Preventable Failures: NetScaler Ransomware, Session Theft, and Email Errors
This episode examines three current UK cyber security incidents that share a troubling characteristic: all were preventable. Mauven MacLeod analyses the seven-step ransomware chain exploiting unpatched Citrix NetScaler appliances (CVE-2025-5777), documented by Huntress across multiple UK organisations. The briefing covers SilabRAT, a subscription-based Remote Access Trojan sold for £3,900 monthly that clones browser sessions to bypass multi-factor authentication, posing particular risk to finance teams and managed service providers. The episode also examines an NHS Forth Valley data breach caused by a misdirected email, representing the most common breach category reported to the ICO. Additional coverage includes GigaWiper destructive malware and active exploitation of Check Point VPN vulnerabilities (CVE-2026-50751) associated with Qilin ransomware. The analysis emphasises the systemic gap between awareness and action, providing specific verification steps for UK small and medium businesses.
Chapters
Introduction: The Common Thread of Prevention FailuresMauven introduces three unrelated but preventable security incidents affecting UK organisations with existing IT support and best-practice solutions. The episode examines systemic failures in closing known security gaps.
CitrixBleed 2: Seven-Step Ransomware ChainAnalysis of the seven-step attack chain exploiting CVE-2025-5777 in Citrix NetScaler appliances, documented by Huntress across multiple UK organisations. Covers the automated exploitation process, Dragonforce ransomware deployment, and the disproportionate risk to UK mid-market professional services firms.
Call to ActionBrief encouragement to follow the show and share with business owners who need threat intelligence briefings.
SilabRAT: Credential Theft by SubscriptionExamination of SilabRAT Remote Access Trojan, available for £3,900 monthly, which clones browser profiles and sessions to bypass multi-factor authentication. Covers Hidden Virtual Network Computing capabilities, targeting of finance teams, and supply chain risks through compromised managed service providers.
NHS Forth Valley: An Email Incident Without an AttackerAnalysis of a maternity patient data breach at NHS Forth Valley caused by misdirected email, representing the most common breach category in ICO statistics. Discusses the need for documented verification processes before sending bulk emails containing sensitive data.
On the Radar: GigaWiper and Check Point VPNBrief coverage of GigaWiper destructive malware and active exploitation of CVE-2026-50751 in Check Point Remote Access VPN since May 2026, associated with Qilin ransomware. Emphasises immediate patch verification requirements.
Conclusion: The Gap Between Awareness and ActionSummary emphasising that the common thread across all incidents is the failure to act on known risks. Provides specific action items for verifying patch status of NetScaler and Check Point VPN systems.
Links
https://www.huntress.com/blog/citrixbleed-2-seven-step-ransomware-chainhttps://www.group-ib.com/blog/silabrat-analysis/https://www.theregister.com/2026/07/nhs-forth-valley-maternity-data-breachhttps://www.ncsc.gov.uk/guidance/email-securityhttps://www.microsoft.com/en-us/security/blog/gigawiper-analysishttps://www.checkpoint.com/advisories/cve-2026-50751