Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
5 intel reports
The Go-based ClosedQuorum malware utilizes multiple commercial AI models to autonomously select post-compromise actions, including credential dumping and process injection, without human operator intervention.
Purple Ghosts compromised over 14,000 Dahua cameras globally using an authentication-bypass chain and P2P relay exploitation to install persistent backdoors and harvest credentials.
A Russian-speaking operator compromised over 14,000 Dahua IP cameras globally, primarily in Ukraine and Russia, using authentication bypasses, P2P relay abuse, and credential brute-forcing.
Russian state-sponsored actor BlueDelta utilized macro-enabled Word documents to deploy HOOKEDGE, a batch-script backdoor abusing legitimate webhook services for C2 and exfiltration targeting European government entities.
The Miasma threat actor compromised 56 npm packages to steal CI/CD secrets and deploy persistent backdoors using a novel binding.gyp execution trigger.