🚨 ACTIVE EXPLOITS & INCIDENTS
- New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure – SecurityWeek Attackers are actively exploiting the CitrixBleed vulnerability (NetScaler appliances) using publicly available PoC code to leak arbitrary memory via HTTP responses. Immediate patching or mitigation is critical to prevent data leakage and lateral movement.
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials – The Hacker News Anubis ransomware affiliates are leveraging CVE-2025-5777 (Citrix Bleed 2) for initial access, combining this with legitimate RMM tools and supply chain credential theft. This highlights evolving ransomware TTPs emphasizing hands-on-keyboard operations and supply chain attack vectors.
- FortiBleed Campaign Traced to INC and Lynx Ransomware Operations – Cybersecurity Dive Ongoing FortiBleed exploitation campaigns have been linked to INC and Lynx ransomware groups. Researchers suspect a zero-day vulnerability may be involved, underscoring the need for heightened monitoring of Fortinet appliance traffic and logs.
- FBI Seizes NetNut Proxy Platform, Popa Botnet – Krebs on Security The FBI, collaborating with industry partners, seized hundreds of domains tied to NetNut, a massive residential proxy network linked to the Popa botnet controlling ~2 million compromised devices. This disrupts a major infrastructure used for anonymizing malicious traffic and botnet operations.
- Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices – The Hacker News Google’s Threat Intelligence Group, working with the FBI and Lumen, has significantly degraded NetNut’s proxy pool by millions of devices. This coordinated takedown targets abuse of home devices as rented relays for illicit traffic, impacting multiple threat actor campaigns.
🔓 VULNERABILITIES & CVEs
- Citrix Bleed 2 (CVE-2025-5777, CVSS 8.7) – Actively exploited for arbitrary memory disclosure on NetScaler appliances. Immediate patching or network segmentation recommended.
- FortiBleed (suspected zero-day) – Under investigation but linked to active ransomware campaigns; Fortinet customers should monitor for unusual activity and apply any emergency mitigations.
🕵️ THREAT RESEARCH & DEEP DIVES
- ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories – The Hacker News A broad analysis reveals systemic weaknesses across browsers, bots, sandboxes, AI systems, and email flows. The common thread is exploitation of small permission gaps and weak checks rather than single catastrophic flaws, emphasizing the need for layered defense and continuous validation of trust boundaries.
- The Gentlemen Ransomware: What You Need to Know – Graham Cluley / Fortra Profile of the “Gentlemen” ransomware gang reveals aggressive tactics and evolving extortion methods. Understanding their tradecraft aids detection and response planning for organizations facing emerging ransomware threats.
🚀 PRODUCT LAUNCHES & UPDATES
- Real-Time Observability: Introducing Akamai Cloud Pulse Alerts – Akamai Blog Akamai launches Cloud Pulse Alerts, a real-time observability tool designed to enhance cloud security monitoring and incident response through immediate alerting on anomalous activity. Early adopters should evaluate integration for improved situational awareness.
📰 LESSER-KNOWN / UNDER-REPORTED
- Most Cybersecurity Workers Have Been Told to Conceal a Breach, Report Finds – Cybersecurity Dive Bitdefender’s report highlights a troubling trend where many cybersecurity professionals are pressured to hide breach incidents. U.S. firms show higher confidence in cyber defense but also report greater operational strain, suggesting cultural and resource challenges impacting incident transparency.