Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
6 intel reports
Financially motivated actors are leveraging ARTEX, an open-source agentic AI pentesting tool, to automate breaches and data exfiltration from South Korean financial institutions.
Gray-market services like Poison Claude and Ecomagent exploit cloud promotional credits and synthetic identities to resell discounted, proxied access to frontier AI models.
The Pluto Hephaestus threat actor utilizes the AI-powered 'Hephaestus' framework to automate the full attack lifecycle against government and educational targets in Southeast Asia and South Korea.
Egyptian threat actor codemado and associates leverage custom Evilginx forks and Device Code Flow abuse to target Microsoft 365 and cryptocurrency users.
The ErrTraffic framework utilizes the ClickFix social engineering tactic and EtherHiding technique to distribute various infostealers and loaders through compromised WordPress sites and AI-themed lures.
Russian-speaking threat actors are conducting a massive, automated credential-harvesting campaign named 'FortiBleed' targeting over 75,000 internet-facing Fortinet FortiGate firewalls and SSL VPNs across nearly 200 countries.