Hackers Launch 11.5 Million Attacks on CitrixBleed 2 - Compromising Over 100 Organizations

Security researcher Kevin Beaumont, who first coined the term “CitrixBleed 2,” reported that attackers have been “carefully selecting victims, profiling NetScaler before attacking to make sure it is a real box”. A massive wave of exploitation targeting the critical CitrixBleed 2 vulnerability (CVE-2025-5777), with over 11.5 million attack attempts recorded since its disclosure in June. The attack data reveals a disturbing pattern of targeted exploitation, with financial services organizations bearing the brunt of malicious activity. According to Imperva’s threat intelligence, nearly 40% of all attack attempts have specifically targeted financial services infrastructure, representing approximately 4.6 million attacks against this critical sector. GreyNoise data shows 22 unique malicious IP addresses have been observed attempting exploitation, with activity originating from China, Russia, South Korea, and the United States. This early exploitation window allowed attackers to establish footholds in victim networks before organizations became aware of the threat. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. GreyNoise’s honeypot data confirms that active exploitation began on June 23, 2025, nearly two weeks before proof-of-concept exploits were publicly released on July 4. The exploitation techniques observed include data collection from user Citrix sessions and the installation of legitimate MSP administrative tools for persistence. One IP address associated with recent exploitation activity (64.176.50.109) has been previously linked to RansomHub ransomware operations by CISA. Despite mounting evidence of active exploitation, Citrix maintained until July 11 that there was “no evidence to suggest exploitation of CVE-2025-5777“. Furthermore, Citrix’s own Web Application Firewall product lacks detection capabilities for this vulnerability, despite the company’s claims that WAF solutions cannot effectively mitigate the threat. The remaining 60% of attacks have spread across other industries, indicating both targeted and opportunistic exploitation patterns. With nearly 4,700 NetScaler instances remaining unpatched as of July 17, according to The Shadowserver Foundation, organizations must immediately prioritize remediation efforts. The campaign has successfully compromised more than 100 organizations worldwide, with attackers demonstrating sophisticated victim profiling and persistence techniques that have largely evaded detection. Intelligence sources have confirmed that at least one ransomware group has been leveraging the vulnerability for initial access since June. Significantly, these attacks have “triggered no alerts in their security stack,” highlighting the stealthy nature of the compromise. Security experts have criticized Citrix’s handling of the vulnerability disclosure and remediation guidance. The company’s patching instructions fail to address session cookie clearance, a critical step that leaves organizations vulnerable to session hijacking even after applying patches. The company only updated its advisory after CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog with an unprecedented 24-hour patching mandate for federal agencies. I’m tracking 128 active CitrixBleed 2 victims in telemetry, today, from attacker infrastructure (one threat actor group). The vulnerability’s exploitation timeline demonstrates a concerning gap between initial attacks and public awareness. Beaumont disclosed that a healthcare organization fell victim to such an attack, though the victim requested anonymity due to ongoing remediation efforts.

This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 18 Jul 2025 11:45:14 +0000


Cyber News related to Hackers Launch 11.5 Million Attacks on CitrixBleed 2 - Compromising Over 100 Organizations

CVE-2023-53560 - In the Linux kernel, the following vulnerability has been resolved: ...
1 month ago
CVE-2022-49069 - In the Linux kernel, the following vulnerability has been resolved: ...
8 months ago
Hackers Launch 11.5 Million Attacks on CitrixBleed 2 - Compromising Over 100 Organizations - Security researcher Kevin Beaumont, who first coined the term “CitrixBleed 2,” reported that attackers have been “carefully selecting victims, profiling NetScaler before attacking to make sure it is a real box”. A massive wave ...
3 months ago Cybersecuritynews.com CVE-2025-5777 Ransomhub
"CitrixBleed 2" Vulnerability PoC Released - Warns of Potential Widespread Exploitation - A new critical vulnerability in Citrix NetScaler devices has security experts warning of potential widespread exploitation, drawing alarming parallels to the devastating “CitrixBleed” attacks that plagued organizations in 2023. The ...
4 months ago Cybersecuritynews.com CVE-2025-5777
Xfinity Customer Data Compromised in Attack Exploiting CitrixBleed Vulnerability - Comcast's Xfinity is informing customers that their information has been compromised in a cyberattack that involved exploitation of the vulnerability known as CitrixBleed. CitrixBleed, officially tracked as CVE-2023-4966, is a critical vulnerability ...
1 year ago Securityweek.com CVE-2023-4966
Xfinity Customer Data Compromised in Attack Exploiting CitrixBleed Vulnerability - Comcast's Xfinity is informing customers that their information has been compromised in a cyberattack that involved exploitation of the vulnerability known as CitrixBleed. CitrixBleed, officially tracked as CVE-2023-4966, is a critical vulnerability ...
1 year ago Packetstormsecurity.com CVE-2023-4966
9 Best DDoS Protection Service Providers for 2024 - eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More. One of the most powerful defenses an organization can employ against distributed ...
1 year ago Esecurityplanet.com
CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch - The first warning of CitrixBleed 2 being exploited came from ReliaQuest on June 27. On July 7, security researchers at watchTowr and Horizon3 published proof-of-concept exploits (PoCs) for CVE-2025-5777, demonstrating how the flaw can ...
4 months ago Bleepingcomputer.com CVE-2025-5777
HackerOne paid ethical hackers over $300 million in bug bounties - HackerOne has announced that its bug bounty programs have awarded over $300 million in rewards to ethical hackers and vulnerability researchers since the platform's inception. Thirty hackers have earned over a million USD for their submissions, and ...
1 year ago Bleepingcomputer.com Inception Hunters
Optimizing Cybersecurity: How Hackers Use Golang Source Code Interpreter to Evade Detection - Hackers have been upping the stakes when it comes to executing cyberattacks, and an increasingly popular tool in their arsenal is the Golang source code interpreter. Reportedly, the interpreter is used to obfuscate code, thus making it harder for ...
2 years ago Bleepingcomputer.com
China's MIIT Proposes Color-coded Contingency Plan for Security Incidents - On Friday, China proposed a four-tier classification system, in an effort to address data security incidents, underscoring concerns of Beijing in regards to the widespread data leaks and hacking incidents in the country. This emergency plan comes ...
1 year ago Cysecurity.news
Cybersecurity Industry Gains $1.7 Billion to Develop Cutting-Edge Protection Technologies - As digital threats grow in sophistication, the cybersecurity sector has ignited a funding frenzy, with startups raising $1.7 billion in April 2025 alone ahead of the RSA Conference in San Francisco. As banks and fintechs face a 40% spike in ...
5 months ago Cybersecuritynews.com
Teens with "digital bazookas" are winning the ransomware war, researcher laments - What do Boeing, an Australian shipping company, the world's largest bank, and one of the world's biggest law firms have in common? All four have suffered cybersecurity breaches, most likely at the hands of teenage hackers, after failing to patch a ...
1 year ago Arstechnica.com LockBit
Misconfigured Firebase Instances Expose 125 Million User Records - Hundreds of websites misconfigured Google Firebase, leaking more than 125 million user records, including plaintext passwords, security researchers warn. It all started with the hacking of Chattr, the AI hiring system that serves multiple ...
1 year ago Securityweek.com
The year of Mega Ransomware attacks with unprecedented impact on global organizations - A Staggering 1 in every 10 organizations worldwide hit by attempted Ransomware attacks in 2023, surging 33% from previous year, when 1 in every 13 organisations received ransomware attacks Throughout 2023, organizations around the world have each ...
1 year ago Blog.checkpoint.com
Xfinity Data Breach Impacts 36 Million Individuals - The data breach disclosed recently by Comcast's Xfinity impacts nearly 36 million individuals, the company told US authorities. The incident was disclosed by the telecommunications and smart home solutions provider on December 18, when it admitted ...
1 year ago Securityweek.com CVE-2023-4966
Comcast Xfinity Breached via CitrixBleed; 35M Customers Affected - The now-infamous CitrixBleed vulnerability has claimed possibly its biggest kill yet: 35 million customers of Comcast Xfinity. Since at least August, attackers have been exploiting CVE-2023-4966, a 7.5 high-severity vulnerability affecting Citrix ...
1 year ago Darkreading.com CVE-2023-4966 LockBit
British retailer M&S reportedly set to claim £100 million from insurers after cyberattack | The Record from Recorded Future News - As first reported by the Financial Times newspaper, the attack driving the insurance claim may have cost M&S more than £60 million (about $79.7 million) to date based just on the loss of its daily online sales. Although the estimate can’t ...
5 months ago Therecord.media Dragonforce
Why Have Big Cybersecurity Hacks Surged in 2023? - Payments made to hackers who hold systems hostage for ransom increased by almost half through September, according to blockchain analytics firm Chainalysis Inc., totaling almost $500 million in payouts. In just the past few months, hackers have ...
1 year ago Bloomberg.com LockBit
T-Mobile pays $31.5 million FCC settlement over 4 data breaches - "With companies like T-Mobile and other telecom service providers operating in a space where national security and consumer protection interests overlap, we are focused on ensuring critical technical changes are made to telecommunications networks to ...
1 year ago Bleepingcomputer.com
More than $100 million in ransom paid to Black Basta gang over nearly 2 years - The Black Basta cybercrime gang has raked in at least $107 million in ransom payments since early 2022, according to research from blockchain security company Elliptic and Corvus Insurance. The group has infected more than 329 victim organizations ...
1 year ago Therecord.media FIN7 Black Basta
The past year was the most detrimental for digital currency security breaches, with North Korean organizations profiting. - In 2022, cyberattacks on cryptocurrency platforms resulted in the theft of almost $4 billion, with a large portion of the activity being attributed to hackers working on behalf of the North Korean government. According to blockchain research firm ...
2 years ago Therecord.media Lazarus Group
BlackCat claims attack on Fidelity National Financial The Register - Fortune 500 insurance biz Fidelity National Financial has confirmed that it has fallen victim to a "Cybersecurity incident." The services we provide related to title insurance, escrow and other title-related services, mortgage transaction services, ...
1 year ago Theregister.com CVE-2023-4966 LockBit
North Korea's state hackers stole $3 billion in crypto since 2017 - North Korean-backed state hackers have stolen an estimated $3 billion in a long string of hacks targeting the cryptocurrency industry over the last six years since January 2017. Kimsuky, Lazarus Group, Andariel, and other North Korean hacking groups ...
1 year ago Bleepingcomputer.com Andariel Kimsuky Lazarus Group
Microsoft: BlueNoroff hackers plan new crypto-theft attacks - Microsoft warns that the BlueNoroff North Korean hacking group is setting up new attack infrastructure for upcoming social engineering campaigns on LinkedIn. This financially motivated threat group also has a documented history of cryptocurrency ...
1 year ago Bleepingcomputer.com

Cyber Trends (last 7 days)