Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande10 days ago

9 intel reports

2CLoader is a sophisticated new malware loader identified in August 2026 that uses indirect system calls and environment spoofing to deliver information stealers like Vidar and Remus.

An unidentified ransomware-related threat actor is using SloppyRAT, a new multi-stage malware, to establish network footholds via ClickFix lures and blockchain-based C2 resolution.

The Vectra (formerly Nyxel) actor operates VectraRAT, a custom Go and C++ Malware-as-a-Service platform delivered via Amadey and ClickFix campaigns targeting corporate Windows environments.

Blind Eagle (APT-C-36) is utilizing a modernized JC-46 AsyncRAT build featuring WNF process injection and a Chrome App-Bound Encryption bypass to target Latin American financial interests.