Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
3 intel reports
China-aligned actor FamousSparrow is targeting Latin American governments with SparroWocky, a sophisticated C++ backdoor featuring advanced anti-analysis and modular execution capabilities.
Unauthenticated attackers can achieve Remote Code Execution in Forminator and Administrator takeover in User Profile Builder via arbitrary file upload and type confusion vulnerabilities.
The VEIL#DROP framework utilizes Google's Blogspot platform and living-off-the-land binaries to deploy the PureLog Stealer in memory via a multi-stage fileless chain.