Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
13 intel reports
Everest is a sophisticated .NET-based ransomware that employs aggressive lateral movement, service termination, and process self-protection while targeting Windows environments.
Suspected North Korean threat actors are using 13 malicious npm packages to deliver WeaselBiscuit, a lightweight stealer targeting Chrome extension storage and system metadata.
A self-proclaimed bug bounty hunter utilizes LLM-generated JavaScript malware named PhantomRaven to compromise developer environments via typosquatted npm packages for credential theft.
A Russian-speaking operator compromised over 14,000 Dahua IP cameras globally, primarily in Ukraine and Russia, using authentication bypasses, P2P relay abuse, and credential brute-forcing.
A sophisticated supply chain attack compromised the AsyncAPI npm organization to distribute the Miasma multi-stage dropper, targeting developers for credential theft and lateral movement.
Russian-speaking actor UAT-11795 is targeting US and European users with trojanized installers for MobaXterm, WebEx, and Zoom to deploy the novel Starland RAT and WLDR PowerShell agent.
A Russian-speaking attacker is deploying the Meow AppleScript RAT via ClickFix social engineering lures to exfiltrate data and hijack cryptocurrency wallets on macOS.
Play Ransomware Group's custom Grixba infostealer has evolved from a monolithic tool to a modular, evasive scanner frequently deployed by DPRK-linked initial access brokers.
Threat actor SheldIO is deploying Amatera Stealer 4.0.2 via the EVALUSION campaign, featuring advanced evasion techniques and significantly expanded targeting for cryptocurrency wallets and messaging apps.
The PhantomRaven actor is targeting DeFi, Cloud, and AI developers via 33 malicious NPM packages using a multi-stage Remote Dynamic Dependency chain to harvest credentials.