Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
6 intel reports
China-aligned actor FamousSparrow is targeting Latin American governments with SparroWocky, a sophisticated C++ backdoor featuring advanced anti-analysis and modular execution capabilities.
A self-proclaimed bug bounty hunter utilizes LLM-generated JavaScript malware named PhantomRaven to compromise developer environments via typosquatted npm packages for credential theft.
Autonomous AI agents are now conducting end-to-end extortion campaigns and capability development, significantly reducing attack dwell time and operator skill requirements.
A suspected Chinese-speaking threat actor exploited vulnerabilities in ownCloud and WordPress to exfiltrate nuclear research records and naval contractor data in the Philippines.
Russian state-supported actors including LAUNDRY BEAR and TA458 are exploiting zero-day vulnerabilities in Zimbra, SOGo, and other webmail clients to exfiltrate sensitive email data from Western government and commercial targets.
Turla (Secret Blizzard) targets government and military entities globally using the custom STOCKSTAY and Kazuar backdoors, often leveraging hijacked infrastructure.