Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
5 intel reports
The ServiceNow Red Team developed Dark, an open-source Mythic C2 agent written in Crystal that features in-memory Beacon Object File (BOF) execution for macOS and Linux.
The SleeperGem campaign involves compromised RubyGems that drop a persistent backdoor and native daemon specifically targeting developer machines while evading CI/CD environments.
The Iranian threat actor Cavern Manticore is targeting Israeli IT providers and government sectors using the modular Cavern C2 framework and supply chain exploitation.
The ClickFix campaign has evolved to deploy PySoxy, an open-source Python SOCKS5 proxy, for redundant encrypted C2 access and persistence following initial social engineering.
The Nightmare-Eclipse toolset, including BlueHammer and RedSun, was observed in a live intrusion following initial access via compromised FortiGate VPN credentials.