// NEXUSVOID CYBER NEWS

<- ALL CYBER NEWS

Critical

Citrix, NetScaler, ransomware, CitrixBleed, actively exploited

Citrix Bleed 2 Exploited Within Hours of Disclosure - Now Feeding Ransomware Operations

A new CitrixBleed vulnerability in NetScaler appliances was exploited immediately after public disclosure using public PoC code, and Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) for initial access. If you run NetScaler, assume you are being scanned right now.

If you want to understand why "we will patch it next cycle" is a losing sentence, watch what happened with the latest Citrix flaw. As SecurityWeek reports, attackers began hitting Citrix NetScaler appliances almost the moment a new CitrixBleed-class vulnerability went public, using ready-made proof-of-concept code to pull sensitive memory straight out of the device. Around the same time, The Hacker News reported that affiliates of the Anubis ransomware operation are using Citrix Bleed 2 (CVE-2025-5777) as their way in.

The reason this class of bug is so dangerous is what leaks out of that memory: session tokens. A stolen token lets an attacker resume a logged-in session without ever touching a password or a multi-factor prompt, which is why the original CitrixBleed was so destructive and why this successor is being weaponized so fast. NetScaler sits at the network edge by design, so compromising it means the attacker is already inside.

What makes the timeline itself the story is that there was no grace period. Disclosure and exploitation happened in the same breath, in public view. That is the clearest possible argument against point-in-time security: the moment of maximum risk is the moment a flaw becomes known, and any defense operating on a weekly or quarterly rhythm is structurally too slow to matter. Edge appliances are exactly where always-on verification earns its keep.

Patch all NetScaler ADC and Gateway appliances now, and then do the step people forget, terminate every active session, because a patch does not invalidate tokens an attacker already stole from memory. After that, hunt for remote-management tools you did not deploy, a common footprint once Anubis-style actors are through the door, and treat any unpatched, internet-facing NetScaler as compromised rather than merely vulnerable.

Sources: SecurityWeek and The Hacker News.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.