CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware

Reported 09 Jul 2026 by otx · Severity: medium

Between January and June 2026, multiple unrelated organizations experienced nearly identical intrusions following a standardized seven-step attack chain. The attacks exploited CitrixBleed 2 (CVE-2025-5777), a memory-overread vulnerability in NetScaler ADC and Gateway appliances.