Related Threat Clusters
-
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Critical RCE Vulnerability in Zimbra Exploited by Attackers
A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers…
35 articles · Updated August 19, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability
The SUNBURST backdoor, discovered by FireEye, exploits trojanized updates to SolarWinds Orion software, affecting numerous public and private organizations globally. The attack vector involves a malicious DLL,…
2 articles · Updated June 16, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques
Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These…
10 articles · Updated August 21, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
UNC1151 Cyber Operations Linked to Belarusian Government and Ghostwriter Campaign
Mandiant Threat Intelligence has assessed with high confidence that UNC1151 is linked to the Belarusian government, conducting cyber operations primarily targeting Ukraine, Lithuania, Latvia, Poland, and Germany. The…
3 articles · Updated May 14, 2026
Recent Intelligence Reports
- Communication Channel Identity Risks — unit42.paloaltonetworks.com · August 31, 2026
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams — Unit42.Paloaltonetworks · August 31, 2026
- Threat Intelligence — www.eset.com · August 27, 2026
- GTIG Tracks Three Russian Espionage Clusters Abusing Auth Flows — Technadu · August 21, 2026
- Apt29 Evolving Diplomatic Phishing — cloud.google.com · August 21, 2026
- Distinct Clusters Target Individuals Of Interest To Russia — cloud.google.com · August 21, 2026
- Russian snoops add OAuth abuse to targeted phishing campaigns — Theregister · August 21, 2026
- Critical Zimbra RCE flaw now actively exploited in attacks — Bleepingcomputer · August 20, 2026