CitrixBleed 2 Is Now Ransomware Infrastructure: CVE-2025-5777 Fueling DragonForce Attacks
CVE-2025-5777 (CitrixBleed 2, CVSS 9.3) lets attackers dump live session tokens from unpatched Citrix NetScaler appliances without logging in — bypassing MFA…
Security research, penetration testing, CVE analysis, PCI-DSS compliance, and defensive programming techniques for web applications.
69 ARTICLES
CVE-2025-5777 (CitrixBleed 2, CVSS 9.3) lets attackers dump live session tokens from unpatched Citrix NetScaler appliances without logging in — bypassing MFA…
An exposed hacker C2 server revealed WP-SHELLSTORM, a webshell access-brokerage crew that used 27 known, already-patched CVEs to backdoor WordPress, Joomla and…
Two zero-click stored XSS flaws in Roundcube Webmail (CVE-2026-54432 / CVE-2026-54433) execute JavaScript just from viewing an email - one via an unescaped…
Ubiquiti Security Advisory Bulletin 066 patches 25 UniFi vulnerabilities, seven of them critical. The headline flaw, CVE-2026-50746 (CVSS 10.0) in UniFi…
BeyondTrust's Remote Support and PRA appliances have two pre-auth CVSS 9.2 auth-bypass flaws (CVE-2026-40138/40139). A network attacker can reach elevated…
GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel rtmutex use-after-free. Any local user gets root and can escape containers to the host. A 97%-reliable…
CISA added two CVSS 10.0 Joomla page-builder flaws (CVE-2026-56290, CVE-2026-48908) to its KEV catalog. Both allow unauthenticated file upload to RCE and are…
WPFunnels (CVE-2026-14345, CVSS 9.8) has an unauthenticated log-poisoning-to-RCE flaw in versions up to 3.12.7. An attacker writes PHP into a log file that…
A 16-year-old use-after-free in Linux KVM's shadow MMU lets a guest VM escape to the host on Intel and AMD. The public PoC panics the host; a withheld exploit…
Two newly disclosed ModSecurity flaws let attackers slip malicious requests past your WAF. CVE-2026-52747 (High) is a multipart parser differential that strips…
CVE-2026-12184 lets a remote server crash a PHP process - and under PHP-FPM the whole worker pool - just by presenting a broken TLS certificate. No auth and no…
CVE-2026-45504 is a server-side request forgery (SSRF) flaw in on-premises Microsoft Exchange that lets an authenticated, low-privileged user read arbitrary…