Citrix provides additional measures to address Citrix BleedSecurity Affairs·Nov 22, 08:15 UTC · Nov 22, 2023RansomwareCVE-2023-496660
Citrix NetScaler customers hit by third actively exploited zeroCyberScoop·Aug 26, 21:28 UTC · Aug 26, 2025Ransomware in the wildCVE-2025-7775CVE-2025-7776CVE-2025-8424+3 CVEs60
Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57
Citrix users hit by actively exploited zeroCyberScoop·Jun 25, 20:38 UTC · Jun 25, 2025Ransomware in the wildCVE-2025-6543CVE-2025-5777CVE-2025-5349+1 CVEs60
HHS warns of ‘Citrix Bleed’ attacks after hospital outagesThe Record·Dec 1, 22:06 UTC · Dec 1, 2023Ransomware in the wildCVE-2023-496660
FIN8-linked actor targets Citrix NetScaler systemsSecurity Affairs·Aug 29, 15:14 UTC · Aug 29, 2023RansomwareCVE-2023-351960
Citrix warns of exploitation of Netscaler devices through new bugsThe Record·Jun 25, 20:23 UTC · Jun 25, 2025RansomwareCVE-2025-6543CVE-2025-5349CVE-2025-577760
China-linked hackers target gov agencies by exploiting known flawsSecurity Affairs·Sep 15, 09:16 UTC · Sep 15, 2020RansomwareCVE-2020-5902CVE-2019-19781CVE-2019-11510+1 CVEs60
Citrix Bleed 2 Flaw Enables Token Theft; SAP GUI Flaws Risk Sensitive Data ExposureThe Hacker News·Jun 27, 10:45 UTC · Jun 27, 2025Ransomware in the wildCVE-2025-0055CVE-2025-0056CVE-2025-0059+2 CVEs60
How LockBit used Citrix Bleed to breach Boeing and other targetsHelp Net Security·Nov 22, 00:00 UTC · Nov 22, 2023Ransomware in the wildCVE-2023-496660
Ransomware group exploits Citrix NetScaler systems for initial accessHelp Net Security·Aug 29, 00:00 UTC · Aug 29, 2023Ransomware in the wildCVE-2023-351960
August 2025 CVE LandscapeRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware in the wildCVE-2025-8088CVE-2025-7775CVE-2025-57819+5 CVEs60
Analyzing the Threat of Ransomware Attacks Against US ElectionsRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware60
‘Advanced’ hacker seen exploiting Cisco, Citrix zeroThe Record·Nov 12, 18:17 UTC · Nov 12, 2025RansomwareCVE-2025-5777CVE-2025-2033760
CISA Urges Patching of Actively Exploited Citrix BugInfosecurity Magazine·Aug 17, 10:30 UTC · Aug 17, 2023Ransomware in the wildCVE-2023-2448960
Citrix security boss warns that cryptojackers are exploiting cloud ignoranceCyberScoop·Dec 3, 21:49 UTC · Dec 3, 2018Ransomware in the wild60
In alerting about two Citrix bugs, CISA recommends immediate attention for oneThe Record·Jan 18, 20:42 UTC · Jan 18, 2024Ransomware in the wildCVE-2023-6548CVE-2023-654960
LockBit Ransomware Exploiting Critical Citrix Bleed Vulnerability to Break InThe Hacker News·Nov 22, 11:59 UTC · Nov 22, 2023RansomwareCVE-2023-496660
Cyber experts and officials raise alarms about exploits against Citrix and Apache productsThe Record·Nov 3, 18:13 UTC · Nov 3, 2023Ransomware in the wildCVE-2023-46604CVE-2023-496660
Citrix NetScaler Alert: Ransomware Hackers Exploiting Critical VulnerabilityThe Hacker News·Aug 30, 03:26 UTC · Aug 30, 2023RansomwareCVE-2023-351960
New Ransomware Campaign Targets Citrix NetScaler FlawInfosecurity Magazine·Aug 29, 16:30 UTC · Aug 29, 2023RansomwareCVE-2023-351960
Week in review: Citrix bug under attack, Windows 7 ransomware risk, ATT&CK for ICSHelp Net Security·Jan 12, 00:00 UTC · Jan 12, 2020Ransomware in the wildCVE-2019-19781CVE-2019-17026CVE-2019-221560
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreThe Hacker News·Aug 4, 12:16 UTC · Aug 4, 2026RansomwareCVE-2026-50746CVE-2026-50747CVE-2026-50748+45 CVEs60
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThe Hacker News·Jul 3, 14:36 UTC · Jul 3, 2026RansomwareCVE-2025-577760
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & MoreThe Hacker News·Mar 19, 14:25 UTC · Mar 19, 2026Ransomware in the wildCVE-2024-55591CVE-2025-71257CVE-2025-71258+4 CVEs60
Week in review: LockBit exploits Citrix Bleed, Apache ActiveMQ bug exploited for cryptojackingHelp Net Security·Nov 26, 00:00 UTC · Nov 26, 2023Ransomware in the wildCVE-2023-4966CVE-2023-1671CVE-2023-4660460
Week in review: Windows crypto flaw, API security risks, exploits for Citrix security hole aboundHelp Net Security·May 28, 11:21 UTC · May 28, 2020RansomwareCVE-2019-19494CVE-2019-19781CVE-2020-060160
Week in review: Kubernetes security challenges, NIST Privacy Framework, Mitsubishi Electric breachHelp Net Security·Jan 26, 00:00 UTC · Jan 26, 2020Ransomware in the wildCVE-2019-19781CVE-2020-067460
Industrial and Commercial Bank of China (ICBC) suffered a ransomware attackSecurity Affairs·Nov 10, 11:11 UTC · Nov 10, 2023Ransomware in the wildCVE-2023-496660
Friday Squid Blogging: Fossil of Squid Eating and Being EatenSchneier on Security·Jun 11, 21:18 UTC · Jun 11, 2021Ransomware57
Cruise line operator Carnival Corporation suffers a ransomware attackSecurity Affairs·Aug 18, 08:21 UTC · Aug 18, 2020RansomwareCVE-2019-19781CVE-2020-202160
CLOP Ransomware operators hacked IndiaBulls GroupSecurity Affairs·Jun 23, 09:55 UTC · Jun 23, 2020RansomwareCVE-2019-1978160
FortiBleed Credential Theft Linked to INC and Lynx Ransomware OperationsThe Hacker News·Jul 2, 13:05 UTC · Jul 2, 2026RansomwareCVE-2026-3561660
IR Q4 2023 trends: Significant increase in ransomware activity found in engagements, while education remains one of the mostCisco Talos·Jan 24, 13:00 UTC · Jan 24, 2024RansomwareCVE-2020-147260
LockBit ransomware gang leaked data stolen from BoeingSecurity Affairs·Nov 13, 14:02 UTC · Nov 13, 2023Ransomware in the wildCVE-2023-496660
Chinese multinational bank hit by ransomwareHelp Net Security·Nov 10, 00:00 UTC · Nov 10, 2023RansomwareCVE-2023-496660
Threat Source newsletter (Jan. 30, 2020)Cisco Talos·Jan 30, 19:00 UTC · Jan 30, 2020RansomwareCVE-2019-1978160
Pennsylvania attorney general says SSNs stolen during August ransomware attackThe Record·Nov 17, 19:58 UTC · Nov 17, 2025RansomwareCVE-2025-577760
Pennsylvania AG says recovery continues after office refused to pay ransomware gangThe Record·Sep 2, 18:35 UTC · Sep 2, 2025RansomwareCVE-2025-577760
Security Affairs newsletter Round 539 by Pierluigi PaganiniSecurity Affairs·Aug 31, 05:51 UTC · Aug 31, 2025Ransomware in the wildCVE-2025-9074CVE-2025-7775CVE-2025-53786160