Velvet Ant is a apt_group tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed December 12, 2025; most recent activity June 15, 2026.
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
The 'Payroll Pirate' campaign has emerged, utilizing advanced phishing and AiTM session hijacking to bypass MFA and reroute payroll disbursements. Targeting mid-market and enterprise organizations, attackers exploit…
The 2025 CWE Top 25 Most Dangerous Software Weaknesses list has been published, identifying critical vulnerabilities that pose significant risks to software security. This list is intended for developers and…