Related Threat Clusters
-
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously…
105 articles · Updated June 17, 2026 -
IBM Whistleblower Alleges Cover-Up of Foreign Cyber Breaches
A former IBM cybersecurity executive, William Barlow, has filed a lawsuit alleging that IBM covered up multiple data breaches by foreign state actors, particularly Chinese hackers, from 2013 to 2016. The breaches…
13 articles · Updated June 5, 2026 -
T-Mobile Thwarts Salt Typhoon Hackers by Isolating Compromised System
In 2024, T-Mobile's cybersecurity team successfully contained a cyber intrusion by the state-sponsored group 'Salt Typhoon' by physically isolating a compromised router at a data center in Bellevue, Washington. This…
3 articles · Updated August 20, 2026 -
Google Sues Chinese Cybercrime Network for AI-Powered Phishing Operations
Google has filed a lawsuit against the 'Outsider Enterprise', a China-based cybercrime network, for allegedly using AI tools, including its Gemini platform, to conduct large-scale phishing operations. The operation has…
57 articles · Updated June 12, 2026 -
New Pink Extortion Group Targets Microsoft 365 via Voice Phishing
The newly identified Pink extortion group has emerged, utilizing voice phishing (vishing) tactics to gain access to Microsoft 365 accounts. Researchers from Unit 42 have tracked the group under cluster designation…
9 articles · Updated June 4, 2026 -
FBI Networks Targeted in Suspicious Cybersecurity Incident
The FBI has confirmed that its networks were targeted in a suspected cybersecurity incident, specifically affecting a sensitive system used for managing wiretaps and intelligence surveillance warrants. The bureau is…
24 articles · Updated March 5, 2026 -
Scattered Spider Reclassified as Decentralized Cybercrime Collective
Scattered Spider, a cybercrime entity linked to various high-profile attacks since 2022, has been reclassified as a decentralized collective rather than a unified group. Group-IB's analysis indicates that it consists of…
2 articles · Updated July 7, 2026 -
Cybersecurity Threats Surge in Professional Sports Amid AI Adoption
A recent report by Darktrace reveals that 84% of professional sports organizations experienced cyber incidents in the past year, with 57% facing multiple attacks. The rise of AI is amplifying these threats, as attackers…
9 articles · Updated June 11, 2026 -
RubyGems Implements Dependency Cooldowns to Combat Supply Chain Attacks
RubyGems has introduced dependency cooldowns in Bundler to mitigate supply chain attacks that exploit newly published packages. This feature delays the installation of packages until they have been available for a…
2 articles · Updated June 8, 2026
Recent Intelligence Reports
- T — Feeds.Feedburner · August 20, 2026
- Snowflake extortionist admits 165-victim cloud crime spree — Theregister · August 6, 2026
- Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign — Infosecurity-Magazine · August 6, 2026
- Canadian pleads guilty to Snowflake cloud data — Bleepingcomputer · August 5, 2026
- Snowflake hacker pleads guilty, faces up to 32 years in prison — Cyberscoop · August 5, 2026
- Swiss train maker tells ransomware crooks to get off at the next stop — Theregister · July 23, 2026
- Connecting Scattered Spider — www.group-ib.com · July 8, 2026
- Xfinity customers can claim up to $10K in Comcast's $117.5 million data breach payout ... — Cnbc · July 6, 2026