Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
The North Korean WaterPlum group uses fake job interviews and malicious development tools to compromise IT professionals, stealing over $10.7 million in cryptocurrency.
ARToken is a Phishing-as-a-Service platform that abuses Microsoft's OAuth 2.0 device code flow to bypass MFA and achieve full Entra tenant takeover.
The threat actor Storm-2372 is utilizing AI-built phishing kits, TokenLover and YaksaLover, to automate large-scale BEC attacks and persistence via Windows Hello for Business key injection.
The EvilTokens Phishing-as-a-Service platform is weaponizing Railway.com PaaS infrastructure to conduct large-scale OAuth token replay and device code phishing campaigns against Microsoft 365 environments.