decrypted · 6 july 2026 · ransomware and cybercrime · vulnerabilities and patching
Two old bug classes, one fresh ransomware wave
This week's ransomware headlines share a boring, useful truth: nobody needed a novel technique to get in. Two vulnerability classes did the work, one in Microsoft SharePoint's on-premises servers, one in Citrix NetScaler appliances, and both were exploited before most administrators had finished reading the advisory. Meanwhile new figures put the UK back at the top of Europe's ransomware league table, a position nobody should want.
SharePoint's patch that arrived too late for its own advice
Microsoft rated CVE-2026-45659, a remote code execution flaw in on-premises SharePoint Server, as "exploitation less likely" when it shipped the fix in May. That confidence did not survive contact with reality: within weeks the US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalogue after confirming it was being used to plant ransomware, ordering federal agencies to patch or disconnect by 4 July. Microsoft has linked the exploitation to Storm-2603, a China-based crew already known for deploying Warlock ransomware through SharePoint bugs, alongside state-linked groups it tracks as Linen Typhoon and Violet Typhoon.
The flaw is a deserialisation bug: SharePoint accepts a packaged blob of data from a logged-in user and unpacks it back into working code and objects. A well-formed but malicious blob from anyone with the lowliest "site member" login, no admin rights required, becomes a set of instructions the server dutifully carries out. Think of it as a lift that reads the floor number scribbled on a delivery slip rather than checking the pass at the door: convenient, right up until someone writes "penthouse" on the slip. Researchers estimate more than 10,000 SharePoint servers are still reachable from the internet, patch status unknown. This is the same bug family as the "ToolShell" chain that hit SharePoint last year, which is the real lesson: a vulnerability class that keeps recurring in the same product is a design problem, not a patching problem. Any UK organisation still running SharePoint on-premises and facing the internet has taken on Microsoft's monthly patch cadence as its own risk. SharePoint Online shifts that cadence to a party that can patch in hours.
A two-week head start on Citrix Bleed's sequel
Citrix's NetScaler ADC and Gateway carry their own recurring flaw, a memory overread nicknamed Citrix Bleed 2 (CVE-2025-5777), patched in June. It works like a photocopier that occasionally hands back a stray page from the previous customer's job: query the appliance the wrong way and it leaks a fragment of memory that can contain another user's live session token. Steal that token and multi-factor authentication becomes irrelevant, since the attacker is not logging in at all, they are simply continuing someone else's already-approved session.
The NCSC's own technical director noted in his weekly threat round-up that researchers at GreyNoise had traced exploitation attempts back to 23 June, nearly two weeks before a public proof-of-concept existed, meaning some attackers had a working exploit before most defenders had anything to test their systems against. The Anubis ransomware crew has been observed using stolen NetScaler sessions to log in from hosting-provider IP addresses that look nothing like a genuine user's usual broadband connection, then blending in with legitimate-looking remote access tools before deploying ransomware. Citrix's own advisory contains a detail worth repeating to anyone who patched and moved on: the fix does not invalidate sessions already stolen before it went in. Administrators are told to explicitly kill active ICA and PCoIP sessions after patching. Skip that step and a working stolen session can outlive the vulnerability that created it.
What the numbers say about where this lands
Figures gathered by the NCSC show 323 UK organisations reported ransomware attacks between April 2025 and March 2026, more than half of them small and medium businesses, with reported losses up 50 percent year on year, and the true toll almost certainly higher given how few victims report at all. Separate research puts the UK as the most ransomware-attacked country in Europe for the first quarter of 2026, with manufacturing and construction now the favoured targets, precisely because those businesses can least afford downtime and pay fastest.
None of this required zero-day sophistication. It required an internet-facing appliance, a known bug class, and a window before patching caught up. NCSC penetration testers, asked what most reliably slows attackers down, gave the same unglamorous answer they always give: segment the network, and log and monitor what happens on it. Neither is exciting. Both would have shortened every intrusion described above.
Sources
- CTO at NCSC Summary: week ending July 5th
- CISA: Microsoft SharePoint RCE flaw now actively exploited
- Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list
- NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-5349 and CVE-2025-5777
- From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks
- UK Leads Europe Ransomware Attacks: Cyble Q1 2026 Report
If any of this touches systems you run, get in touch and we'll help you work through it.
More like this
- The npm maintainer account North Korea phished, and the four packages it unlocked 31 july 2026
- The Department for Education's helpdesk, and the 607,000 records it was never built to hold 31 july 2026
- An SD-WAN console with no way to hide, and the flaw attackers found first 28 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.