Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
The Aeternum botnet utilizes the public Polygon blockchain as a decentralized command-and-control infrastructure to distribute XWorm, XMRig, and data-stealing payloads.
Threat actors are exploiting CVE-2026-48558 in SimpleHelp RMM software to deploy TaskWeaver and Djinn Stealer, targeting cloud, AI, and developer credentials across Windows, macOS, and Linux.
Threat actors are exploiting CVE-2026-48558 in SimpleHelp RMM to deploy TaskWeaver, a modular Node.js loader, and Djinn Stealer, a cross-platform information stealer targeting developer and AI credentials.
The Mini Shai-Hulud worm was deployed via compromised @antv npm packages to exfiltrate developer secrets and propagate to other repositories.