Sandworm Team is a apt_group tracked across 10 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed April 28, 2026; most recent activity July 22, 2026.
In 2026, Iranian APT groups, including MuddyWater, APT42, and APT34, intensified cyber operations against U.S. targets, exploiting geopolitical tensions. MuddyWater deployed a backdoor named Dindoor to compromise U.S.…
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of critical vulnerabilities in Lantronix EDS5000-series devices and Ubiquiti's UniFi OS. The Lantronix vulnerability,…
Zimperium's zLabs has reported a significant increase in Android Banking Trojan activity, identifying four distinct campaigns: RecruitRat, SaferRat, Astrinox, and Massiv. These campaigns utilize advanced…
Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026,…
On May 20, 2026, The Oncology Institute, Inc. was notified of unauthorized access to its systems by Kroll, a third-party vendor. The incident, confirmed in an SEC filing on May 22, 2026, involved patient data…
A stack-based buffer overflow vulnerability (CVE-2026-5525) has been identified in Notepad++ version 8.9.3. This flaw occurs when a user drops a directory path of 259 characters onto the application, causing a stack…
The ATT&CK framework has released version 19, which includes significant updates to its structure and coverage. Notably, the Defense Evasion Tactic has been split into two distinct categories: Stealth and Defense…