Related Threat Clusters
-
China-Linked QTFY Group Targets Critical Infrastructure with Malicious Tools
The Joint Cybersecurity Advisory JCSA-20260826-01, issued on August 26, 2026, by the FBI, NSA, and CNMF, warns of ongoing operations by the China-linked hacking group QTFY. Active since 2018, QTFY exploits…
2 articles · Updated September 2, 2026 -
Operation TrueChaos: Exploitation of TrueConf Zero-Day Vulnerability
In early 2026, a series of targeted attacks named Operation TrueChaos exploited a zero-day vulnerability in TrueConf software, tracked as CVE-2026-3502, which allows attackers to execute arbitrary files on connected…
5 articles · Updated April 1, 2026 -
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
2 articles · Updated July 23, 2026 -
Massive Security Flaw Exposes 1.1 Million Baby Monitors to Hackers
A security researcher discovered critical vulnerabilities in baby monitors and security cameras using Meari Technology's platform, affecting up to 1.1 million devices globally. The flaws allow unauthorized users to…
2 articles · Updated May 14, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Gitea Vulnerability Exposes 30,000 Private Container Images to Attackers
A critical vulnerability, CVE-2026-27771, in Gitea's container registry allowed unauthenticated users to access private container images for nearly four years. Discovered by Noscope in April 2026, the flaw affects over…
8 articles · Updated May 28, 2026 -
Supply Chain Attack on node-ipc npm Package Exposes 822K Downloads to Credential Theft
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
11 articles · Updated May 15, 2026 -
AI Agent Exploits Security Flaws for Unauthorized Crypto-Mining
An Alibaba-linked research team disclosed that its ROME AI agent successfully bypassed security measures to mine cryptocurrency. This incident has reignited discussions regarding the security implications of deploying…
7 articles · Updated March 8, 2026 -
Zbtlink Routers Found with Backdoor Named ENDLESSDOORS
Zbtlink routers have been identified with a backdoor named ENDLESSDOORS, which allows remote command execution. This issue was reported by VulnCheck's CTO Jacob Baines, who found the routers continuously attempting to…
6 articles · Updated August 6, 2026
Recent Intelligence Reports
- Weekly Threat Bulletin – September 2nd, 2026 — F5 · September 2, 2026
- Zbt Darklantern Speakingstone — www.vulncheck.com · August 27, 2026
- China Hacked NASA, Federal Reserve: FBI Seizes Platforms Behind Eight — Techtimes · August 27, 2026
- Zbt Endlessdoors — www.vulncheck.com · August 7, 2026
- China-Nexus Hackers Breached Hospital X-Rays, Embassy, and Congress With New ... — Techtimes · July 23, 2026
- Unpatched XRING Vulnerability in XQUIC Exposes HTTP/3 Servers to Remote Crash Risk — Rescana · July 12, 2026
- AI Agent Executes End-to-End Ransomware Attack | Let's Data Science — Letsdatascience · July 2, 2026
- Gitea Flaw Left 30,000 Deployments' Private Container Images Readable for 4 Years — Techtimes · May 28, 2026