Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Malaysia's Cyber Threat Landscape Faces Significant Transformation Amid Digital Expansion
Malaysia's cyber threat landscape is experiencing a structural shift due to rapid digital growth and geopolitical factors, making it a prime target for cyber attacks. A report from Cyfirma indicates that state-backed…
2 articles · Updated April 8, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
Spearphishing Campaigns Exploit Malicious Links for User Execution
Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information,…
2 articles · Updated September 2, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026 -
Chrome Vulnerabilities Allow Arbitrary Code Execution and System Crashes
Google has released a critical security update for Chrome, addressing two high-severity vulnerabilities that could allow arbitrary code execution and denial-of-service attacks. Users on Windows, macOS, and Linux are…
503 articles · Updated February 4, 2026 -
CYFIRMA Industry Reports on Cyber Threats in Telecommunications and Manufacturing
CYFIRMA released two industry reports focusing on the telecommunications and manufacturing sectors, analyzing the external threat landscape over the past three months. The reports provide insights into key trends and…
2 articles · Updated November 25, 2025
Recent Intelligence Reports
- 001 — attack.mitre.org · September 2, 2026
- T1189 — attack.mitre.org · August 7, 2026
- 001 — attack.mitre.org · July 23, 2026
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- External Remote Services — attack.mitre.org · June 3, 2026
- T1505.003 Web Shell — attack.mitre.org · May 13, 2026
- Malaysia's digital growth and geopolitics widen cyber attack surface, raising critical ... — Industrialcyber.Co · April 7, 2026
- CYFIRMA INDUSTRY REPORT : TELECOMMUNICATIONS & MEDIA — Cyfirma · November 25, 2025