Intel Exchange

Browse public community intelligence reports, source analysis, and threat research.

Cover image for Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited

Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.

Vikas Lokhande@vlokhande9 days ago

7 intel reports

The Russian-aligned Lunex Malware-as-a-Service platform utilizes a complex four-stage attack chain, including BYOVD-based EDR neutralization, to deploy a sophisticated information stealer and C2 agent.

Unauthenticated attackers are chaining signature algorithm confusion and OpenSSL error handling vulnerabilities to bypass authentication and gain administrator access on WordPress sites using the miniOrange SAML SSO plugin.

Adversaries can bypass passwordless protections by exploiting Google’s Cloud Authenticator onboarding and recovery flows to extract master keys or forge authentication signatures.

Mandiant researchers identified a method for attackers to recover active ADFS signing keys from Machine DPAPI when configuration drift occurs during manual certificate rotations, enabling Golden SAML token forgery.