Related Threat Clusters
-
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Critical Check Point VPN Vulnerability Exploited by Ransomware Gang
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The…
46 articles · Updated June 8, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
Critical CVE-2026-11624 Vulnerability in Model Context Protocol
CVE-2026-11624, published on June 13, 2026, exposes the Model Context Protocol to DNS rebinding attacks due to improper validation of the 'Origin' header. This vulnerability allows unauthenticated attackers to bypass…
3 articles · Updated June 14, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Major Cyber Breach: Russian Hackers Compromise UK Government Logins
Russian hackers have infiltrated the email accounts of UK government officials and Foreign Office staff in a significant cyber breach, dubbed 'FortiBleed.' The attack exploited vulnerabilities in over 80,000 Fortinet…
28 articles · Updated July 5, 2026 -
Two Former Chinese Military Personnel Arrested in South Korea for Espionage
Two ex-Chinese military servicemembers were arrested in South Korea on espionage charges. They are accused of intercepting communications between fighter jets and ground control, and collecting sensitive information…
11 articles · Updated August 11, 2026
Recent Intelligence Reports
- 5 Common Browser Attacks And How To Prevent Them — www.techtarget.com · August 31, 2026
- Zbt Darklantern Speakingstone — www.vulncheck.com · August 27, 2026
- TP — Gbhackers · August 27, 2026
- New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments — Gbhackers · August 20, 2026
- Expired credit cards revived by researchers to make unauthorized payments — Theregister · August 18, 2026
- SUSE Linux Micro 6.2 Important open-iscsi Update Vulnern 2026-23157 — Linuxsecurity · August 18, 2026
- Researchers Use A Physical Device To Take Over Electronics In A Boeing 737 — today.ucsd.edu · August 16, 2026
- openSUSE open-iscsi Important Local Access Security Update 2026-21580 — Linuxsecurity · August 16, 2026