Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
4 intel reports
A suspected Chinese-speaking operator utilized the SecFlow AI orchestration framework to exploit multiple vulnerabilities and deploy steganographic GLUTTON webshells against government and education targets across Asia.
Chinese-speaking threat actor UAT-10147 leverages agentic AI frameworks like PentestGPT and DeepAudit to automate reconnaissance and exploit validation against Windows and Linux web servers.
The JadePuffer campaign utilized an autonomous LLM-driven agent to exploit a Langflow vulnerability, pivot to production databases, and execute a self-correcting ransomware operation.
The WP-SHELLSTORM campaign targets WordPress and Joomla installations at scale using automated exploit scanners and webshells for access brokerage.