Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
6 intel reports
ShinyHunters (UNC6240) is targeting healthcare through identity-access extortion using vishing/AitM kits and mass exploitation of CVE-2026-35273 in Oracle PeopleSoft.
ChainDrop, a descendant of the Shai-Hulud malware family, is a self-propagating npm worm targeting developer workstations and CI/CD pipelines to harvest cloud, registry, and AI tool credentials.
Russian state-supported actors including LAUNDRY BEAR and TA458 are exploiting zero-day vulnerabilities in Zimbra, SOGo, and other webmail clients to exfiltrate sensitive email data from Western government and commercial targets.
The pro-Ukrainian threat actor Bearlyfy (Toy Ghouls) is targeting Russian organizations using their custom GenieLocker ransomware across Windows, Linux, and ESXi platforms.
Kimsuky targeted South Korean groupware vendors to compromise downstream customers using new Gomir malware variants and credential harvesting techniques.
The Iranian threat actor Cavern Manticore is targeting Israeli IT providers and government sectors using the modular Cavern C2 framework and supply chain exploitation.