The hackers notably used custom malware and were exploiting CVE-2025-5777, now known colloquially as “Citrix Bleed Two”, before it was disclosed publicly in July.
First seen on therecord.media
Jump to article: therecord.media/advanced-hacker-exploiting-cisco-citrix-zero-days-amazon
![]()

