Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande10 days ago

4 intel reports

Storm-2992 operates EvilTokens, an AI-driven Phishing-as-a-Service platform targeting Microsoft 365 through device code authentication abuse to facilitate business email compromise.

The Forg365 Phishing-as-a-Service platform utilizes AI-assisted lures, device-code flow abuse, and a custom browser extension to compromise and maintain access to Microsoft 365 environments.

The EvilTokens Phishing-as-a-Service leverages Microsoft device code authentication flows and AI-driven automation to exfiltrate tokens and orchestrate large-scale Business Email Compromise (BEC) attacks.

The threat actor Storm-2372 is utilizing the EvilToken Phishing-as-a-Service (PhaaS) toolkit to execute automated, AI-enhanced device code phishing attacks against organizational accounts.