Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
6 intel reports
The Cling botnet exploits multiple IoT vulnerabilities to deploy a worm-like malware that repurposes legitimate STUN traffic and infrastructure for command-and-control communications.
Sophisticated threat actor UAT-8616 and additional clusters are exploiting at least 12 vulnerabilities in Cisco SD-WAN, FMC, and ASA/FTD devices for persistent access and root escalation.
KATARU is a newly observed IoT malware family that utilizes Linux local privilege escalation exploits and encrypted C2 to conduct DDoS attacks.
The Evooo1Bot and GorillaBot threat actors are deploying highly modular Mirai-based malware targeting Linux systems and IoT devices to execute large-scale DDoS attacks and establish persistent proxy relays.
Tengu is an evolved Mirai-derived IoT botnet featuring AEAD-encrypted C2, proxy capabilities, and aggressive self-defense mechanisms targeting Linux and Android systems.
The Chinese threat actor VerdantBamboo is targeting unmonitored edge appliances such as firewalls and NAS devices to maintain persistence and bypass EDR security controls.