Related Threat Clusters
-
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
2 articles · Updated June 5, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Google Reports 90 Exploited Zero-Day Vulnerabilities in 2025
Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors…
35 articles · Updated March 5, 2026 -
Exploitation of Critical VMware vCenter Server Bug CVE-2024-37079
A critical vulnerability in VMware vCenter Server, tracked as CVE-2024-37079, is being actively exploited more than a year after Broadcom issued a patch. This out-of-bounds write flaw in the DCERPC protocol has a CVSS…
2 articles · Updated January 23, 2026 -
China's Brickstorm Malware Compromises US Critical Networks
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…
10 articles · Updated December 4, 2025 -
China Bans U.S. and Israeli Cybersecurity Software Amid National Security Concerns
Chinese authorities have instructed domestic firms to cease using cybersecurity software from over a dozen U.S. and Israeli companies due to national security concerns. Affected vendors include VMware, Palo Alto…
3 articles · Updated January 15, 2026 -
CISA Alerts on Chinese BrickStorm Malware Targeting VMware Servers
CISA, in collaboration with the NSA and Canada's Cyber Security Centre, has issued a warning about Chinese hackers using BrickStorm malware to backdoor VMware vSphere servers. The attacks primarily affect government and…
3 articles · Updated December 4, 2025 -
Chinese State Hackers Deploy BRICKSTORM Malware Against VMware Systems
Chinese state-sponsored hackers are utilizing a new malware known as BRICKSTORM, a stealthy Go-based backdoor, targeting VMware systems for long-term espionage in government and IT networks. Additionally, the threat…
2 articles · Updated December 6, 2025 -
Chinese Malware Targeting US Organizations: Warp Panda's Attack Campaign
The China-linked threat actor Warp Panda has been targeting US organizations in the legal, manufacturing, and technology sectors using advanced malware. The malware variants identified include BrickStorm, Junction, and…
2 articles · Updated December 5, 2025 -
WARP PANDA Cyber-Espionage Targets US Legal and Tech Sectors
CrowdStrike has reported on WARP PANDA, a China-linked cyber-espionage group targeting North American legal, technology, and manufacturing firms throughout 2025. The group specializes in covert operations within…
3 articles · Updated December 5, 2025
Recent Intelligence Reports
- The AI Arms Race Goes Covert: China Leads Cyber Espionage Against Tech Sector — Briefglance · June 9, 2026
- Verdantbamboo Just Another Brickstorm In The Firewall — www.volexity.com · June 5, 2026
- China’s VerdantBamboo Experimented With Three Re — Thecyberexpress · June 5, 2026
- Spyware suppliers exploit more zero — Computerweekly · March 5, 2026
- Critical VMware vCenter Server bug under attack — Theregister · January 23, 2026
- Patch or die: VMware vCenter Server bug fixed in 2024 under attack today — Theregister · January 23, 2026
- China blacklists VMware, Palo Alto Networks software over national security fears: report — Sdxcentral · January 15, 2026
- PRC spies Brickstormed their way into critical US networks — Theregister · December 5, 2025