{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreihfyofljnq4r4t3d7m35ft5ho3hzeppsbtv5u5fbtpmo4ejg6kpaq",
"uri": "at://did:plc:ghkvexthfanuyq7fb5veq6tw/app.bsky.feed.post/3mpoyqxobshx2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreihrs6kyrhwtwhttejt7hcfsyihs7z4vuxrivxoa3tcaft77dqq4fm"
},
"mimeType": "image/jpeg",
"size": 376970
},
"path": "/2026/07/ransomware-groups-turn-to-citrix-bleed.html",
"publishedAt": "2026-07-02T18:30:33.000Z",
"site": "https://thehackernews.com",
"textContent": "Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.\n\n\"Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral",
"title": "Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials"
}