Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
7 intel reports
Storm-2992 operates EvilTokens, an AI-driven Phishing-as-a-Service platform targeting Microsoft 365 through device code authentication abuse to facilitate business email compromise.
Storm-2755 (Payroll Pirates) uses AiTM phishing and residential proxies to compromise Microsoft 365 accounts for financial data theft and payroll diversion.
Chinese-speaking threat actors are using OctLurk and SilkLurk backdoors to target government, healthcare, and educational sectors in Central Asia via modular in-memory plugins.
The Russia-aligned actor TA458 uses half-click XSS zero-day exploits against SOGo, Zimbra, and Roundcube webmail to deploy SpyPress malware and steal sensitive government data.
The EvilTokens and ARToken Phishing-as-a-Service (PhaaS) platforms use Microsoft Device Code flows and browser-side decryption to bypass MFA and achieve persistent Microsoft 365 account takeovers.
ARToken is an EvilTokens-linked Phishing-as-a-Service platform that uses Microsoft OAuth Device Code grants to capture Primary Refresh Tokens (PRTs) for persistent access and BEC operations.
The ToddyCat APT group utilizes Umbrij malware to compromise corporate Gmail accounts by leveraging a technique called Shadow Token via Remote Debug (STRD) to steal OAuth tokens.