Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
Purple Ghosts compromised over 14,000 Dahua cameras globally using an authentication-bypass chain and P2P relay exploitation to install persistent backdoors and harvest credentials.
A skilled human threat actor exploited a Marimo RCE vulnerability to pivot into an AWS environment in eight seconds, while concurrent campaigns targeted Redis servers for cryptomining and Dahua cameras.
A Russian-speaking operator compromised over 14,000 Dahua IP cameras globally, primarily in Ukraine and Russia, using authentication bypasses, P2P relay abuse, and credential brute-forcing.
Russian-speaking operators are using custom platforms like camview and open-source scanners to exploit vulnerabilities in IP cameras and routers across Ukraine and Europe to build proxy networks.