Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
9 intel reports
The JeetBot browser extension exfiltrates Twitch OAuth tokens to Russian proxy infrastructure, affecting over 31,000 users.
Rapidly deployed AI-built educational applications are collecting sensitive student data, including PII and biometric inputs, often without basic security configurations or privacy policies.
Tengu is a Linux-based botnet targeting IoT and server environments, utilizing kernel-worker masquerading and multiple persistence mechanisms to facilitate DDoS attacks.
TWINLOOT is a modular Python implant using Microsoft SharePoint, Teams, and headless Edge browsers for stealthy command-and-control and lateral movement.
CISA red teams achieved full domain compromise and sensitive system access in two organizations, highlighting risks in cloud identity permissions and Active Directory Certificate Services (ADCS).
OnyxC2 is a sophisticated Malware-as-a-Service info-stealer and remote access toolkit targeting over 200 applications including crypto wallets, browsers, and 2FA extensions.
LabubaRAT is a newly discovered Rust-based remote access tool that uses NVIDIA-themed metadata and multiple communication channels, including DNS tunneling, to maintain persistence and control over infected Windows hosts.
StealC and Amadey operate as a coordinated Malware-as-a-Service ecosystem to harvest credentials and provide initial access for ransomware and espionage operations.
A Qilin ransomware affiliate is targeting WatchGuard and Fortinet appliances using multiple CVEs to deploy Sliver C2 and establish reverse SOCKS tunnels into internal networks.