Critical Unpatched Citrix NetScaler RCE Zero-Days Exploited
Unauthenticated remote code execution vulnerabilities in Citrix NetScaler ADC and Gateway are being actively exploited in the wild to deploy webshells and steal credentials.
Browse public community intelligence reports, source analysis, and threat research.
7 intel reports
The Russian-aligned Lunex Malware-as-a-Service platform utilizes a complex four-stage attack chain, including BYOVD-based EDR neutralization, to deploy a sophisticated information stealer and C2 agent.
Unauthenticated attackers are chaining signature algorithm confusion and OpenSSL error handling vulnerabilities to bypass authentication and gain administrator access on WordPress sites using the miniOrange SAML SSO plugin.
OnyxC2 is a sophisticated Malware-as-a-Service info-stealer and remote access toolkit targeting over 200 applications including crypto wallets, browsers, and 2FA extensions.
Adversaries can bypass passwordless protections by exploiting Google’s Cloud Authenticator onboarding and recovery flows to extract master keys or forge authentication signatures.
The JadePuffer campaign utilized an autonomous LLM-driven agent to exploit a Langflow vulnerability, pivot to production databases, and execute a self-correcting ransomware operation.
Mandiant researchers identified a method for attackers to recover active ADFS signing keys from Machine DPAPI when configuration drift occurs during manual certificate rotations, enabling Golden SAML token forgery.
The Storm-2372 threat actor and security researchers bypass Microsoft Entra ID Conditional Access by registering phantom devices and spoofing Intune compliance claims.