Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande10 days ago

4 intel reports

The threat actor Storm-2372 is utilizing AI-built phishing kits, TokenLover and YaksaLover, to automate large-scale BEC attacks and persistence via Windows Hello for Business key injection.

The EvilTokens Phishing-as-a-Service platform is weaponizing Railway.com PaaS infrastructure to conduct large-scale OAuth token replay and device code phishing campaigns against Microsoft 365 environments.