Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…
9 articles · Updated June 13, 2026 -
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
The Russian Foreign Intelligence Service (SVR) has been exploiting multiple vulnerabilities, including the SolarWinds breach, to compromise U.S. and allied networks. The SolarWinds attack, which began in September 2019,…
2 articles · Updated May 24, 2026 -
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
CISA has added critical vulnerabilities in IBM Langflow, Apache Tomcat, and N-able N-central to its Known Exploited Vulnerabilities catalog, with a deadline for federal agencies to patch by August 7, 2026. The Langflow…
2 articles · Updated August 7, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
Iranian Hackers Target US Aviation with New Malware and SEO Poisoning
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
6 articles · Updated May 26, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted…
324 articles · Updated July 27, 2026
Recent Intelligence Reports
- Hackers Target Claude Accounts With Malware That Steals Login Sessions — Pymnts · August 31, 2026
- How To Mitigate Wiper Malware — www.techtarget.com · August 28, 2026
- What Are Social Engineering Attacks — www.techtarget.com · August 27, 2026
- The Infrastructure Quartermaster Inside A China Nexus State Enablement Model — www.lumen.com · August 27, 2026
- Dark Caracal group enhances cyberespionage with new GoCaracal malware — Scworld · August 27, 2026
- Warning: Two particularly dangerous malware strains. — Vietnam.Vn · August 27, 2026
- Warning: Some malware strains are particularly dangerous. — Vietnam.Vn · August 27, 2026
- Spyware scam targeting Indeed users – infected interview apps — Heise.De · August 26, 2026