Dev-0322 is an apt_group tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.
Dev-0322 is a apt_group tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed February 24, 2026; most recent activity June 5, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of a high-severity vulnerability in SolarWinds Serv-U, tracked as CVE-2026-28318. This flaw allows…
SolarWinds has issued security updates for four critical remote code execution vulnerabilities in its Serv-U software, which could allow attackers to gain root access to unpatched servers. The affected software is used…
A remote code execution (RCE) vulnerability in BeyondTrust products is currently under active exploitation. Organizations using affected BeyondTrust software are at risk, and immediate action is recommended to mitigate…
Dev-0322 is an apt_group tracked by ThreatCluster, appearing in 3 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning Dev-0322 on ThreatCluster is dated June 5, 2026. Activity was first observed February 24, 2026, giving a tracked span from then to June 5, 2026.
Across ThreatCluster reporting, Dev-0322 most frequently co-occurs with Data Breach, DDoS, Ransomware, Zero-day Exploit, SolarWinds, among 12 tracked related entities.
The most significant recent cluster is “Active Exploitation of SolarWinds Serv-U Flaw CVE-2026-28318” (13 articles · Updated June 5, 2026). Dev-0322 appears across 3 threat clusters in total, listed above with sources.
Dev-0322 appears in 3 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.