Hafnium is a China-based APT group historically known for exploiting Microsoft Exchange Server vulnerabilities to gain initial access, establish persistence, and move laterally within target networks.
Hafnium is a China-based APT group historically known for exploiting Microsoft Exchange Server vulnerabilities to gain initial access, establish persistence, and move laterally within target networks. Its campaigns have underscored the ongoing risk to on-premises Exchange environments and the critical need for rapid patching, strong access controls, and robust monitoring to defend against such threats.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026,…
On May 20, 2026, The Oncology Institute, Inc. was notified of unauthorized access to its systems by Kroll, a third-party vendor. The incident, confirmed in an SEC filing on May 22, 2026, involved patient data…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have issued new guidance to help organizations secure their on-premises Microsoft Exchange Servers. This advisory…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) have issued new guidance to enhance security for Microsoft Exchange Servers amid ongoing cyber threats. This…
Germany's infosec office (BSI) reported that 92 percent of Exchange servers in the country are still operating on out-of-support software. This situation follows Microsoft's termination of support for Exchange versions…
Germany's infosec office (BSI) reports that 92% of Exchange servers in the country are still operating on software that is no longer supported. This situation follows Microsoft's termination of support for Exchange…