Related Threat Clusters
-
Microsoft Office 0-day Vulnerability CVE-2026-21509 Exploited; Emergency Fix Released
Microsoft Office 2016 to 2024 and Office 365 apps are affected by a zero-day vulnerability (CVE-2026-21509) that is currently being exploited in attacks. Microsoft has released emergency security updates to address this…
7 articles · Updated January 27, 2026 -
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as…
2 articles · Updated August 12, 2026 -
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
The Russian Foreign Intelligence Service (SVR) has been exploiting multiple vulnerabilities, including the SolarWinds breach, to compromise U.S. and allied networks. The SolarWinds attack, which began in September 2019,…
2 articles · Updated May 24, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
EU Officials Targeted by State-Sponsored Cyberattacks on Messaging Apps
For the first time, the EU has officially acknowledged that state actors are attempting to hack into the messaging accounts of high-ranking officials using spear-phishing techniques. The attacks primarily target Signal…
5 articles · Updated August 26, 2026 -
Global Takedown of Kratos Phishing-as-a-Service Infrastructure
On July 20, 2026, German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its developer in Indonesia. The operation neutralized over 200 servers and disrupted approximately…
17 articles · Updated July 21, 2026 -
Iran-Linked Handala Group Launches Cyberattack on Stryker Medical Technology
On March 11, 2026, the Iranian-linked hacking group Handala executed a significant cyberattack on Stryker, a major U.S. medical technology company, causing a global disruption across its Microsoft environment. The…
276 articles · Updated March 11, 2026
Recent Intelligence Reports
- RevStealer malware spread through fake Claude Opus 5 download | news — Scworld · September 1, 2026
- New RevStealer malware spreads as fake Claude Opus 5 desktop app — Cyberinsider · August 31, 2026
- Data Breach — www.techtarget.com · August 27, 2026
- State actors tried to hack EU officials' messaging apps, cybersecurity body warns — Uk.News.Yahoo · August 26, 2026
- Calix GigaSpire Flaw Lets Strangers Control Your Home Firewall: No Patch — Techtimes · August 25, 2026
- Microsoft's CVSS 10.0 Entra ID RCE Briefly Tagged 'Exploited' Before Correction — Forkast.News · August 22, 2026
- Microsoft patches flaw in Entra ID identity software | news — Scworld · August 21, 2026
- Microsoft confirms maximum severity flaw in Entra ID targeted for exploitation — Cybersecuritydive · August 21, 2026