Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
An operator identified as Zaib Ali uses a massive npm typosquatting campaign to discover infrastructure and a custom FastAPI framework called VHX Harvester to hijack GPU resources on the vast.ai marketplace.
Storm-2945, a sub-cluster of Midnight Blizzard (APT29), is hijacking hospitality Wi-Fi networks to deliver CornFlake RAT and ChocoShell infostealer via DNS poisoning and fake update prompts.
Russian intelligence services APT28 (GRU) and FSB Center 16 are systematically compromising SOHO and enterprise routers to build global proxy networks and conduct DNS hijacking for credential theft.
The ErrTraffic framework utilizes the ClickFix social engineering tactic and EtherHiding technique to distribute various infostealers and loaders through compromised WordPress sites and AI-themed lures.