Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
13 intel reports
The Shai Hulud threat actor compromised SAP CAP framework packages by exploiting an AI coding assistant's GitHub integration to inject malicious code and steal npm OIDC tokens.
SERPENTINE#CLOUD has updated its delivery chain using ClickFix lures and Cloudflare tunnels to deploy a multi-RAT suite including Brute Ratel C4 and PureHVNC.
North Korean-linked EtherRAT utilizes 'EtherHiding' via Ethereum smart contracts to manage resilient C2 infrastructure for host fingerprinting and asset theft.