logo

What it means — CitrixBleed ransom group woes grow as over 60 credit unions, hospitals…

ID: aff39153-ffa7-5d4c-b0b1-b9bf1717a4a7

STIX ID: report--aff39153-ffa7-5d4c-b0b1-b9bf1717a4a7

Feed Name: DoublePulsar

Threat Score
85/100

Date Published: 2023-12-03

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

The report outlines widespread active exploitation of the Citrix 'CitrixBleed' Netscaler vulnerability that bypasses MFA and produces no initial exploitation logs, enabling ransomware and extortion groups (e.g., ALPHV/AlphV, LockBit and others) to breach MSPs, credit unions, hospitals and financial firms across the US and internationally; it highlights late patching, supply-chain impacts, mass data theft, and calls for stronger vendor security, transparency on incidents, and policy changes such as outlawing ransom payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.