Related Threat Clusters
-
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Critical RCE Vulnerability in Zimbra Exploited by Attackers
A critical remote code execution vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite is being actively exploited by attackers. The flaw, which affects versions prior to 10.1.20, allows unauthenticated attackers…
35 articles · Updated August 19, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Russian Cyber Espionage Clusters Exploit OAuth and Phishing Techniques
Google's Threat Intelligence Group (GTIG) is tracking three Russian cyber espionage clusters—UNC6293, UNC7005, and UNC5976—targeting individuals in academia, defense, and government across Europe and the U.S. These…
10 articles · Updated August 21, 2026 -
Azerbaijan Establishes Cybersecurity Agency Amid Rising Russian and Iranian Threats
Azerbaijan has created a National Cybersecurity Agency (NCA) to combat increasing cyber threats from Russia and Iran. This decision follows a significant cyberattack in February 2025 attributed to the Russian group…
2 articles · Updated June 15, 2026 -
CallPhantom Fraudulent Apps Scam Millions of Android Users
A series of fraudulent apps named CallPhantom were discovered on Google Play, promising access to call histories for any phone number. Users were tricked into paying for subscriptions, only to receive fabricated data.…
7 articles · Updated May 7, 2026 -
Silver Fox APT Deploys ValleyRAT via Fake Installers Targeting China
The Silver Fox APT group has launched a campaign targeting users in China by distributing malware through fake installers of popular applications, including Microsoft Teams. The malware, known as ValleyRAT, employs…
2 articles · Updated December 4, 2025 -
SEC Drops Case Against SolarWinds Over 2020 Cyberattack
The SEC has dropped its civil fraud case against SolarWinds and its CISO, Tim Brown, related to the 2020 SUNBURST cyberattack. This decision ends a significant legal action that aimed to hold the company accountable for…
8 articles · Updated November 20, 2025 -
SEC Dismisses Case Against SolarWinds Over 2020 Cyberattack
The SEC has dropped its case against SolarWinds and its CISO, Tim Brown, regarding their handling of a 2020 cyberattack linked to Russian hackers. The lawsuit, initiated in late 2023, accused them of failing to disclose…
8 articles · Updated November 22, 2025 -
Bitdefender Achieves 100% Telemetry in EDR Test
Bitdefender GravityZone Business Security Enterprise achieved 100% relevant telemetry in AV-Comparatives’ inaugural EDR Detection Validation Certification Test published in May 2026. This certification tested the…
2 articles · Updated May 15, 2026
Recent Intelligence Reports
- Threat Intelligence — www.eset.com · August 27, 2026
- Russian snoops add OAuth abuse to targeted phishing campaigns — Theregister · August 21, 2026
- Critical Zimbra RCE flaw now actively exploited in attacks — Bleepingcomputer · August 20, 2026
- Azerbaijan's New Cybersecurity Agency Targets Rising Russian and Iranian Digital Threats — United24Media · June 15, 2026
- Azerbaijan establishes National Cybersecurity Agency to protect against attacks of Russian ... - УНН — Unn.Ua · June 14, 2026
- Bitdefender GravityZone: 100% Telemetry in AV — Bitdefender · May 15, 2026
- Bitdefender GravityZone: 100% Telemetry in AV — Bitdefender · May 14, 2026
- ESET Threat Intelligence — www.eset.com · May 7, 2026