Related Threat Clusters
-
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
CISA has added critical vulnerabilities in IBM Langflow, Apache Tomcat, and N-able N-central to its Known Exploited Vulnerabilities catalog, with a deadline for federal agencies to patch by August 7, 2026. The Langflow…
2 articles · Updated August 7, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
Russia's Bauman University: Training Ground for GRU Hackers and Spies
Bauman Moscow State Technical University is revealed to host a secret department training students for the GRU, Russia's military intelligence. Leaked documents show that over 2,000 students have been trained in…
15 articles · Updated May 7, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
HoneyMyte APT Upgrades CoolClient Backdoor with Kernel Driver for Enhanced Stealth
The HoneyMyte APT group has deployed an upgraded variant of the CoolClient backdoor in cyber-espionage campaigns targeting organizations in Myanmar, Mongolia, Pakistan, India, and Russia. This new variant introduces a…
10 articles · Updated August 14, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
135 articles · Updated May 22, 2026 -
Discovery of Fast16 Malware: Precursor to Stuxnet Targeting Iranian Nuclear Program
Researchers at SentinelOne have uncovered a malware framework named fast16, which dates back to 2005 and predates the infamous Stuxnet worm by five years. Fast16 is designed to subtly corrupt high-precision mathematical…
17 articles · Updated April 27, 2026 -
Wikimedia Foundation Targeted by Self-Propagating JavaScript Worm
The Wikimedia Foundation faced a security incident on March 5, 2026, when a self-propagating JavaScript worm began vandalizing pages and modifying user scripts across multiple wikis, including Wikipedia. The attack…
2 articles · Updated March 6, 2026
Recent Intelligence Reports
- How To Mitigate Wiper Malware — www.techtarget.com · August 28, 2026
- Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more — Grahamcluley · August 28, 2026
- Australian cops cuff alleged TeamPCP masterminds — Theregister · August 28, 2026
- Threat Landscape For Industrial Automation Systems Q2 2026 — ics-cert.kaspersky.com · August 27, 2026
- Threat landscape for industrial automation systems. Q2 2026 — Securelist · August 27, 2026
- BleepingComputer's EternalSilence coverage — www.bleepingcomputer.com · August 25, 2026
- Family Tree Dll Sideloading Cases May Be Related — www.sophos.com · August 15, 2026
- Exam 1: Network Security Fundamentals — Examlexapp.Work · August 8, 2026