Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
Gamaredon, a Russian state-backed APT group, is actively exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy malware against Ukrainian government and military targets. The attack begins with a spearphishing…
7 articles · Updated June 2, 2026 -
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026 -
Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
7 articles · Updated June 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Global Takedown of Kratos Phishing-as-a-Service Infrastructure
On July 20, 2026, German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its developer in Indonesia. The operation neutralized over 200 servers and disrupted approximately…
17 articles · Updated July 21, 2026 -
Kimsuky Group Leverages AI for Malware Targeting South Korean Government
The North Korean hacking group Kimsuky is utilizing generative AI to create malware aimed at South Korean government systems, as reported by Kaspersky on May 14, 2026. The malware, named HelloDoor, is a Rust-based…
5 articles · Updated May 14, 2026 -
Nuxt Security Vulnerabilities Require Immediate Attention
Nuxt has released security patches for versions 4.5.1 and 3.21.10, addressing multiple vulnerabilities including a high-severity server-side remote code execution (RCE) risk. The RCE vulnerability occurs when the Vue…
4 articles · Updated July 27, 2026 -
Global Surge in Government Access to Commercial Spyware Threatens Privacy
A recent report from UK intelligence reveals that over 100 governments now have access to commercial spyware tools, a significant increase from 80 in 2023. These tools, such as NSO Group's Pegasus and Paragon's…
48 articles · Updated April 22, 2026 -
Critical RCE and SQL Injection Vulnerabilities in WordPress Disclosed
On July 17, 2026, WordPress disclosed two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, affecting its core software. CVE-2026-63030 is a remote code execution (RCE) vulnerability in the REST API, while…
6 articles · Updated July 17, 2026
Recent Intelligence Reports
- Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel — Gbhackers · August 29, 2026
- Iauthflow V2 Phishing Google Passkeys — abnormal.ai · August 21, 2026
- CDN Tsunami: Critical HTTP/3 to HTTP/1.1 Protocol Translation Vulnerability Triggers Up to ... — Rescana · August 20, 2026
- Kriminal breaks out of Grok, Claude guardrails at $12.99 — Csoonline · August 20, 2026
- South Korea targets illegal filming sites with proposed lawful hacking — Koreajoongangdaily · August 20, 2026
- Unc6671 Targets Financial Services And Enterprise Cloud Environments — cloud.google.com · August 18, 2026
- The Outsider Part 2 Putting A Price On A Phishing Machine — tapetumlabs.com · August 14, 2026
- The Outsider Part 1 Pulling One Thread On A 1 9 Billion Phishing Machine — tapetumlabs.com · August 14, 2026