Related Threat Clusters
-
Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
8 articles · Updated November 12, 2025 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Massive Data Breach at Change Healthcare Affects 190 Million Americans
In February 2024, Change Healthcare suffered a ransomware attack attributed to the ALPHV group, impacting approximately 190 million individuals, making it the largest medical data breach in U.S. history. The attack…
3 articles · Updated June 18, 2026 -
Critical Memory Overread Vulnerability in Citrix NetScaler Exploited
Citrix NetScaler ADC and Gateway are affected by CVE-2026-3055, a critical vulnerability due to insufficient input validation during SAML authentication, leading to memory overread. Exploitation attempts have surged,…
2 articles · Updated May 29, 2026 -
State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits
Recent reports indicate a significant rise in the exploitation of edge devices, such as VPN gateways and firewalls, by state-sponsored actors. These devices have become the primary attack vector for espionage…
3 articles · Updated July 22, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Citrix NetScaler Vulnerabilities Enable DoS and Memory Disclosure Attacks
Citrix disclosed six high-severity vulnerabilities in NetScaler ADC and Gateway appliances, including CVE-2026-8451, which allows unauthenticated memory disclosure when configured as a SAML identity provider. Other…
85 articles · Updated July 1, 2026 -
Critical Vulnerabilities in Citrix NetScaler ADC and Gateway Require Immediate Patching
Cloud Software Group has identified and patched two critical vulnerabilities in Citrix NetScaler ADC and Gateway products. The vulnerabilities, tracked as CVE-2026-3055, allow unauthenticated remote attackers to exploit…
30 articles · Updated March 23, 2026 -
Critical Ivanti EPMM Vulnerabilities Under Active Exploitation
Two critical vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM), CVE-2026-1281 and CVE-2026-1340, have been actively exploited in the wild, allowing unauthenticated remote code execution (RCE) with a CVSS score…
64 articles · Updated January 29, 2026 -
Critical Zoom Vulnerabilities Enable Remote Code Execution via AI-Driven Exploits
A critical zero-click vulnerability in Zoom's annotation feature, dubbed 'Zoomsday,' allows attackers to remotely execute code on participants' devices during meetings without user interaction. Discovered by A Security…
46 articles · Updated August 11, 2026
Recent Intelligence Reports
- Targeted Campaign Us Law Firms — cloud.google.com · August 16, 2026
- Zoom zero — Csoonline · August 11, 2026
- Defending Your Network Edge Against The Next Zero Day Exploit — www.sygnia.co · July 23, 2026
- Craneware confirms data breach after cyberattack — Computing · July 20, 2026
- A Huge Trove Of Leaked Black Basta Chat Logs Expose The Ransomware Gangs Key Members And Victims — techcrunch.com · July 5, 2026
- CC-4805 — Digital.Nhs.Uk · July 1, 2026
- One Medical: After cyberattack on Amazon's health service, data leak threatened — Heise.De · June 21, 2026
- 193 million — www.nixonpeabody.com · June 18, 2026