Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande10 days ago

3 intel reports

The threat actor Storm-2372 is utilizing AI-built phishing kits, TokenLover and YaksaLover, to automate large-scale BEC attacks and persistence via Windows Hello for Business key injection.

Threat actors are increasingly abusing native Microsoft 365 mailbox rules to maintain persistence, suppress security alerts, and automate data exfiltration following account compromise.