Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande9 days ago

8 intel reports

The SleeperGem campaign involves compromised RubyGems that drop a persistent backdoor and native daemon specifically targeting developer machines while evading CI/CD environments.

Threat actors are spoofing OAuth client IDs in Microsoft Entra to perform stealthy user enumeration and credential validation without generating successful sign-in logs.

A customized variant of DcRAT named BeepRAT is being distributed via a Chinese phone number management utility, targeting telecommunications providers with an extensive C2 command framework.

The EDRChoker tool weaponizes Windows Policy-based Quality of Service (QoS) to throttle EDR process bandwidth to 8 bits per second, effectively isolating them from their management servers.

Threat actors can abuse Windows Quality of Service (QoS) policies via PowerShell or WMI to throttle EDR agent outbound bandwidth to near zero, effectively silencing cloud-based telemetry.

Nation-state actors including Cloaked Ursa and Curious Serpens are weaponizing the ROADtools framework to enumerate Entra ID environments and maintain persistence through rogue device registration.