Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
6 intel reports
Autonomous AI agents are now conducting end-to-end extortion campaigns and capability development, significantly reducing attack dwell time and operator skill requirements.
The wp2shell exploit chain leverages vulnerabilities in WordPress Core's REST API and WP_Query to achieve unauthenticated remote code execution on default installations.
The JadePuffer campaign utilized an autonomous LLM-driven agent to exploit a Langflow vulnerability, pivot to production databases, and execute a self-correcting ransomware operation.
Russian FSB Center 16 (Static Tundra) targets critical infrastructure by exploiting weak SNMP configurations and legacy Cisco vulnerabilities to exfiltrate device configurations.
Threat actors are exploiting an unauthenticated remote code execution vulnerability in Langflow (CVE-2026-33017) to deploy a multi-stage Monero cryptomining toolchain and spread via SSH key reuse.
Attackers weaponized an unauthenticated RCE in Langflow within 20 hours of disclosure to exfiltrate credentials and deploy second-stage payloads.