{
  "$type": "site.standard.document",
  "bskyPostRef": {
    "cid": "bafyreihfyofljnq4r4t3d7m35ft5ho3hzeppsbtv5u5fbtpmo4ejg6kpaq",
    "uri": "at://did:plc:ghkvexthfanuyq7fb5veq6tw/app.bsky.feed.post/3mpoyqxobshx2"
  },
  "coverImage": {
    "$type": "blob",
    "ref": {
      "$link": "bafkreihrs6kyrhwtwhttejt7hcfsyihs7z4vuxrivxoa3tcaft77dqq4fm"
    },
    "mimeType": "image/jpeg",
    "size": 376970
  },
  "path": "/2026/07/ransomware-groups-turn-to-citrix-bleed.html",
  "publishedAt": "2026-07-02T18:30:33.000Z",
  "site": "https://thehackernews.com",
  "textContent": "Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.\n\n\"Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral",
  "title": "Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials"
}