Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Nothing Phone (3) Review: A Unique ‘Flagship’ Phone

    Snag a pair of ultra-fast 240W USB-C cables for only $11 right now

    This mini PC with 16GB of RAM is just $157, no Prime necessary

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      AI chatbot Grok issues apology for antisemitic posts

      July 13, 2025

      Apple sued by shareholders for allegedly overstating AI progress

      June 22, 2025

      How far will AI go to defend its own survival?

      June 2, 2025

      The internet thinks this video from Gaza is AI. Here’s how we proved it isn’t.

      May 30, 2025

      Nvidia CEO hails Trump’s plan to rescind some export curbs on AI chips to China

      May 22, 2025
    • Business

      Cloudflare open-sources Orange Meets with End-to-End encryption

      June 29, 2025

      Google links massive cloud outage to API management issue

      June 13, 2025

      The EU challenges Google and Cloudflare with its very own DNS resolver that can filter dangerous traffic

      June 11, 2025

      These two Ivanti bugs are allowing hackers to target cloud instances

      May 21, 2025

      How cloud and AI transform and improve customer experiences

      May 10, 2025
    • Crypto

      3 LetsBONK.fun Ecosystem Tokens To Watch For the Third Week of July

      July 14, 2025

      Bank of England Chief Sounds Alarm on Big Bank Stablecoin Issuance

      July 14, 2025

      XRP Rally Is Being Driven By South Korean Traders

      July 14, 2025

      Analyst Says MicroStrategy Could Trigger a Bitcoin Cascade Worse Than Mt. Gox or 3AC

      July 14, 2025

      Pudgy Penguins (PENGU) Skyrockets as Justin Sun Joins the Huddle

      July 14, 2025
    • Technology

      Snag a pair of ultra-fast 240W USB-C cables for only $11 right now

      July 14, 2025

      This mini PC with 16GB of RAM is just $157, no Prime necessary

      July 14, 2025

      10 can’t-miss Prime Day tech deals you can still score for cheap

      July 14, 2025

      Asus turns heads with $500K RTX 5090 made with 11 pounds of real gold

      July 14, 2025

      Gmail AI summaries can be hijacked for phishing scams

      July 14, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Shop Now
    Tech AI Verse
    You are at:Home»Technology»Citrix Bleed 2 flaw now believed to be exploited in attacks
    Technology

    Citrix Bleed 2 flaw now believed to be exploited in attacks

    TechAiVerseBy TechAiVerseJune 28, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Citrix Bleed 2 flaw now believed to be exploited in attacks
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Citrix Bleed 2 flaw now believed to be exploited in attacks

    A critical NetScaler ADC and Gateway vulnerability dubbed “Citrix Bleed 2” (CVE-2025-5777) is now likely exploited in attacks, according to cybersecurity firm ReliaQuest, seeing an increase in suspicious sessions on Citrix devices.

    Citrix Bleed 2, named by cybersecurity researcher Kevin Beaumont due to its similarity to the original Citrix Bleed (CVE-2023-4966), is an out-of-bounds memory read vulnerability that allows unauthenticated attackers to access portions of memory that should typically be inaccessible.

    This could allow attackers to steal session tokens, credentials, and other sensitive data from public-facing gateways and virtual servers, enabling them to hijack user sessions and bypass multi-factor authentication (MFA).

    Citrix’s advisor also confirms this risk, warning users to end all ICA and PCoIP sessions after installing security updates to block access to any hijacked sessions.

    The flaw, tracked as CVE-2025-5777, was addressed by Citrix on June 17, 2025, with no reports of active exploitation. However, Beaumont warned about the high likelihood of exploitation earlier this week.

    The researcher’s worries now seem justified, as ReliaQuest says with medium confidence that CVE-2025-5777 is already being leveraged in targeted attacks.

    “While no public exploitation of CVE-2025-5777, dubbed “Citrix Bleed 2,” has been reported, ReliaQuest assesses with medium confidence that attackers are actively exploiting this vulnerability to gain initial access to targeted environments,” warns ReliaQuest.

    This conclusion is based on the following observations from actual attacks seen recently:

    • Hijacked Citrix web sessions were observed where authentication was granted without user interaction, indicating attackers bypassed MFA using stolen session tokens.
    • Attackers reused the same Citrix session across both legitimate and suspicious IP addresses, suggesting session hijacking and replay from unauthorized sources.
    • LDAP queries were initiated post-access, showing that attackers performed Active Directory reconnaissance to map users, groups, and permissions.
    • Multiple instances of ADExplorer64.exe ran across systems, indicating coordinated domain reconnaissance and connection attempts to various domain controllers.
    • Citrix sessions originated from data center IPs associated with consumer VPN providers like DataCamp, suggesting attacker obfuscation via anonymized infrastructure.

    The above is consistent with post-exploitation activity following unauthorized Citrix access, reinforcing the assessment that CVE-2025-5777 is being exploited in the wild.

    To protect against this activity, potentially impacted users should upgrade to versions 14.1-43.56+, 13.1-58.32+, or 13.1-FIPS/NDcPP 13.1-37.235+ to remediate the vulnerability.

    After installing the latest firmware, admins should terminate all active ICA and PCoIP sessions, as they may have already been hijacked.

    Before killing active sessions, admins should first review them for suspicious activity using the show icaconnection command and  NetScaler Gateway > PCoIP > Connections.

    After reviewing the active sessions, admins can then terminate them using these commands:

    kill icaconnection -all
    kill pcoipconnection -all

    If the immediate installation of security updates is impossible, it is recommended that external access to NetScaler be limited via network ACLs or firewall rules.

    In response to our questions as to whether CVE-2025-5777 is being actively exploited, Citrix referred us back to a blog post published yesterday where they state that they see no signs of exploitation.

    “Currently, there is no evidence to suggest exploitation of CVE-2025-5777,” reads the Citrix post.

    However, another Citrix vulnerability, tracked as CVE-2025-6543 is being exploited in attacks to cause a denial of service condition on NetScaler devices.

    Citrix says that this flaw and the CVE-2025-5777 flaw are in the same module but are different bugs.

    Update 6/27/25: Added information about Citrix’s blog post.

    Why IT teams are ditching manual patch management

    Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

    In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleBrother printer bug in 689 models exposes default admin passwords
    Next Article Russia’s throttling of Cloudflare makes sites inaccessible
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Snag a pair of ultra-fast 240W USB-C cables for only $11 right now

    July 14, 2025

    This mini PC with 16GB of RAM is just $157, no Prime necessary

    July 14, 2025

    10 can’t-miss Prime Day tech deals you can still score for cheap

    July 14, 2025
    Leave A Reply Cancel Reply

    Top Posts

    New Akira ransomware decryptor cracks encryptions keys using GPUs

    March 16, 202528 Views

    OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits

    April 19, 202522 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202520 Views

    Rsync replaced with openrsync on macOS Sequoia

    April 7, 202520 Views
    Don't Miss
    Gadgets July 14, 2025

    Nothing Phone (3) Review: A Unique ‘Flagship’ Phone

    Nothing Phone (3) Review: A Unique ‘Flagship’ Phone The Nothing Phone (3) might be the…

    Snag a pair of ultra-fast 240W USB-C cables for only $11 right now

    This mini PC with 16GB of RAM is just $157, no Prime necessary

    10 can’t-miss Prime Day tech deals you can still score for cheap

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Nothing Phone (3) Review: A Unique ‘Flagship’ Phone

    July 14, 20252 Views

    Snag a pair of ultra-fast 240W USB-C cables for only $11 right now

    July 14, 20253 Views

    This mini PC with 16GB of RAM is just $157, no Prime necessary

    July 14, 20253 Views
    Most Popular

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    French Apex Legends voice cast refuses contracts over “unacceptable” AI clause

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.