Researchers reported that APT5 is exploiting a newly disclosed vulnerability in Citrix ADC and Citrix Gateway, adding another high-risk edge-device intrusion case to the threat landscape. The activity highlights continued targeting of internet-facing remote access infrastructure, where successful exploitation can give attackers an initial foothold inside enterprise environments and enable follow-on espionage or broader network compromise.
The reporting appeared alongside separate coverage of a ransomware attack that disrupted Ardent Health Services, underscoring how perimeter compromises and healthcare intrusions remain pressing concerns across sectors. While the incidents involve different threat activity, together they reflect sustained pressure on organizations to rapidly patch exposed appliances, monitor for suspicious access on remote connectivity systems, and strengthen incident response readiness for both state-linked intrusions and financially motivated attacks.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Duo Security published a report that Ardent Health Services had been hit in a ransomware attack. The publication publicly identified the victim and the incident.
Duo Security published a report stating that APT5 was exploiting a newly identified vulnerability affecting Citrix ADC and Gateway products. The report publicly disclosed the exploitation activity and attribution to APT5.
Check Point released a blog post detailing the Petya ransomware and its behavior, providing technical analysis of the threat. This publication marked a public disclosure of technical details about Petya.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.