Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande10 days ago

8 intel reports

The Go-based ClosedQuorum malware utilizes multiple commercial AI models to autonomously select post-compromise actions, including credential dumping and process injection, without human operator intervention.

Threat actors are abusing FTP banners as Dead Drop Resolvers (DDRs) to deliver novel RATs, E4del and PINHOLE, using legitimate services like Pinterest and SurveyMonkey for configuration retrieval.

Russian-speaking actor UAT-11795 is targeting US and European users with trojanized installers for MobaXterm, WebEx, and Zoom to deploy the novel Starland RAT and WLDR PowerShell agent.

Russian-speaking threat actor UAT-11795 is utilizing ClickFix lures and trojanized software to deploy novel Python-based Starland RAT and PowerShell-based WLDR agent for cryptocurrency theft.