Incident
DECEMBER 2025
769Before Incident
NOVEMBER 2025
768Before Incident
OCTOBER 2025
768Before Incident
SEPTEMBER 2025
768Before Incident
AUGUST 2025
768Before Incident
JULY 2025
768Before Incident
JANUARY 2024
768Before Incident
Vulnerability
01 Jan 2024CSG
Citrix and WhatsUp Gold: INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New Attacks

INC Ransomware Emerges as a Top Global Threat, Targeting Critical Sectors with Rust-Based Encryptors

766After Incident
CRITICAL-2
PROCLO1781871843
INC Ransomware Emerges as a Top Global Threat, Targeting Critical Sectors with Rust-Based Encryptors Since its emergence in mid-2023, INC ransomware has rapidly evolved into one of the most prolific ransomware operations, claiming over 800 victims worldwide. Operating under a Ransomware-as-a-Service (RaaS) model, the group recruits affiliates and equips them with advanced tools to scale attacks across industries. Initially focusing on healthcare and education, INC has expanded its targeting to legal services, manufacturing, construction, and technology sectors under regulatory pressure and more likely to pay ransoms quickly. The group employs a double extortion tactic, encrypting files while threatening to leak stolen data on its leak site, compounding operational and reputational risks for victims. A recent report from Acronis highlights significant technical advancements in INC’s toolkit. Both its Windows and Linux/ESXi encryptors have been rewritten in Rust, enabling cross-platform attacks with greater evasion capabilities. The updated Windows variant targets Veeam backup deployments, while the Linux/ESXi version optimizes encryption speed by distinguishing local disks from network shares. Both payloads use partial encryption to maintain system usability while ensuring ransom notes remain visible. INC affiliates leverage legitimate remote access tools including CobaltStrike, AnyDesk, ScreenConnect, and TeamViewer to blend into normal IT activity. They also deploy process terminators like PsKill to disable endpoint defenses before exfiltrating data via rclone and 7-Zip. Credential theft has been refined to target salted DPAPI-encrypted Veeam backups. The group’s influence extends beyond its core operations. Following the 2024 disruption of its source code seller, related ransomware families like Lynx and Knoba emerged with overlapping code, indicating the spread of INC’s tooling into adjacent threat groups. Security researchers have identified multiple vulnerabilities exploited in INC attacks, including CVE-2023-3519 (Citrix NetScaler RCE), CVE-2023-4966 (Citrix Bleed), CVE-2023-35082 (SimpleHelp RMM), and CVE-2024-4885 (WhatsUp Gold RCE). Indicators of compromise (IoCs) include Rust-based encryptor hashes, abused legitimate tools, and ransom note filenames like INC-README.TXT.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData exfiltration
IMPACT
Data Compromised: Stolen data leaked on leak siteWindowsLinux/ESXiOperational Impact: Partial encryption to maintain system usabilityBrand Reputation Impact: Reputational risks due to data leaks

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CSG ?
?
What was CSG's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CSG's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CSG's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CSG's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CSG's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CSG's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CSG's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CSG's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CSG's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CSG's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CSG's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CSG's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CSG ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CSG's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?