Last Week in Ransomware: 12.18.2023
ID: 796f5f09-e590-591e-af61-2519215f5c53
STIX ID: report--796f5f09-e590-591e-af61-2519215f5c53
Feed Name: Halcyon Blog
LockBit operators are actively exploiting the Citrix Bleed vulnerability (CVE-2023-4966) to bypass authentication and hijack sessions, while separate reporting notes a likely law-enforcement disruption of BlackCat/ALPHV leak infrastructure, the abuse of Wyoming-registered LLCs as command-and-control providers, and a UK committee warning the nation faces a high risk of a catastrophic ransomware attack—underscoring active exploitation, infrastructure-enabled attribution challenges, and the need for urgent patching and defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
