#citrixbleed
New by me - although Citrix say there is no evidence of exploitation of CitrixBleed 2 vulnerability, they are wrong - it has been under active exploitation since mid June by an IP associated to a ransomware group, with multiple IP addresses now involved.

doublepulsar.com/citrixbleed-...
CitrixBleed 2 exploitation started mid-June — how to spot it
CitrixBleed 2 — CVE-2025–5777 — has been under active exploitation to hijack Netscaler sessions, bypassing MFA, globally for a month.
doublepulsar.com
July 8, 2025 at 2:46 PM
citrix finally admitted Citrix Bleed 2 is under exploitation!

by not commenting to press and then editing an old blog post doublepulsar.com/citrixbleed-...
CitrixBleed 2 situation update — everybody already got owned
Citrix acknowledge exploitation finally.
doublepulsar.com
July 14, 2025 at 7:13 PM
I’m tracking 128 active CitrixBleed 2 victims in telemetry, today, from attacker infrastructure (one threat actor group).
July 11, 2025 at 8:45 AM
CitrixBleed 2 - internet scan data for vulnerability

raw.githubusercontent.com/GossiTheDog/...

+8k new hosts today

Over 3k orgs still unpatched a month after patch, and despite China and Russia exploitation in June + widespread exploitation this week.

Background: doublepulsar.com/citrixbleed-...
raw.githubusercontent.com
July 15, 2025 at 9:46 PM
June 24, 2025 at 5:58 PM
They've also botched the patching instructions, by not instructing people to clear sessions where cookies could have been stolen - so still vuln to session hijack after patching.

First screenshot = CitrixBleed 2 support page
Second screenshot = CitrixBleed 1 support page
July 10, 2025 at 5:32 PM
🩸& #threatintel | We (GreyNoise) just published a quick note (www.greynoise.io/blo...) regarding CVE-2025-5777 - CitrixBleed 2
1/2
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
www.greynoise.io
July 16, 2025 at 9:05 PM
GreyNoise observed exploitation of CitrixBleed 2 (CVE-2025-5777) nearly two weeks before a public PoC was released. Full breakdown ⬇️
#GreyNoise #ThreatIntel #CitrixBleed #Citrix #NetScaler
Exploitation of CitrixBleed 2 (CVE-2025-5777) Began Before PoC Was Public
GreyNoise has observed active exploitation attempts against CVE-2025-5777 (CitrixBleed 2), a memory overread vulnerability in Citrix NetScaler. Exploitation began on June 23 — nearly two weeks before a public proof-of-concept was released on July 4.
www.greynoise.io
July 16, 2025 at 8:45 PM
Now everybody but Citrix agrees that CitrixBleed 2 is under exploit
Now everybody but Citrix agrees that CitrixBleed 2 is under exploit
Add CISA to the list The US Cybersecurity and Infrastructure Security Agency has added its weighty name to the list of parties agreeing that CVE-2025-5777, dubbed CitrixBleed 2 by one researcher, has been under exploitation and abused to hijack user sessions.…
dlvr.it
July 10, 2025 at 10:17 PM
CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands
CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands
NetScaler vendor issued a patch but otherwise, stony silence Multiple exploits are circulating for CVE-2025-5777, a critical bug in Citrix NetScaler ADC and NetScaler Gateway dubbed CitrixBleed 2, and security analysts are warning a "significant portion" of users still haven't patched.…
dlvr.it
July 7, 2025 at 8:37 PM
-Major vulnerability can bring trains to sudden stops
-Researchers spot a Lazarus backdoor attack targeting crypto contracts
-Spain hands Huawei control over its wiretapping system
-CISA warns of CitrixBleed 2 attacks

Newsletter: news.risky.biz/risky-bullet...
Podcast: risky.biz/RBNEWS451/
July 14, 2025 at 7:59 AM
A recent vulnerability in Citrix NetScaler ADC and Gateway is dubbed "CitrixBleed 2," after its similarity to an older exploited flaw that allowed unauthenticated attackers to hijack authentication session cookies from vulnerable devices.
New ‘CitrixBleed 2’ NetScaler flaw let hackers hijack sessions
A recent vulnerability in Citrix NetScaler ADC and Gateway is dubbed "CitrixBleed 2," after its similarity to an older exploited flaw that allowed unauthenticated attackers to hijack authentication session cookies from vulnerable devices.
www.bleepingcomputer.com
June 25, 2025 at 4:10 PM
Now everybody but Citrix agrees that CitrixBleed 2 is under exploit
CISA agrees that CitrixBleed 2 is under exploit
: Add CISA to the list
www.theregister.com
July 10, 2025 at 10:36 PM
Now everybody but Citrix agrees that CitrixBleed 2 is under exploit
CISA agrees that CitrixBleed 2 is under exploit
: Add CISA to the list
www.theregister.com
July 10, 2025 at 11:30 PM
Citrix has patched two NetScaler ADC and NetScaler Gateway vulnerabilities, one of which is very similar to the CitrixBleed and CitrixBleed2 flaws exploited in zero-day attacks in recent years.
Citrix urges admins to patch NetScaler flaws as soon as possible
Citrix has patched two NetScaler ADC and NetScaler Gateway vulnerabilities, one of which is very similar to the CitrixBleed and CitrixBleed2 flaws exploited in zero-day attacks in recent years.
www.bleepingcomputer.com
March 25, 2026 at 3:52 PM