When Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk

A recent ransomware attack by the Anubis group against Coca-Cola-owned dairy company Fairlife forced a temporary suspension of U.S. production facilities for eleven days after threat actors exploited CitrixBleed 2 (CVE-2025-5777) to compromise Nutanix systems and exfiltrate approximately 1 TB of data. This incident underscores a critical security gap: while patching NetScaler ADC and Gateway appliances closes the input validation vulnerability, it does not automatically invalidate session tokens or credentials harvested by attackers prior to the update. This risk is compounded by a broader industry shift toward targeting internet-facing network edge devices, which accounted for 22% of vulnerability exploitations in 2025 according to Verizon, and where nearly 29% of vulnerabilities show exploitation evidence on or before their public disclosure date. Similarly, campaigns like FortiBleed demonstrate that firmware upgrades on Fortinet FortiGate appliances fail to automatically migrate legacy SHA-256 password hashes to PBKDF2 or remove unauthorized persistence mechanisms, proving that version-based vulnerability management must be paired with active device-level integrity verification and compromise assessments.

Severity: Critical

Threat Details and IOCs

Malware: Anubis, Sphinx
CVEs: CVE-2025-5777
Technologies: Cisco, Citrix NetScaler, Citrix NetScaler ADC, Citrix NetScaler Gateway, Fortinet FortiGate, FreeBSD, Ivanti, Linux, Microsoft Windows, Palo Alto Networks, SonicWall, VMware ESXi
Threat Actors: AnubisMedia, Sphinx
Attacker Countries: Russia
Attacker Domains: anubisyfkh5rixydjpoo3jqucauajz2juybrbtuglcppjj2y3eg3y6ad[.]onion
Attacker URLs: hxxp[://]anubisyfkh5rixydjpoo3jqucauajz2juybrbtuglcppjj2y3eg3y6ad[.]onion/r/x7DNhT0kG8Z2ElnASoBnUa6rQFDRfZY+9fQnDAj5hl81pP0y31BKlZ59ZhogDQmjybVZnkYgmubSZs2FNfuTd6TTVRZmtB
Victim Industries: Agriculture, Food & Beverage, Manufacturing
Victim Countries: United States

Mitigation Advice

  • Immediately apply the patch for CitrixBleed 2 (CVE-2025-5777) to all vulnerable NetScaler ADC and NetScaler Gateway appliances.
  • Force the termination of all active user and administrator sessions on NetScaler ADC and Gateway appliances after patching to invalidate any potentially stolen session tokens.
  • Force a password rotation for all accounts, including administrator and service accounts, that have authenticated through or are stored on NetScaler appliances.
  • Audit all internet-facing network appliances, including firewalls and VPN gateways, to identify and remove any unauthorized or suspicious local user and administrator accounts.
  • On Fortinet FortiGate devices, hunt for evidence of compromise by searching for unauthorized symlinks in the `/data/etc/` and `/data/lib/` directories.

Compliance Best Practices

  • Implement a device integrity verification solution to continuously monitor network edge appliances for unauthorized configuration changes, firmware modifications, and other signs of compromise that version scanning cannot detect.
  • Implement network segmentation to create a perimeter DMZ that isolates internet-facing appliances from critical internal networks, such as production, development, and corporate data environments.
  • Develop and formalize an incident response plan specifically for network infrastructure that includes procedures for compromise assessment, forensic data collection, and credential rotation, in addition to patching.
  • Revise the vulnerability management policy to establish an accelerated patching SLA for all internet-facing network infrastructure, prioritizing known exploited vulnerabilities.
  • Establish and enforce a configuration standard for all network appliances that requires the use of modern, strong password hashing algorithms like PBKDF2 or bcrypt, and periodically audit devices for compliance.

Unauthenticated Remote Code Execution in Citrix NetScaler via SAML Heap Overflow (CVE-2026-8452)

A heap overflow vulnerability, likely tracked as CVE-2026-8452, exists in the packet-processing engine (`nsppe`) of Citrix NetScaler ADC and NetScaler Gateway versions 14.1 prior to 14.1-72.61 and 13.1 prior to 13.1-63.18 when configured to use SAML as a Service Provider or Identity Provider. The vulnerability occurs during SAML signature canonicalization, where the application copies attacker-controlled data from the `PrefixList` attribute of the `ds:SignedInfo` element into a fixed-size global buffer without validating its size. By supplying an oversized `PrefixList` containing unique space-separated values, an unauthenticated remote attacker can overflow the buffer and corrupt the metadata of adjacent network buffer chunks (`nsb`). This corruption allows control over a destination pointer in a subsequent `memcpy` operation within `splitPktInner`, establishing a write-what-where primitive. By leveraging this primitive to overwrite the `tx_pkt_complete_fptr` function pointer, arbitrary instruction pointer (RIP) control is achieved. To prevent the `pitboss` process from rebooting the appliance upon the resulting crash, the signal handlers for `SIGSEGV` and `SIGBUS` can be neutralized using the `sigaction` system call, allowing a dropped PHP webshell to persist and execute commands via a modified SUID binary.

Severity: Critical

Threat Details and IOCs

CVEs: CVE-2026-8452
Technologies: Citrix ADC, Citrix Gateway, Citrix NetScaler ADC, Citrix NetScaler Gateway
Victim Industries: E-commerce, Education, Financial Services, Government, Healthcare, Insurance, Manufacturing, Public Sector, Retail, Technology Hardware, Telecommunications, Transportation

Mitigation Advice

  • Update all NetScaler ADC and NetScaler Gateway 14.1 instances to version 14.1-72.61 or a later version.
  • Update all NetScaler ADC and NetScaler Gateway 13.1 instances to version 13.1-63.18 or a later version.
  • Scan all NetScaler appliances for unauthorized files in the `/var/vpn/theme/` directory, paying special attention to PHP webshells.
  • On all NetScaler appliances, check the permissions of the `/bin/sh` binary and other common system executables to identify any with an unauthorized SUID bit set.
  • Review NetScaler system logs for an abnormal pattern of `nsppe` process crashes followed by a process respawn, rather than a full system reboot.
  • If patching is delayed, configure your Web Application Firewall (WAF) or Intrusion Prevention System (IPS) to block or alert on SAML authentication requests containing an abnormally large `PrefixList` attribute.

Compliance Best Practices

  • Establish and maintain a detailed asset inventory of all network appliances, documenting their software versions and specific service configurations, such as the use of SAML.
  • Implement file integrity monitoring on critical network appliances to detect unauthorized changes to system files and web directories.
  • Implement and enforce network segmentation rules that strictly limit outbound connections from perimeter devices like NetScaler appliances to only essential, pre-approved internal systems.
  • Incorporate security requirements into the procurement process for network infrastructure, giving preference to vendors and products that implement memory safety protections like ASLR and Data Execution Prevention (DEP).
  • Develop and enforce a patch management policy that prioritizes security updates for internet-facing, business-critical systems like VPN gateways and application delivery controllers.

One Missing MFA Control Lets Credential Spray Become Full Akira Ransomware Intrusion

In early August 2026, a credential-spraying campaign successfully compromised a SonicWall SSL VPN account lacking multi-factor authentication (MFA) protection, initiating an Akira ransomware intrusion. The attack began at 03:45 UTC on August 4, with a successful login recorded at 03:52 UTC from the external IP address `72.23.77[.]35`. Within two hours, the threat actor utilized Remote Desktop Protocol (RDP) to access the domain controller, executing PowerShell commands to perform Active Directory reconnaissance and exporting user and computer data to `AdUsers.txt` and `AdComp.txt` under `C:\ProgramData\`. The attacker then moved to an application server, installed WinRAR to archive mapped shares, and exfiltrated the staged data to an attacker-controlled S3 bucket using `s5cmd`. To establish interactive control, the actor installed AnyDesk as a Windows service before launching `msconfig.exe` at 06:29 UTC to reboot the host `WIN-DNCVG09TAT8` into Safe Mode with Networking, a tactic designed to evade endpoint detection and response (EDR) agents prior to ransomware deployment.

Severity: High

Threat Details and IOCs

Malware: Akira, Akira_v2, AvosLocker, LummaC2, Lumma Stealer, Megazord, Snatch
CVEs: CVE-2024-40766
Technologies: Microsoft Windows Server, SonicWall SSL-VPN
Threat Actors: Akira, AvosLocker, GoldSahara, HowlingScorpius, PUNKSPIDER, SnatchTeam, Storm-1567, Storm1567
Attacker Countries: Russia
Attacker IPs: 72[.]23[.]77[.]35
Attacker Hashes: 414b9985f46714f44dd1bd63860d2a48dcfababcfe5c712a4b4f575378127a56, e2356c742c74cce5c6b6100162d0071a3f71e2fed2ed895c2011061a95b3299a
Victim Industries: Agriculture, Business Services, Cloud Infrastructure, Construction, Education, Financial Services, Government, Healthcare, Legal Services, Manufacturing, Professional Services, Real Estate, Retail, Technology Hardware
Victim Countries: Colombia

Mitigation Advice

  • Add the IP address 72.23.77.35 to the deny list on your network firewall and VPN concentrator.
  • Use your EDR or a manual search to scan all endpoints, especially domain controllers, for the existence of files named 'AdUsers.txt' or 'AdComp.txt' in the 'C:\ProgramData\' directory.
  • Create a detection rule in your SIEM or EDR to generate a high-priority alert for any execution of 'msconfig.exe' on server-class operating systems.
  • Review VPN authentication logs from the last 30 days for patterns of high-volume failed logins followed by a successful login from the same source IP address.

Compliance Best Practices

  • Conduct a comprehensive audit of all internet-facing services, including VPNs, and enforce non-bypassable multi-factor authentication (MFA) for all user accounts.
  • Implement a policy to restrict RDP access to domain controllers, allowing connections only from a limited set of privileged accounts originating from dedicated secure administrative workstations or jump hosts.
  • Use an application control technology, such as Windows AppLocker or a similar EDR feature, to create a policy that blocks the execution of unapproved remote administration tools like AnyDesk on all servers.
  • Use an application control technology, such as Windows AppLocker or a similar EDR feature, to create a policy that blocks or alerts on the execution of unapproved file archiving utilities like WinRAR and 7-Zip on servers.
  • Enable PowerShell Script Block Logging and Module Logging via Group Policy and ensure these logs are forwarded to your SIEM for monitoring and alerting on suspicious AD enumeration commands.
  • Develop and implement a network segmentation strategy that isolates critical servers, such as domain controllers, into a secure tier and strictly controls inbound traffic from user subnets and other server tiers.
  • Configure your EDR to detect and alert on the execution of uncommon command-line data transfer utilities, such as s5cmd, rclone, or azcopy, on endpoints and servers.

ShieldBreak: New Zero-Day Local Privilege Escalation to SYSTEM on Fully Patched Windows

A newly released zero-day exploit named "ShieldBreak," developed by the researcher known as Nightmare Eclipse, allows local privilege escalation to SYSTEM level on fully patched Windows 10, Windows 11, and Windows Server systems. Although initially framed as a patch bypass for the RoguePlanet vulnerability (CVE-2026-50656) resolved in July, ShieldBreak operates differently by utilizing a user-mode callback hook to alter file contents during a Microsoft Defender cloud-hydration scan via the Cloud Filter API (cfapi). Security researcher Kevin Beaumont has verified the exploit's efficacy on the latest Windows 11 builds and released three hunting queries to assist defenders in detecting exploitation attempts. This release marks the tenth zero-day published by Nightmare Eclipse since April, joining other unpatched flaws such as LegacyHive, a local privilege escalation vulnerability targeting Windows user hives, and GreatXML, a BitLocker encryption bypass. Microsoft is currently investigating the vulnerability, which remains unpatched following the company's August Patch Tuesday.

Severity: Critical

Threat Details and IOCs

Malware: BlueHammer, FunnyApp.exe, GreatXML, RedSun, RedSun.exe, RoguePlanet, RoguePlanet.exe, UnDefend, undef.exe, z.exe
CVEs: CVE-2020-17103, CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586, CVE-2026-50656, CVE-2026-50661, CVE-2026-62832
Technologies: Microsoft BitLocker, Microsoft Defender Antivirus, Microsoft Windows, Microsoft Windows Recovery Environment, Microsoft Windows Server
Threat Actors: ChaoticEclipse, DeadEclipse, INFINITENIGHTMARE, MSNightmare, Nightmare-Eclipse, NightmareEclipse
Attacker Countries: Russia
Attacker Domains: git[.]projectnightcrawler[.]dev
Attacker URLs: hxxps[://]git[.]projectnightcrawler[.]dev/NightmareEclipse/ShieldBreak/src/branch/main/ShieldBreak.cpp
Victim Industries: Aerospace, Defense, Government, Healthcare
Victim Countries: United States

Mitigation Advice

  • Implement the threat hunting queries published by security researcher Kevin Beaumont for the ShieldBreak vulnerability in our endpoint detection and response (EDR) and security information and event management (SIEM) tools.
  • Use our vulnerability scanning tool to audit all Windows systems and confirm that patches for CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586, CVE-2020-17103, and CVE-2026-50656 are installed.
  • Actively monitor official Microsoft security update channels for a patch addressing the ShieldBreak vulnerability and prepare for expedited testing and deployment.

Compliance Best Practices

  • Conduct a comprehensive review of user and service accounts to enforce the principle of least privilege, removing all non-essential local administrator rights from standard user accounts.
  • Develop and deploy an application control policy, such as Windows Defender Application Control (WDAC), to restrict executable files, scripts, and DLLs to a list of known and trusted applications.
  • Enable, audit, and enforce Microsoft Defender Attack Surface Reduction (ASR) rules across all Windows endpoints to block suspicious behaviors commonly used in exploit chains.
  • Establish a formal process to analyze the technical details of new vulnerabilities and proactively develop custom detection logic for our security tools, independent of public releases.

APT36 Campaign Leverages PATCHCORD Backdoor and SuperShell C2 Against Critical Infrastructure

A cyber espionage campaign, attributed with moderate confidence to the APT36 (Transparent Tribe) threat cluster, has targeted Afghan telecom providers and South Asian critical infrastructure using a layered ecosystem of custom implants and spoofed delivery portals. The intrusion begins with social-engineering lures, such as a malicious Inno Setup package named `TMS_AfghanTelecom.exe` (SHA-256: `cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6`), which deploys a core Windows backdoor known as PATCHCORD. PATCHCORD establishes persistence by hijacking browser shortcuts for Microsoft Edge, Google Chrome, and Mozilla Firefox, and communicates with the command-and-control (C2) domain `appstoore[.]solutions` (IP `46.30.188[.]13` on port 8080) to execute arbitrary commands, manage persistence, and execute memory-only shellcode via `VirtualAlloc` and `CreateThread`. Infrastructure analysis revealed that the threat actors' staging environment hosted exploit tooling for the OpenSSH vulnerability CVE-2024-6387 (regreSSHion), the open-source Chinese-language C2 platform SuperShell v2.0.0, and additional implants including SHEETCORD—a Go-based backdoor that hijacks browser shortcuts and abuses the Google Sheets API for C2 tasking—and the HACKERAI C2 Agent, which leverages GitHub Gists for data exfiltration and command delivery.

Severity: Critical

Threat Details and IOCs

Malware: HACKERAI C2, HACKERAI C2 Agent, PATCHCORD, SHEETCORD, ValleyRAT, Winos, Winos 4.0
CVEs: CVE-2024-6387
Technologies: Linux, Microsoft Windows
Threat Actors: APT36, TransparentTribe
Attacker Countries: Pakistan
Attacker IPs: 46[.]30[.]188[.]13
Attacker Domains: afghanistanupdates[.]site, afghantelecom[.]site, appstoore[.]duckdns[.]org, appstoore[.]solutions, caprispine[.]health, defence[.]cgda[.]site, nicservice[.]org, nic-support[.]site, servicesindia[.]services, vpn01[.]afghantelecom[.]site, www[.]afghanistanupdates[.]site, www[.]appstoore[.]solutions, www[.]caprispine[.]health, www[.]nicservice[.]org, www[.]servicesindia[.]services, www[.]zala-aer[.]info, zala-aer[.]info
Attacker URLs: hxxps[:]//tms.afghantelecom.af
Attacker Hashes: 0f4073d3c866bc3daf55b25f71250b96ec120db94a4f9cc8fe85b7c9f9d346b3, 1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94, 2323b55ea743c813e48689318e8ed54ae838cf9e8a2adbfc2488ea8a36dd0126, 2eddfebb3f7419af27493a6a3bb601372cf6c494da8df62640cce7f830b4a73b, 378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668, 50fc220347f9e281037e831c3755dc70a8ba7f663025aea35b301226918b016b, 5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a, 74d347785dc47f8cda3876826cdd3fb3935ac55dc8e9e0c0f96d5ef4e00089a2, 959bbb09cd86ce3930406bf1cf32776ca477dfefe3fd63e90bf0017fccd90587, b56fab5a6834c51d85787e7c1177720dfba5a5823763f3fcf432196cd2a1bdf3, cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6, d46ee94d6a27ff9f02cff6fb57780acac2833ce48c95e63042a6274e24a040bb, ea0934472121848b80455581d289ce4480b1e5cc05678c1b90ecfc465b5ec350
Victim Industries: Cloud Infrastructure, Defense, Government, Telecommunications
Victim Countries: Afghanistan, Bangladesh, Bhutan, India, Maldives, Nepal, Pakistan, Sri Lanka

Mitigation Advice

  • Add the domains `appstoore.solutions` and `nic-support.site` to the network firewall, web proxy, and DNS sinkhole blocklists.
  • Create a firewall rule to block all inbound and outbound traffic to and from the IP address `46.30.188.13`.
  • Add the file hashes `cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6`, `1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94`, `ea0934472121848b80455581d289ce4480b1e5cc05678c1b90ecfc465b5ec350`, `5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a`, and `378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668` to your EDR and antivirus blocklists.
  • Query network traffic logs (e.g., firewall, proxy, NetFlow) for connections to destination port 8080 containing the User-Agent string `Beacon/1.0.0` or the URI path `/api.jsp`.
  • Scan endpoint file systems for browser shortcut files (.lnk) located on user desktops and in Start Menu directories, and inspect their 'Target' property to ensure they point directly to a legitimate browser executable (e.g., chrome.exe, msedge.exe, firefox.exe) and not another path.
  • Inspect the contents of user `Startup` folders and the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` and `HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run` registry keys for suspicious or recently added VBScripts and executables.
  • Identify all internet-facing Linux systems running OpenSSH, scan them for CVE-2024-6387, and immediately apply patches or mitigations to any vulnerable instances.

Compliance Best Practices

  • Develop and implement a policy to monitor and restrict outbound API calls to `sheets.googleapis.com` from general user endpoints, allowing it only for specific approved services or users.
  • Assess business need for access to `gist.github.com` and, if possible, block or restrict access at the web proxy. If required for business, implement enhanced logging and monitoring for large or frequent uploads to the service from endpoints.
  • Implement an application whitelisting solution, such as Windows AppLocker, to restrict program execution from user-writable directories like `Downloads` and `AppData`, allowing only signed or approved applications to run.
  • Configure your EDR solution to detect and alert on suspicious memory allocation patterns, such as a process allocating executable memory (`VirtualAlloc`) and then creating a new thread (`CreateThread`) without a corresponding module being loaded from disk.
  • Enable and ingest PowerShell Script Block Logging (Event ID 4104) and VBScript logging into your SIEM. Develop detection rules to alert on obfuscated scripts and scripts executed by unusual parent processes (e.g., Microsoft Office applications).
  • Implement a default-deny egress firewall policy that blocks all outbound traffic except for specifically allowed ports and destinations required for business functions (e.g., TCP/443, TCP/80).
  • Develop and implement a recurring security awareness training program that includes phishing simulations and focuses on identifying suspicious downloads, especially those masquerading as legitimate software from trusted entities.

Authors & Contributors

Brian Sayer (Author)

Threat Intelligence Analyst, F5