Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
3 intel reports
The RevStealer infostealer uses trojanized Electron applications and blockchain-based C2 failover to target credentials, cryptocurrency wallets, and browser data on Windows systems.
TWINLOOT is a modular Python implant using Microsoft SharePoint, Teams, and headless Edge browsers for stealthy command-and-control and lateral movement.
Exploits named BlueHammer and RedSun leverage a TOCTOU race condition (CVE-2026-33825) in Windows Defender to achieve SYSTEM-level privilege escalation via filesystem manipulation.