Citrix provides additional measures to address Citrix BleedSecurity Affairs·Nov 22, 08:15 UTC · Nov 22, 2023RansomwareCVE-2023-496660
Citrix Bleed 2 Flaw Enables Token Theft; SAP GUI Flaws Risk Sensitive Data ExposureThe Hacker News·Jun 27, 10:45 UTC · Jun 27, 2025Ransomware in the wildCVE-2025-0055CVE-2025-0056CVE-2025-0059+2 CVEs60
FIN8-linked actor targets Citrix NetScaler systemsSecurity Affairs·Aug 29, 15:14 UTC · Aug 29, 2023RansomwareCVE-2023-351960
Citrix warns of exploitation of Netscaler devices through new bugsThe Record·Jun 25, 20:23 UTC · Jun 25, 2025RansomwareCVE-2025-6543CVE-2025-5349CVE-2025-577760
Citrix NetScaler customers hit by third actively exploited zeroCyberScoop·Aug 26, 21:28 UTC · Aug 26, 2025Ransomware in the wildCVE-2025-7775CVE-2025-7776CVE-2025-8424+3 CVEs60
Ransomware group exploits Citrix NetScaler systems for initial accessHelp Net Security·Aug 29, 00:00 UTC · Aug 29, 2023Ransomware in the wildCVE-2023-351960
Citrix NetScaler Alert: Ransomware Hackers Exploiting Critical VulnerabilityThe Hacker News·Aug 30, 03:26 UTC · Aug 30, 2023RansomwareCVE-2023-351960
New Ransomware Campaign Targets Citrix NetScaler FlawInfosecurity Magazine·Aug 29, 16:30 UTC · Aug 29, 2023RansomwareCVE-2023-351960
August 2025 CVE LandscapeRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware in the wildCVE-2025-8088CVE-2025-7775CVE-2025-57819+5 CVEs60
Citrix users hit by actively exploited zeroCyberScoop·Jun 25, 20:38 UTC · Jun 25, 2025Ransomware in the wildCVE-2025-6543CVE-2025-5777CVE-2025-5349+1 CVEs60
In alerting about two Citrix bugs, CISA recommends immediate attention for oneThe Record·Jan 18, 20:42 UTC · Jan 18, 2024Ransomware in the wildCVE-2023-6548CVE-2023-654960
Cyber experts and officials raise alarms about exploits against Citrix and Apache productsThe Record·Nov 3, 18:13 UTC · Nov 3, 2023Ransomware in the wildCVE-2023-46604CVE-2023-496660
LockBit Reigns Supreme in Soaring Ransomware LandscapeInfosecurity Magazine·Feb 2, 10:30 UTC · Feb 2, 2024Ransomware60
HHS warns of ‘Citrix Bleed’ attacks after hospital outagesThe Record·Dec 1, 22:06 UTC · Dec 1, 2023Ransomware in the wildCVE-2023-496660
How LockBit used Citrix Bleed to breach Boeing and other targetsHelp Net Security·Nov 22, 00:00 UTC · Nov 22, 2023Ransomware in the wildCVE-2023-496660
Industrial and Commercial Bank of China dealing with LockBit ransomware attackThe Record·Nov 9, 21:55 UTC · Nov 9, 2023RansomwareCVE-2023-496660
Week in review: VPNs vulnerable to TunnelCrack attacks, Cybertech Africa 2023Help Net Security·Aug 20, 00:00 UTC · Aug 20, 2023Ransomware in the wildCVE-2023-32560CVE-2023-3519CVE-2023-2448960
Pennsylvania attorney general says SSNs stolen during August ransomware attackThe Record·Nov 17, 19:58 UTC · Nov 17, 2025RansomwareCVE-2025-577760
‘Advanced’ hacker seen exploiting Cisco, Citrix zeroThe Record·Nov 12, 18:17 UTC · Nov 12, 2025RansomwareCVE-2025-5777CVE-2025-2033760
Pennsylvania AG says recovery continues after office refused to pay ransomware gangThe Record·Sep 2, 18:35 UTC · Sep 2, 2025RansomwareCVE-2025-577760
What happened in Vegas (that you actually want to know about)Cisco Talos·Aug 14, 18:00 UTC · Aug 14, 2025RansomwareCVE-2025-654360
Security Affairs newsletter Round 531 by Pierluigi PaganiniSecurity Affairs·Jul 6, 04:54 UTC · Jul 6, 2025Ransomware in the wildCVE-2025-6543CVE-2025-655460
Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal ConflictsThe Hacker News·Feb 27, 05:08 UTC · Feb 27, 2025Ransomware in the wildCVE-2024-50623CVE-2009-3960CVE-2010-2861+8 CVEs60
INC Ransom Claims CyberInfosecurity Magazine·Nov 29, 11:50 UTC · Nov 29, 2024RansomwareCVE-2023-496660
Report Reveals Record Exploitation Rate For Load BalancersInfosecurity Magazine·Jun 18, 11:00 UTC · Jun 18, 2024Ransomware in the wildCVE-2023-496660
LockBit Ransomware Exploiting Critical Citrix Bleed Vulnerability to Break InThe Hacker News·Nov 22, 11:59 UTC · Nov 22, 2023RansomwareCVE-2023-496660
LockBit ransomware gang leaked data stolen from BoeingSecurity Affairs·Nov 13, 14:02 UTC · Nov 13, 2023Ransomware in the wildCVE-2023-496660
Industrial and Commercial Bank of China (ICBC) suffered a ransomware attackSecurity Affairs·Nov 10, 11:11 UTC · Nov 10, 2023Ransomware in the wildCVE-2023-496660
July 2026 CVE LandscapeRecorded Future·Aug 7, 00:00 UTC · Aug 7, 2026Ransomware in the wildCVE-2025-3248CVE-2008-4128CVE-2017-17215+78 CVEs160
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreThe Hacker News·Aug 4, 12:16 UTC · Aug 4, 2026RansomwareCVE-2026-50746CVE-2026-50747CVE-2026-50748+45 CVEs60
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News·Jul 30, 15:25 UTC · Jul 30, 2026RansomwareCVE-2026-33017CVE-2026-21858CVE-2025-68613+5 CVEs60
Ransomware Groups Increasingly Deploy EDR Kill TechniquesInfosecurity Magazine·Jul 27, 10:01 UTC · Jul 27, 2026RansomwareCVE-2025-5777CVE-2024-40766CVE-2024-5559160
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain CredentialsThe Hacker News·Jul 3, 14:36 UTC · Jul 3, 2026RansomwareCVE-2025-577760
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023The Hacker News·Jun 18, 14:12 UTC · Jun 18, 2026RansomwareCVE-2023-3519CVE-2025-5777CVE-2023-48788+1 CVEs160
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC ZeroRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2017-7921CVE-2026-27483CVE-2026-27944+10 CVEs260
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & MoreThe Hacker News·Mar 19, 14:25 UTC · Mar 19, 2026Ransomware in the wildCVE-2024-55591CVE-2025-71257CVE-2025-71258+4 CVEs60
Half of Ransomware Access Due to Hijacked VPN CredentialsInfosecurity Magazine·Nov 19, 09:40 UTC · Nov 19, 2025RansomwareCVE-2025-53770CVE-2025-54309CVE-2025-20333+2 CVEs60
Security Affairs newsletter Round 539 by Pierluigi PaganiniSecurity Affairs·Aug 31, 05:51 UTC · Aug 31, 2025Ransomware in the wildCVE-2025-9074CVE-2025-7775CVE-2025-53786160
Storm-0501 Exploits Entra ID to Exfiltrate and Delete Azure Data in Hybrid Cloud AttacksThe Hacker News·Aug 28, 03:58 UTC · Aug 28, 2025Ransomware60
Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57