XHunt is an Advanced Persistent Threat (APT) group observed in 2025 that targets Windows infrastructure by exploiting internet-facing Microsoft Exchange and IIS Web Server deployments to deploy bespoke backdoors.
XHunt is an Advanced Persistent Threat (APT) group observed in 2025 that targets Windows infrastructure by exploiting internet-facing Microsoft Exchange and IIS Web Server deployments to deploy bespoke backdoors. Their focus on Exchange and IIS and deployment of custom backdoors indicates a persistent capability to gain and maintain access within enterprise networks.
Threat actors are actively exploiting critical authentication bypass vulnerabilities in Fortinet's FortiGate appliances, specifically CVE-2025-59718 and CVE-2025-59719. These vulnerabilities allow unauthenticated single…
The xHunt APT group is conducting targeted cyber-espionage campaigns against organizations in Kuwait, specifically focusing on the government, shipping, and transportation sectors. They exploit vulnerabilities in…
In December 2025, Japanese organizations are facing attacks exploiting the React2Shell vulnerability (CVE-2025-55182) in React/.js applications. Initially used for cryptocurrency mining, the ZnDoor malware has evolved…