Citrix Zero-Day Vulnerability Update
On Oct 10, 2023, Citrix released a security bulletin for two previously unknown zero-day vulnerabilities: CVE-2023-4966 and CVE-2023-4967. These...
In September 2025, IronGate observed two confirmed LockBit 5.0 incidents, marking the sixth anniversary of the LockBit affiliate program. This resurgence follows a quiet period after Operation Cronos in early 2024, a multinational law enforcement operation that disrupted LockBit’s infrastructure. The latest version introduces a revamped affiliate model with improved incentives, aiming to attract new cybercriminal partners. LockBit continues to employ double extortion tactics, combining file encryption with data theft and public leaks to pressure victims.
Threat Actor Profile: LockBit 5.0 Ransomware
Attack Lifecycle
Initial Access
Execution & Evasion
Persistence & Anti-Forensics
Impact
Recommended Mitigations
Contact us today to learn more about our Digital Forensics and Incident Response (DFIR) services.
![]() |
Steve Ramey has spent the past two decades helping clients protect, investigate, and respond to events involving their digital interests. |
On Oct 10, 2023, Citrix released a security bulletin for two previously unknown zero-day vulnerabilities: CVE-2023-4966 and CVE-2023-4967. These...
On February 19, 2024, ConnectWise released a security bulletin reporting two vulnerabilities: CVE-2024-1709 and CVE-2024-1708. Both vulnerabilities...