Related Threat Clusters
-
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Russian APT Exploits Zimbra XSS to Target Ukrainian Government
A Russian state-linked advanced persistent threat (APT) has targeted a Ukrainian government agency through a cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite, identified as CVE-2025-66376. The…
4 articles · Updated March 20, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
FrostyNeighbor Cyberespionage Campaign Targets Ukrainian and Polish Governments
The Belarus-aligned cyber group FrostyNeighbor has launched a targeted campaign against government organizations in Ukraine and Poland since March 2026. Utilizing spearphishing techniques, the group delivers malicious…
8 articles · Updated May 14, 2026 -
APT28 Revives Advanced Malware Toolkit for Cyber-Espionage
APT28, a Russian threat actor, has reactivated its malware development team and deployed a modern espionage toolkit that includes a customized version of the Covenant open-source tool. This resurgence indicates a…
10 articles · Updated March 10, 2026 -
APT28's Operation MacroMaze: Macro Malware Campaign Targets Europe
APT28, a Russia-linked advanced persistent threat group, conducted a cyberespionage campaign named Operation MacroMaze from September 2025 to January 2026. The campaign involved deploying macro malware embedded in…
3 articles · Updated February 24, 2026 -
Cyberattacks Target Ukraine and EU via Microsoft Office Vulnerability
CERT-UA has reported a new wave of cyberattacks targeting Ukrainian government agencies and EU organizations, exploiting the Microsoft Office vulnerability CVE-2026-21509. Attackers are using malicious emails disguised…
59 articles · Updated February 2, 2026 -
Benchmarking Cyber Threat Intelligence Services: Key Findings
A hands-on benchmark of five cyber threat intelligence services was conducted, evaluating them against 33 criteria across eight categories. The evaluation utilized historical indicators of compromise (IOCs), six threat…
4 articles · Updated August 12, 2026
Recent Intelligence Reports
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- 621822 — www.cybersecuritydive.com · May 14, 2026
- APT28 exploit routers to enable DNS hijacking operations — Wired-Gov · April 8, 2026
- FBI Takes Down APT28 Network Behind Global DNS Hijacking Attacks — Thecyberexpress · April 8, 2026
- Warning from UK: Russian cybercriminals hijack routers to steal passwords — Heise.De · April 7, 2026
- Russian Hackers Exploiting Home and Small — Cybersecuritynews · April 7, 2026
- Russian APT weaponizes critical Zimbra bug in Ukraine-targeted intrusions — Scworld · March 20, 2026