Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
8 intel reports
Unauthenticated attackers are exploiting CVE-2026-104286, a critical path traversal vulnerability in FortiMail, to write arbitrary files and achieve persistent remote code execution.
Russian state-supported actors including LAUNDRY BEAR and TA458 are exploiting zero-day vulnerabilities in Zimbra, SOGo, and other webmail clients to exfiltrate sensitive email data from Western government and commercial targets.
Adversaries can exploit Azure Container Registry permissions to push malicious images, modify ACR Tasks, and abuse Managed Identities for secret exfiltration and remote code execution.
Akira ransomware actors utilized Bumblebee malware and AdaptixC2 via Bing SEO poisoning to gain initial access, move laterally, and exfiltrate over 75GB of data.
Bluekit PhaaS leverages advanced Browser-in-the-Middle (BitM) techniques and AI to bypass MFA by streaming live DOM interactions to victims.
The Drun Backdoor is a modular two-stage infostealer that utilizes the Chromelevator loader to inject into processes via direct syscalls, targeting browser credentials, session tokens, and gaming accounts.
The MexicanMafia threat actor, also known as PanchoVilla, is conducting a sophisticated campaign using the Kimera reconnaissance engine and custom exploits against perimeter devices in Latin America.
Atomic Stealer (AMOS) leverages a new macOS persistence mechanism, anti-VM evasion, and trojanized hardware wallet applications to exfiltrate sensitive data and crypto credentials.