Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Spoofed Tankers Are Flooding the Strait of Hormuz. These Analysts Are Tracking Them
    • Polymarket is in talks to raise $400M at a ~$15B post-money valuation, up from $9B in October 2025, but below Kalshi’s $22B valuation from March 2026 (The Information)
    • Today’s NYT Connections: Sports Edition Hints, Answers for April 20 #574
    • Will Humans Live Forever? AI Races to Defeat Aging
    • AI evolves itself to speed up scientific discovery
    • Australia’s privacy commissioner tried, in vain, to sound the alarm on data protection during the u16s social media ban trials
    • Nothing Phone (4a) Pro Review: A Close Second
    • Match Group CEO Spencer Rascoff says growing women’s share on Tinder is his “primary focus” to stem user declines; Sensor Tower says 75% of Tinder users are men (Kieran Smith/Financial Times)
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Monday, April 20
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Critical CitrixBleed 2 vulnerability has been under active exploit for weeks
    News

    Critical CitrixBleed 2 vulnerability has been under active exploit for weeks

    Editor Times FeaturedBy Editor Times FeaturedJuly 9, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    A vital vulnerability permitting hackers to bypass multifactor authentication in community administration gadgets made by Citrix has been actively exploited for greater than a month, researchers mentioned. The discovering is at odds with advisories from the seller saying there isn’t any proof of in-the-wild exploitation.

    Tracked as CVE-2025-5777, the vulnerability shares similarities with CVE-2023-4966, a safety flaw nicknamed CitrixBleed, which led to the compromise of 20,000 Citrix devices two years in the past. The checklist of Citrix prospects hacked within the CitrixBleed exploitation spree included Boeing, Australian transport firm DP World, Business Financial institution of China, and the Allen & Overy regulation agency. A Comcast community was also breached, permitting menace actors to steal password information and different delicate data belonging to 36 million Xfinity prospects.

    Giving attackers a head begin

    Each CVE-2025-5777 and CVE-2023-4966 reside in Citrix’s NetScaler Utility Supply Controller and NetScaler Gateway, which offer load balancing and single sign-on in enterprise networks, respectively. The vulnerability causes susceptible gadgets to leak—or “bleed”—small chunks of reminiscence contents after receiving modified requests despatched over the Web.

    By repeatedly sending the identical requests, hackers can piece collectively sufficient information to reconstruct credentials. The unique CitrixBleed had a severity score of 9.8. CitrixBleed 2 has a severity score of 9.2.

    Citrix disclosed the newer vulnerability and launched a safety patch for it on June 17. In an update printed 9 days later, Citrix mentioned it was “at the moment unaware of any proof of exploitation.” The corporate has supplied no updates since then.

    Researchers, nonetheless, say that they’ve discovered proof that CitrixBleed 2, because the newer vulnerability is being referred to as, has been actively exploited for weeks. Safety agency Greynoise said Monday {that a} search by means of its honeypot logs discovered exploitation as early as July 1. On Tuesday, unbiased researcher Kevin Beaumont said telemetry from those self same honeypot logs signifies that CitrixBleed 2 has been exploited since a minimum of June 23, three days earlier than Citrix mentioned it had no proof of such assaults.

    Citrix’s failure to reveal lively exploitation is just one of many particulars researchers say was lacking from the advisories. Final week, safety agency watchTowr printed a post titled “How A lot Extra Should We Bleed? – Citrix NetScaler Reminiscence Disclosure (CitrixBleed 2 CVE-2025-5777).” It criticized Citrix for withholding indicators that prospects may use to find out if their networks have been underneath assault. On Monday, fellow safety agency Horizon3.ai said a lot the identical factor. Firm researchers wrote:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Polymarket is in talks to raise $400M at a ~$15B post-money valuation, up from $9B in October 2025, but below Kalshi’s $22B valuation from March 2026 (The Information)

    April 20, 2026

    Match Group CEO Spencer Rascoff says growing women’s share on Tinder is his “primary focus” to stem user declines; Sensor Tower says 75% of Tinder users are men (Kieran Smith/Financial Times)

    April 20, 2026

    Sources say NSA is using Mythos Preview, and a source says it is also being used widely within the DoD, despite Anthropic’s designation as a supply chain risk (Axios)

    April 19, 2026

    Vercel says it detected unauthorized access to its internal systems after a hacker using the ShinyHunters handle claimed a breach on BreachForums (Lawrence Abrams/BleepingComputer)

    April 19, 2026

    A look at Dylan Patel’s SemiAnalysis, an AI newsletter and research firm that expects $100M+ in 2026 revenue from subscriptions and AI supply chain research (Abram Brown/The Information)

    April 19, 2026

    Google is in talks with Marvell Technology to develop a memory processing unit that works alongside TPUs, and a new TPU for running AI models (Qianer Liu/The Information)

    April 19, 2026

    Comments are closed.

    Editors Picks

    Spoofed Tankers Are Flooding the Strait of Hormuz. These Analysts Are Tracking Them

    April 20, 2026

    Polymarket is in talks to raise $400M at a ~$15B post-money valuation, up from $9B in October 2025, but below Kalshi’s $22B valuation from March 2026 (The Information)

    April 20, 2026

    Today’s NYT Connections: Sports Edition Hints, Answers for April 20 #574

    April 20, 2026

    Will Humans Live Forever? AI Races to Defeat Aging

    April 20, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Google’s Latest Enticement for Its AI Pro Plan: 5TB of Cloud Storage

    April 2, 2026

    How many Windows 10 PCs are still in use? No one knows, but they try to tell you anyway

    February 4, 2025

    Gear News of the Week: Google’s Pixel 10a Arrives Soon, and Valve Delays Its Steam Hardware

    February 8, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.