Related Threat Clusters
-
AzCopy Utility Exploited in Ransomware Data Exfiltration Campaigns
Ransomware operators have begun misusing Microsoft's AzCopy, a legitimate command-line utility, to facilitate data exfiltration in ongoing attacks. This shift marks a significant change in tactics, as attackers leverage…
3 articles · Updated March 4, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
54 articles · Updated July 2, 2026 -
Slovakia Discovers Russian Backdoor in Traffic Speed Cameras
Slovakia's national security service NBU has issued a security alert regarding NERO R-ONE high-speed traffic cameras, which were found to contain a backdoor allowing access via SMS from hardcoded Russian phone numbers.…
4 articles · Updated August 19, 2026
Recent Intelligence Reports
- Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power — Gbhackers · August 27, 2026
- Cloud Security — securis360.com · August 26, 2026
- Securelist — securelist.com · August 26, 2026
- Digital Forensics and Incident Response, Senior Consultant DFIR — Jobs24 · August 26, 2026
- Microsoft Doubles Down on Security and AI Amid Stock Lull — Tipranks · August 22, 2026
- Microsoft Stock (NASDAQ:MSFT) Notches Up With 22 New Security Patches — Tipranks · August 22, 2026
- CVE-2026-69855 - Microsoft Copilot in Azure Information Disclosure Vulnerability Latest Vulnerabilities / 1d CVE ID : CVE-2026-69855 Published : Aug. 20, 2026, 10:18 p.m. 3 hours, 39 minutes ago Description : Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. Severity: 7.7 HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more... — cvefeed.io · August 22, 2026
- Microsoft patches flaw in Entra ID identity software | news — Scworld · August 21, 2026