Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, and AI Coding Attacks
ID: f1de5260-78bc-5f85-ad03-eb57c7e0d587
STIX ID: report--f1de5260-78bc-5f85-ad03-eb57c7e0d587
Feed Name: CosmicBytez Labs
The Hacker News weekly recap reports several active, high-risk incidents: Progress Software ordered immediate shutdown of self-hosted ShareFile Storage Zone Controller servers (likely unpatched zero-day or compromise); Citrix NetScaler CVE-2025-5777 is being actively exploited by ransomware groups (DragonForce and Anubis) using a shared seven-step playbook that bypasses MFA and results in large-scale ransomware deployments; researchers also demonstrated prompt-injection chains leading to remote code execution across multiple AI coding assistants, while a new phishing-as-a-service (Forg365) and thousands of exposed MCP servers expand the threat surface—organizations are advised to shut affected services, patch immediately, terminate sessions, and audit for compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
