What We Know
REST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gapsREST OF WORLD:Constitutional Court vote may influence Puigdemont’s arrest warrant and return to CataloniaGAMING:Control Resonant’s launch hotfix eases combat and strengthens Dylan’s early progressionSPORTS:Maple Leafs acquire Kirill Marchenko from Blue Jackets and sign him to six-year extensionMARKETS:August U.S. Inflation Rose Less Than Expected as Spending Stayed Strong and Price Pressures PersistedCYBERSECURITY:Citrix NetScaler zero-days prompt global alerts and urgent mitigation effortsPOLITICS:Iran-US Nuclear and Hormuz Discussions Continue Amid Mediation and Doubts Over a DealAI:The EU advances AI Act enforcement as draft rules and provider letters emergeTOP STORIES:Ukraine develops affordable interceptor drones as jet-powered threats expose defense gaps
Older than 2 weeksJust now

Anubis Ransomware Hits 91 Victims: Citrix Bleed 2 Bypasses MFA Before Encryption

  • 8 sources analyzed
  • Source mix: Web
  • Momentum: Older than 2 weeks

What We Know

Multiple security reports describe an active Anubis ransomware campaign that investigators link to exploitation of the Citrix “Bleed 2” pre‑authentication flaw (CVE-2025-5777) in Citrix NetScaler/ADC. Reporting says the operation has claimed 91 victims overall, including 11 victims in June 2026, and that attackers have used the Citrix flaw to gain initial access and move to encryption while defeating multi‑factor authentication protections before carrying out encryption.

Analysts from Arctic Wolf and other observers detail a pattern of combined techniques: exploiting CitrixBleed 2, abusing stolen VPN credentials and supply‑chain or service credentials, and leveraging legitimate remote‑management tooling (including RMM products and tunneling tools such as cloudflared, per Arctic Wolf) to maintain access and stage ransomware. Coverage across The Hacker News, InfoSec Today, Techzine, and others highlights that Anubis affiliates are using a mix of credential abuse, BYOVD (bring your own VPN/device) and legitimate‑access techniques rather than relying solely on classic exploit‑and‑encrypt methods.

Source Comparison

Aligned reporting
7 corroborates - 1 adds context - 0 conflicts

Corroborates