Initial access broker linked to weaponization of CitrixBleed2 flaw

Initial access broker linked to weaponization of CitrixBleed2 flaw

By David Jones
Publication Date: 2026-07-10 11:24:00

An initial access broker weaponized a critical vulnerability known as CitrixBleed 2 in a series of attacks during the first half of 2026 across multiple organizations, according to a report released Thursday by the security company Huntress. 

After exploiting the vulnerability, the hackers escalated privileges, created rogue local administrator accounts and established persistence with legitimate remote access tools, including ScreenConnect and Zoho Assist. 

About a half-dozen cases between January and June followed a consistent playbook. In the most advanced case, the attackers deployed DragonForce ransomware, Huntress researchers said.  

“In the incident that progressed to ransomware, the speed the adversary operated with was their singular advantage — ransomware was deployed almost immediately following the execution of the local privilege escalation script — leaving little time for defenders to respond,”…