By Joshua Mitchell
Publication Date: 2026-07-04 15:13:00
A ransomware operation that emerged barely 19 months ago has claimed 91 victims — 11 of them in June 2026 alone — by exploiting a critical pre-authentication vulnerability in Citrix NetScaler appliances to steal session tokens without ever touching a user’s password, then hiding its persistence inside the same commercial remote management tools that IT teams use every day. Defenders who patch CVE-2025-5777 and consider the job finished are still at risk: tokens extracted before the patch was applied remain valid until explicitly revoked, and no antivirus signature flags a legitimate ScreenConnect installer.
Arctic Wolf Labs published its full investigation of the Anubis ransomware-as-a-service operation on July 1, 2026, documenting intrusions across healthcare, financial services, manufacturing, and technology sectors throughout this year. The report named six commercial remote monitoring and management (RMM) tools — ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC,…


