Trellix Reports on Five Evasive Cyber Campaigns in 2026

Trellix Reports on Five Evasive Cyber Campaigns in 2026

First seen 10 Sep 2026, 18:47 UTC TrellixCybermagazine 77.0

Article Content

Browse articles
ThreatCluster

Trellix's SecondSight Threat Hunting Report details five significant cyber campaigns from the first half of 2026, including APT28 and the Axios npm supply chain attack. Attackers exploited trusted infrastructures and employed advanced evasion techniques, such as using compromised government accounts and weaponizing CVE-2026-21509. The APT28 spear-phishing campaign targeted European government and defense organizations, utilizing malicious emails that bypassed conventional detection methods. The report emphasizes the importance of combining AI and human intelligence in threat hunting, allowing for quicker detection and response to these sophisticated attacks. Trellix's findings highlight the ongoing challenges in cybersecurity as adversaries adapt their tactics to evade detection.

Key Points: • Trellix identified five major cyber campaigns in early 2026, including APT28 and Axios npm. • Attackers used sophisticated evasion techniques, exploiting trusted infrastructures and CVE-2026-21509. • The combination of AI and human intelligence is crucial for effective threat hunting and response.

Ask AI about this cluster

Timeline

2025-07-29
CVE-2025-31277 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-12
CVE-2025-43520 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-12
CVE-2025-14174 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-12
CVE-2025-43510 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-15
CVE-2025-43529 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-01-26
CVE-2026-21509 published
A Microsoft Office OLE security feature bypass was disclosed, exploited in APT28's campaign.
Cybermagazine
2026-01-26
CVE-2026-21509 added to CISA KEV
CISA listed CVE-2026-21509 for active exploitation on the same day it was published.
Cybermagazine
2026-02-11
CVE-2026-20700 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-20
Multiple CVEs added to CISA KEV
CVE-2025-43520, CVE-2025-43510, and CVE-2025-31277 were added to the KEV catalog for active exploitation.
Trellix
Recent
Trellix releases threat hunting report
The report outlines five cyber campaigns from early 2026, focusing on evasion techniques and AI's role in detection.
Cybermagazine