Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
Storm-2992 operates EvilTokens, an AI-driven Phishing-as-a-Service platform targeting Microsoft 365 through device code authentication abuse to facilitate business email compromise.
The Forg365 Phishing-as-a-Service platform utilizes AI-assisted lures, device-code flow abuse, and a custom browser extension to compromise and maintain access to Microsoft 365 environments.
The EvilTokens Phishing-as-a-Service leverages Microsoft device code authentication flows and AI-driven automation to exfiltrate tokens and orchestrate large-scale Business Email Compromise (BEC) attacks.
The threat actor Storm-2372 is utilizing the EvilToken Phishing-as-a-Service (PhaaS) toolkit to execute automated, AI-enhanced device code phishing attacks against organizational accounts.