Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
The CL-CRI-1171 threat actor operates a mature Pay-Per-Install (PPI) marketplace that leverages SEO poisoning and trojanized YouTube gaming content to distribute OfferLoader and a variety of secondary payloads including Insomnia RAT and ARKTunnel.
The BengalSEO group, linked to WeConnect Solutions and Garage2Global, utilizes sophisticated SEO poisoning and a custom Traffic Distribution System (TDS) to deploy MayaBot malware and tech support scams.
Threat actors Storm-2755 and Storm-2657 utilize AiTM session theft and Microsoft Graph API reconnaissance to execute financial theft by redirecting payroll payments.
Financially motivated actors are using SEO poisoning to impersonate AI tools like Gemini and Claude Code, delivering a fileless PowerShell infostealer to developer workstations.