Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
3 intel reports
The threat actor Storm-2372 is utilizing AI-built phishing kits, TokenLover and YaksaLover, to automate large-scale BEC attacks and persistence via Windows Hello for Business key injection.
UNC6508, a PRC-nexus threat actor, targets medical and military research institutions using INFINITERED malware to harvest credentials and exfiltrate data via manipulated compliance rules.
Threat actors are increasingly abusing native Microsoft 365 mailbox rules to maintain persistence, suppress security alerts, and automate data exfiltration following account compromise.