Related Threat Clusters
-
Cisco Fixes Critical AsyncOS Vulnerability Under Attack
Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…
11 articles · Updated January 15, 2026 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
Malaysia's Cyber Threat Landscape Faces Significant Transformation Amid Digital Expansion
Malaysia's cyber threat landscape is experiencing a structural shift due to rapid digital growth and geopolitical factors, making it a prime target for cyber attacks. A report from Cyfirma indicates that state-backed…
2 articles · Updated April 8, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026
Recent Intelligence Reports
- 005 — attack.mitre.org · August 20, 2026
- Dead Drop Resolver — attack.mitre.org · August 14, 2026
- T1027 — attack.mitre.org · August 7, 2026
- North Korea Hid New Google Drive Backdoors Inside South Korean Groupware Firms — Techtimes · July 24, 2026
- 003 — attack.mitre.org · July 23, 2026
- T1102 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026