Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Chinese State Actor Compromises Notepad++ Update Infrastructure
Between June and December 2025, the Chinese state group Lotus Blossom compromised the shared hosting provider for Notepad++, redirecting update traffic to deliver malicious installers to targeted users. The attackers…
2 articles · Updated March 19, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
Armored Likho Expands Cyber-Espionage with New Rust Toolkit
In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and…
2 articles · Updated August 13, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Operation ASTERIX: AI-Driven Crypto Fraud Campaign Exposed
Operation ASTERIX is a sophisticated cryptocurrency fraud campaign that utilized vishing, phishing, and fake wallet applications to steal recovery phrases from victims. Rapid7 researchers discovered an exposed server…
12 articles · Updated August 18, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026 -
Chrome Vulnerabilities Allow Arbitrary Code Execution and System Crashes
Google has released a critical security update for Chrome, addressing two high-severity vulnerabilities that could allow arbitrary code execution and denial-of-service attacks. Users on Windows, macOS, and Linux are…
500 articles · Updated February 4, 2026
Recent Intelligence Reports
- Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline — Rapid7 · August 17, 2026
- Dead Drop Resolver — attack.mitre.org · August 14, 2026
- T1189 — attack.mitre.org · August 7, 2026
- T1620 — attack.mitre.org · July 23, 2026
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- Hacker hijacks Axios open-source project, used by millions, to push malware — Techcrunch · March 31, 2026
- Defending Supply Chain Software Pipelines Against Nation — Mbtmag · March 19, 2026
- Defending Supply Chain Software Pipelines Against Nation — Mbtmag · March 19, 2026