CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware
Reported 09 Jul 2026 by otx · Severity: medium
Between January and June 2026, multiple unrelated organizations experienced nearly identical intrusions following a standardized seven-step attack chain. The attacks exploited CitrixBleed 2 (CVE-2025-5777), a memory-overread vulnerability in NetScaler ADC and Gateway appliances.