logo

Tech Brief - Citrix Bleed Abused by Ransomware Crews

ID: 14b235ec-ddf5-55e7-aa6b-eb3cb5472d47

STIX ID: report--14b235ec-ddf5-55e7-aa6b-eb3cb5472d47

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

Executive Summary: TrustedSec warns that the Citrix NetScaler vulnerability CVE-2023-4966 ("Citrix Bleed") is being actively abused by ransomware crews to hijack sessions and move laterally — an observed incident allowed access impacting 60 credit unions. The brief highlights limited NetScaler logging and detection gaps and recommends improving log collection, developing detections for attack paths, and rehearsing incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.