Related Threat Clusters
-
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware
The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two…
3 articles · Updated September 1, 2026 -
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
2 articles · Updated July 1, 2026 -
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…
16 articles · Updated March 26, 2026 -
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
54 articles · Updated July 2, 2026 -
Drone Strikes Disrupt AWS Infrastructure, Trigger Cybersecurity Crisis for MSPs
On April 6, 2026, drone strikes targeted AWS infrastructure in the UAE, prompting Managed Service Providers (MSPs) to activate disaster recovery plans. The strikes have led to significant disruptions in cloud services,…
2 articles · Updated April 6, 2026 -
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
AWS Warns of Data Exfiltration Risks from Outbound Traffic Blind Spots
AWS has highlighted the risks associated with unmonitored outbound traffic in cloud environments, particularly in light of the CVE-2025-55182 vulnerability affecting React Server Components. This vulnerability allows…
4 articles · Updated June 23, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026
Recent Intelligence Reports
- WAF logging examples — docs.aws.amazon.com · September 1, 2026
- Iranian Hackers Pose as Recruiters to Deliver Cross — Thehackernews · September 1, 2026
- Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations — Gbhackers · September 1, 2026
- Hackers Target AWS Root Accounts at 150+ Organizations in Password — Cybersecuritynews · September 1, 2026
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Cybersecurity-Insiders · August 31, 2026
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Markets.Businessinsider · August 31, 2026
- Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI ... — Cio · August 31, 2026
- Extend your data perimeter to the AWS Management Console with Private Access — Aws.Amazon · August 28, 2026