Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
3 intel reports
A threat actor designated TH-3BB targeted Thai ISP 3BB and Jasmine International using CVE-2024-21762 for initial access and MeshCentral for persistent command-and-control.
A suspected Chinese-speaking operator utilized the SecFlow AI orchestration framework to exploit multiple vulnerabilities and deploy steganographic GLUTTON webshells against government and education targets across Asia.
The MexicanMafia threat actor, also known as PanchoVilla, is conducting a sophisticated campaign using the Kimera reconnaissance engine and custom exploits against perimeter devices in Latin America.