Almost 1,289 Citrix NetScaler ADC and NetScaler Gateway servers continue to be at risk of intrusions involving the critical out-of-bounds memory vulnerability CVE-2025-5777, dubbed as "Citrix Bleed 2", while 2,100 instances remain vulnerable to the critical memory overflow issue, tracked as CVE-2025-6543, following the release of fixes last week, according to Cyber Security News.
Threat actors were observed by ReliaQuest to have been leveraging the recently disclosed critical Citrix NetScaler Gateway vulnerability, tracked as CVE-2025-5777, to facilitate initial systems compromise, according to Cybersecurity Dive.
The U.S. government is warning organizations to check their operational technology (OT) networks following the disclosure of new vulnerabilities in industrial control system (ICS) hardware.
More than 7,000 of over 15,000 Model Context Protocol servers, which enable artificial intelligence app access to data outside their training models, around the world are exposed to the internet, hundreds of which are impacted by the "NeighborJack" vulnerability that allows access to anyone within the same local network, Infosecurity Magazine reports.
Threat actors were confirmed by the Cybersecurity and Infrastructure Security Agency to have been targeting AMC MegaRAC Baseboard Management Controller software instances impacted by the maximum severity authentication bypass flaw, tracked as CVE-2024-54085, BleepingComputer reports.