July 4, 2026
- Anubis ransomware adopts Citrix Bleed 2 for initial access. Affiliates are exploiting CVE-2025-5777 and leaning on legitimate RMM tooling and hands-on-keyboard tradecraft. CERT-EU separately advised on multiple NetScaler ADC/Gateway flaws. The Hacker News · CERT-EU 2026-003 · Threat Intelligence
in Silent Active Directory Recon and a Near-Perfect Linux Root Exploit Lead the Offensive Beat