CitrixBleed 2 is a vulnerability tracked by ThreatCluster, appearing in 8 threat clusters built from 12 intelligence report mentions.
CitrixBleed 2 is a vulnerability tracked across 8 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed November 12, 2025; most recent activity July 6, 2026.
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
Between June 29 and July 6, 2026, GreyNoise observed a significant increase in exploitation attempts targeting Palo Alto GlobalProtect CVE-2019-1579, with over 120 malicious hosts detected on July 6. This activity was…
Cloud Software Group has identified and patched two critical vulnerabilities in Citrix NetScaler ADC and Gateway products. The vulnerabilities, tracked as CVE-2026-3055, allow unauthenticated remote attackers to exploit…
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
A low-skilled attacker exploited AI agents Claude and Codex to breach 14 companies. Researchers from OALABS analyzed over 1,000 sessions from a compromised server, revealing how the attacker bypassed security measures…
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
In 2025, the number of known exploited vulnerabilities in CISA's KEV catalog increased by 20%, with 245 new vulnerabilities added. However, research from Miggo Security indicates that the catalog may only represent 12%…
CitrixBleed 2 is a vulnerability tracked by ThreatCluster, appearing in 8 threat clusters built from 12 intelligence report mentions.
The most recent intelligence report mentioning CitrixBleed 2 on ThreatCluster is dated July 6, 2026. Activity was first observed November 12, 2025, giving a tracked span from then to July 6, 2026.
Across ThreatCluster reporting, CitrixBleed 2 most frequently co-occurs with Data Breach, Malware, Phishing, Ransomware, Zero-day Exploit, among 12 tracked related entities.
The most significant recent cluster is “Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities” (8 articles · Updated November 12, 2025). CitrixBleed 2 appears across 8 threat clusters in total, listed above with sources.
CitrixBleed 2 appears in 12 intelligence report mentions across 8 deduplicated threat clusters, aggregated from 17,000+ monitored sources.