Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande7 days ago

11 intel reports

Kimsuky leverages AI agents like opencode and HeadlessChrome to mass-produce decoy documents while evolving its GitHub-based LNK execution framework with enhanced evasion and persistence.

The threat actor zdn2pwn utilizes XHOPELESS v1.0, a sophisticated multi-phase wiper designed to permanently brick Windows systems by corrupting UEFI firmware, destroying disk partitions, and disabling all recovery mechanisms.

Suspected Russian clusters UNC6293, UNC7005, and UNC5976 are abusing legitimate authentication flows like OAuth and app passwords to target individuals in government, defense, and academia.

Threat actors can leverage WSL2's virtualized environment to download and stage payloads on Windows while remaining invisible to host-based network and process-attribution telemetry.

The SStar Agent is a Go-based cross-platform RAT delivered via a poisoned npm package (tw-style-utils) targeting Web3 developers with surveillance and exfiltration capabilities.