news.mlab.sh
2 results
ransomware

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like ScreenConnect and Zoho Assist, combined with stolen VPN credentials and techniques like credential stuffi…

The Hacker News · Jul 2, 2026 High