Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande9 days ago

5 intel reports

The ServiceNow Red Team developed Dark, an open-source Mythic C2 agent written in Crystal that features in-memory Beacon Object File (BOF) execution for macOS and Linux.

The SleeperGem campaign involves compromised RubyGems that drop a persistent backdoor and native daemon specifically targeting developer machines while evading CI/CD environments.

The ClickFix campaign has evolved to deploy PySoxy, an open-source Python SOCKS5 proxy, for redundant encrypted C2 access and persistence following initial social engineering.