In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
Handala Hack, an Iranian state-linked threat actor, has executed a series of destructive cyberattacks targeting organizations in Israel, Albania, and the United States. The attacks utilize Remote Desktop Protocol (RDP)…
The Iran-aligned hacking group Handala has claimed responsibility for breaching California water utility systems, framing the operation as retaliation for recent US airstrikes that damaged water infrastructure in Iran.…
CVE-2026-21514 is a security feature bypass vulnerability in Microsoft Word, disclosed on February 10, 2026. This flaw allows attackers to exploit nearly 14 million assets across seven Tier 1 countries, primarily in the…
Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026,…
On May 20, 2026, The Oncology Institute, Inc. was notified of unauthorized access to its systems by Kroll, a third-party vendor. The incident, confirmed in an SEC filing on May 22, 2026, involved patient data…
On April 1, 2026, Chime Financial's mobile app experienced a significant outage attributed to a cyberattack by the pro-Iranian hacker group Team 313. Customers reported being unable to access their accounts, leading to…