Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
3 intel reports
The CSuite operation targets US and European organizations using sophisticated phishing lures to steal Microsoft 365 sessions and deploy legitimate RMM tools like ScreenConnect for persistent endpoint access.
The PhantomEnigma campaign leverages compromised Brazilian .gov.br infrastructure to deliver a modular Node.js backdoor aimed at banking credential theft.
Turla (Secret Blizzard) targets government and military entities globally using the custom STOCKSTAY and Kazuar backdoors, often leveraging hijacked infrastructure.