Published Security3 min read
A dairy plant stopped for 11 days because a NetScaler appliance leaked memory
Anubis used CitrixBleed 2 to get into Coca-Cola's Fairlife, then encrypted its Nutanix systems and halted US production. This is edge appliance risk measured in idle plants.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- A ransomware attack caused Coca-Cola-owned dairy company Fairlife to temporarily suspend production across its U.S. facilities after an unauthorized third party gained access to systems that included production-related infrastructure.
- Eleven days after the initial disclosure, Coca-Cola said the majority of production had resumed.
- The Anubis ransomware group claimed responsibility for the Fairlife attack and said it encrypted Fairlife's Nutanix systems.
- Anubis said it stole approximately 1 TB of data from Fairlife.
- Coca-Cola subsequently confirmed that data had been taken, although it has not publicly validated all of Anubis's claims about the attack.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Coca-Cola-owned Fairlife temporarily suspended production across its US facilities after an unauthorized third party gained access to systems that included production-related infrastructure [1]. Eleven days after Coca-Cola's initial disclosure, the company said the majority of production had resumed [2].
That gap between an appliance flaw and an idle plant is the point. The Anubis ransomware group claimed responsibility, saying it encrypted Fairlife's Nutanix systems and stole approximately 1 TB of data [3][4]. Coca-Cola subsequently confirmed data had been taken, but has not publicly validated all of Anubis's claims [5]. According to published reporting summarised by the security vendor Eclypsium, Anubis used CitrixBleed 2, tracked as CVE-2025-5777, for initial access before encrypting the Nutanix infrastructure [6]. The chain, as described, runs from an internet-facing appliance to virtualisation to physical output. Worth noting: the incident account is a vendor blog post built on third-party reporting rather than primary incident documents [7].
CitrixBleed 2 is an insufficient input validation vulnerability in NetScaler ADC and NetScaler Gateway that lets an unauthenticated attacker read appliance memory, potentially exposing credentials and session tokens [8]. A patch has been available since 2025 [9]. The uncomfortable part is that installing it closes the hole without invalidating session material an attacker already took, so an appliance can report the corrected version while someone retains access established before remediation [10]. Patch status is not compromise status.
The timing arithmetic is what makes edge devices attractive. Verizon's 2025 Data Breach Investigations Report found edge devices and VPNs made up 22% of targets in vulnerability exploitation, up from 3% the year before, close to an eightfold rise [11][12]. Verizon also found organisations fully remediated only about 54% of tracked edge vulnerabilities, leaving roughly 46% not fully remediated, with a median remediation time of 32 days [13][1]. VulnCheck reviewed 884 vulnerabilities with first-time exploitation evidence during 2025 and found nearly 29% showed exploitation on or before the day the CVE was published, with network edge devices, firewalls, VPNs and proxies the most frequently targeted category [14][15]. Set the two together and the median defender is roughly 32 days behind an attacker who arrives on publication day [2].
Mandiant's M-Trends 2026 data has vulnerability exploitation as the most common initial infection vector for the sixth consecutive year, at 32% of intrusions where the initial vector was identified, with sustained interest in edge and core network devices because those systems frequently do not support traditional security tooling [16][17]. JPMorgan Chase global CISO Pat Opet put the mismatch bluntly in his RSA 2026 keynote: "The very devices that are supposed to be our frontline defense are turning into our greatest weakness. I would argue that the mean time to adapt those devices is on a potentially decade scale, versus the speed of the attacker which is on a daily scale." [18]
What to watch: whether Coca-Cola or Fairlife confirm the CitrixBleed 2 entry path in any formal filing, since that link currently rests on reporting and Anubis's own claims [5][6]. Also watch how much of the 1 TB Anubis claimed actually surfaces [4]. For operators running NetScaler, the practical question is not whether the version string is current but whether anyone checked for pre-patch session reuse, configuration changes, and secondary footholds behind the appliance [10].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A ransomware attack caused Coca-Cola-owned dairy company Fairlife to temporarily suspend production across its U.S. facilities after an unauthorized third party gained access to systems that included production-related infrastructure.
- [2]
Eleven days after the initial disclosure, Coca-Cola said the majority of production had resumed.
- [3]
The Anubis ransomware group claimed responsibility for the Fairlife attack and said it encrypted Fairlife's Nutanix systems.
- [4]
Anubis said it stole approximately 1 TB of data from Fairlife.
- [5]
Coca-Cola subsequently confirmed that data had been taken, although it has not publicly validated all of Anubis's claims about the attack.
- [6]
According to published reporting, Anubis exploited CitrixBleed 2 (CVE-2025-5777) to gain initial access to Fairlife's environment before encrypting its Nutanix infrastructure.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- eclypsium.comChris GarlandAug 13When Patching Isn't Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk
Additional citations
- Eclypsium blog, citing reporting from MSN and others
- Eclypsium blog
- Anubis, via Eclypsium blog
- Eclypsium blog, citing published reporting
- Verizon 2025 DBIR, via Eclypsium blog
- VulnCheck, via Eclypsium blog
- Mandiant M-Trends 2026, via Eclypsium blog
- Mandiant, via Eclypsium blog
- Pat Opet, RSA 2026 keynote, via Eclypsium blog



