Related Threat Clusters
-
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
2 articles · Updated June 17, 2026 -
State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits
Recent reports indicate a significant rise in the exploitation of edge devices, such as VPN gateways and firewalls, by state-sponsored actors. These devices have become the primary attack vector for espionage…
3 articles · Updated July 22, 2026 -
Belgian State Security and Organizations Targeted by Cyberattacks
Between May 2025 and Spring 2026, the Belgian State Security experienced a data breach exposing employee information, attributed to vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). Hackers exploited flaws…
5 articles · Updated June 23, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
5 articles · Updated June 5, 2026 -
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
2 articles · Updated June 5, 2026 -
Korean Diplomatic Academy Hacked for Nearly 10 Months, Data Potentially Compromised
The Korea National Diplomatic Academy's online training platform was hacked for nearly 10 months, from April 2025 to February 2026. Attackers exploited a zero-day vulnerability in the server software, allowing them to…
35 articles · Updated July 20, 2026 -
Google Reports 90 Exploited Zero-Day Vulnerabilities in 2025
Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors…
35 articles · Updated March 5, 2026 -
Chinese Hackers Exploit Dell Zero-Day Flaw CVE-2026-22769 Since Mid-2024
A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw, tracked as CVE-2026-22769, features a…
40 articles · Updated February 17, 2026 -
F5 BIG-IP Security Breach Exposes Critical Infrastructure Risks
F5 disclosed a security breach affecting its BIG-IP product line, where a state-sponsored threat actor gained unauthorized access to the company's internal engineering and product development environments. The attackers…
2 articles · Updated November 5, 2025
Recent Intelligence Reports
- Mandiant and Google's Threat Intelligence Group documented — cloud.google.com · July 29, 2026
- Edge Under Siege How State Sponsored Actors Exploit Your Perimeter — www.trendmicro.com · July 23, 2026
- South Korea's Diplomatic Roster Exposed by Zero-Day for Nearly Ten Months — Techtimes · July 20, 2026
- Belgian State Security hit by data breach, employee data potentially exposed — Cybernews · June 23, 2026
- Verdantbamboo Just Another Brickstorm In The Firewall — www.volexity.com · June 5, 2026
- Chinese APT deploys new malware to keep access to hacked networks — Bleepingcomputer · June 5, 2026
- Chinese APT deploys new malware to keep access to hacked networks — Bleepingcomputer · June 5, 2026
- China’s VerdantBamboo Experimented With Three Re — Thecyberexpress · June 5, 2026