NetNut seized; Citrix Bleed 2 exploited; ToddyCat hijacks Gmail via OAuth
ID: 6d082311-1129-5559-a59e-4499ac04bcc4
STIX ID: report--6d082311-1129-5559-a59e-4499ac04bcc4
Feed Name: defend.network
This briefing reports multiple high-priority threats: Google/FBI actions degraded the NetNut residential proxy network abused for fraud and account takeover; Citrix Bleed 2 (CVE-2025-5777) is being actively exploited by Anubis ransomware affiliates; ToddyCat’s Umbrij malware is abusing Google OAuth to access corporate Gmail; and ConsentFix/ClickFix campaigns are stealing Microsoft 365 tokens by abusing OAuth consent flows — recommended actions include urgent Citrix patching, auditing OAuth consents, blocking NetNut-related infrastructure, and tightening conditional access policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
