Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande10 days ago

2 intel reports

The Forg365 Phishing-as-a-Service platform utilizes AI-assisted lures, device-code flow abuse, and a custom browser extension to compromise and maintain access to Microsoft 365 environments.

Threat actors are increasingly abusing native Microsoft 365 mailbox rules to maintain persistence, suppress security alerts, and automate data exfiltration following account compromise.