Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
11 intel reports
The threat actor Larva-25012 is utilizing the DPLoader malware to distribute various Proxyware SDKs like DigitalPulse and SOAX to monetize infected systems' bandwidth.
The RevStealer infostealer uses trojanized Electron applications and blockchain-based C2 failover to target credentials, cryptocurrency wallets, and browser data on Windows systems.
Kimsuky leverages AI agents like opencode and HeadlessChrome to mass-produce decoy documents while evolving its GitHub-based LNK execution framework with enhanced evasion and persistence.
The threat actor zdn2pwn utilizes XHOPELESS v1.0, a sophisticated multi-phase wiper designed to permanently brick Windows systems by corrupting UEFI firmware, destroying disk partitions, and disabling all recovery mechanisms.
Suspected Russian clusters UNC6293, UNC7005, and UNC5976 are abusing legitimate authentication flows like OAuth and app passwords to target individuals in government, defense, and academia.
An isolated malware dropper, ascii-fetcher, utilizes a malicious npm dependency named @jaymara/jsononifier to execute XOR-encoded commands on Windows systems via VS Code.
Attackers leverage the Windows Distributed Component Object Model (DCOM) to execute remote commands via trusted binaries like mmc.exe and excel.exe.
Threat actors can leverage WSL2's virtualized environment to download and stage payloads on Windows while remaining invisible to host-based network and process-attribution telemetry.
The SStar Agent is a Go-based cross-platform RAT delivered via a poisoned npm package (tw-style-utils) targeting Web3 developers with surveillance and exfiltration capabilities.
NVIDIA's NemoClaw sandbox environment is vulnerable to data exfiltration and configuration poisoning via weaponized authorized tools and emoji-based evasion.