Citrix Bleed 2 (CVE-2025-5777): how Anubis steals sessions and skips MFA before it encrypts
Anubis ransomware has claimed 91 victims by exploiting Citrix Bleed 2: it leaks NetScaler memory, steals session tokens and walks in with no password and no MFA. What to detect before encryption.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador