Citrix Bleed 2 — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
November 12, 2025
Last Seen
November 20, 2025

Related Threat Clusters

  • Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities

    An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…

    8 articles · Updated November 12, 2025
  • FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…

    100 articles · Updated November 15, 2025
  • APT Exploits Zero-Day Vulnerabilities in Cisco and Citrix Systems

    An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…

    16 articles · Updated November 18, 2025
  • Ransomware Attack in Pennsylvania Exposes Personal and Medical Data

    The Pennsylvania Attorney General's Office confirmed that a ransomware attack in August 2025, attributed to the INC ransomware group, resulted in the theft of personal information, including names, Social Security…

    43 articles · Updated November 18, 2025
  • Shift in Ransomware Tactics Targeting Cloud Assets

    Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…

    56 articles · Updated November 19, 2025
  • Pennsylvania AG Confirms Ransomware Data Breach by INC Group

    The Pennsylvania Office of the Attorney General confirmed that personal and medical information was stolen during an August 2025 ransomware attack attributed to the INC ransomware-as-a-service operation. Although the…

    2 articles · Updated November 18, 2025

Recent Intelligence Reports

  • Stolen VPN Credentials Most Common Ransomware Attack Vector — Thecyberexpress · November 20, 2025
  • Ransomware-related breach confirmed by Pennsylvania Attorney General's Office — Scworld · November 18, 2025
  • Pennsylvania AG confirms data breach after INC Ransom attack — Bleepingcomputer · November 17, 2025
  • Zero-day attacks against Cisco ISE, Citrix NetScaler observed — Scworld · November 13, 2025
  • Zero — Csoonline · November 13, 2025
  • Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks — Bleepingcomputer · November 12, 2025
  • Hackers exploited Citrix, Cisco ISE flaws in zero — Bleepingcomputer · November 12, 2025

CVSS v3.1 Breakdown