Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
14 intel reports
An attacker compromised the CDN API keys of OptinMonster, TrustPulse, and PushEngage to serve tampered JavaScript that creates rogue admin accounts on customer sites.
The Pakistan-aligned APT36 is deploying a new variant of the SHEETCREEP RAT using Google Sheets for C2 communication, targeting Indian diplomatic interests.
Mustang Panda APT utilizes a multi-stage PlugX execution chain involving legitimate G DATA binaries and complex obfuscation to target systems via fake browser updates.
The China-aligned APT group Webworm has shifted focus to European government entities using new backdoors EchoCreep and GraphWorm along with custom proxy tools.