This Week - Ending 11th July 2025
This week: Some key arrests by the National Crime Agency (NCA) over the M&S and Co-op hacks in the UK with links to LAPSUS$. Citrix and Fortinet vulnerabilities.
First of hopefully a regular set of newsletters on weekly news as well as other more focused posts on specific subjects.
Thanks for reading Elliot’s Substack! Subscribe for free to receive new posts and support my work.
Let’s see how it goes.
Round-Up
-
National Crime Agency arrests ScatterSpider hackers – Suspects arrested in the recent retailer-focused ransomware incidents at the Co-op, M&S, and Harrods. Includes links to LAPSUS$. Krebs
-
McDonald’s McHire AI gaffe – Admin access to the system run by Paradox AI allowed access to 64 million people’s records via an unsecured API. Source: Here
-
CVE-2025-5777 aka CitrixBleed2 – Allows bypass of MFA and has been actively exploited for over a month. Citrix has been reserved in disclosing details to customers, which has led to criticism. Sources: NIST, Ars Technica
-
Adarma notice of intent to file for administration – Scotland-based MSSP appears to be facing financial difficulties. Source: Digit News
-
Pre-auth Fortinet FortiWeb RCE - CVE-2025-25257 – Proof-of-concept exploits have been released for a critical SQLi vulnerability in Fortinet FortiWeb.Source: Bleeping Computer
-
UK Gov boosts Eutelsat’s OneWeb LEO broadband satellites by £140m – A further investment into the Starlink competitor to support the company’s growth. Source: ISPReview
-
National alert system to be tested again – Emergency alert to be sent to mobile phones across the UK in the second ever national test. The alert will sound at around 3pm on Sunday 7 September. Source:UK Gov.
-
Microsoft expands its Zero Trust Workshop – Now including Networking, SecOps, and more. Source: Microsoft Security Blog
-
Patch Tuesday - 137 vulnerabilities in Windows fixed – SANS have a breakdown of each CVE and fix here. Source:Talos.
Citrix Bleed 2 - CVE-2025-5777
As it’s become clear over the past couple of years, continued exploits targeting VPNs are proving difficult to combat. This is due not only to inconsistent patching practices by organisations using appliances, but also to mixed response times by vendors.
CVE-2025-5777, aka CitrixBleed 2, has come into focus this week. This 9.3 CVSS-rated security flaw allows remote, unauthenticated attackers to read sensitive information — such as session tokens — from memory in NetScaler devices configured as a gateway (e.g. VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
The NSA has added it to its Known Actively Exploited list after evidence emerged of active exploitation — reportedly affecting over 120 organisations, including some US Government systems. Kevin Beaumont shared findings here. Kevin references NetFlow data from GreyNoise, indicating exploitation attempts since 23 June. Citrix issued a statement on 26 June denying knowledge of active exploitation. That position appears unchanged.
Vulnerabilities are expected, but delayed vendor communication can affect an organisation’s ability to take timely, proactive steps. Consistent and transparent advisories are critical. Beaumont estimates 24% of publicly facing NetScalers remain unpatched. With this CVE on the KEV list, organisations should validate patch status and review logs regardless of whether updates were recently applied.
More Information
-
Horizon3’s guidance on checking for signs of exploitation – Twitter
-
Kevin’s blog post with detection and threat hunting steps – Here
-
Post-patch validation remains recommended for all affected systems.
-
GreyNoise mass exploitation IPs – here
Sources: Double Pulsar, NetScaler, CVE-2025-5777, HelpNet Security
