Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
Critical Linux Kernel Vulnerabilities in Ubuntu Affecting Multiple Systems
Recent advisories detail critical vulnerabilities in the Linux kernel affecting various Ubuntu versions. Ubuntu 20.04 and 18.04 are impacted by multiple security issues, including CVE-2026-31657 and CVE-2026-53045.…
4 articles · Updated August 20, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
Critical Linux Kernel Vulnerabilities Affect Multiple Ubuntu Releases
Recent security advisories have revealed multiple vulnerabilities in the Linux kernel affecting various Ubuntu releases, including 22.04 LTS, 20.04 LTS, 18.04 LTS, 25.10, and 24.04 LTS. These vulnerabilities are…
3 articles · Updated June 4, 2026 -
Multiple Linux Kernel Vulnerabilities Discovered Affecting Various Subsystems
A series of vulnerabilities in the Linux kernel have been identified, with significant risks posed to systems running affected versions. Notably, CVE-2025-27558 allows attackers to inject packets due to improper…
104 articles · Updated August 12, 2026 -
FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
135 articles · Updated May 22, 2026 -
Data Centers Targeted Amid Rising Cybersecurity Threats
Data centers have become high-value targets for cyber and physical attacks, highlighted by drone strikes on Amazon Web Services facilities in March 2026. These incidents, attributed to Iranian forces, resulted in…
7 articles · Updated April 30, 2026 -
Cordyceps Vulnerability Exposes Thousands of Code Repositories to Attacks
A newly identified supply chain vulnerability named 'Cordyceps' affects CI/CD workflows across major platforms, allowing unauthenticated attackers to exploit Git-based repositories. Novee's research flagged 654…
13 articles · Updated June 23, 2026
Recent Intelligence Reports
- New SynkLoader malware pushed in Microsoft Teams phishing campaign — Bleepingcomputer · August 21, 2026
- Ubuntu 20.04 18.04 Linux Kernel Critical Network Threats USN-8666 — Linuxsecurity · August 20, 2026
- Nova Scotia Power can't explain why hacked customer data was not deleted as planned — Halifax.Citynews.Ca · August 19, 2026
- Ubuntu Linux Kernel Security Advisory USN-8643 — Linuxsecurity · August 18, 2026
- Silent 'TwinLoot' Cyber Threat Operates Entirely From Microsoft's Cloud — Darkreading · August 18, 2026
- Azure credential theft puts 3.6 million enterprise directory records up for sale — Feeds.4Sysops · August 17, 2026
- TCS, HCL, Hexaware named in global Azure directory data leak linked to infostealers — Crnasia · August 17, 2026
- Crook hawks millions of records allegedly plundered from corporate Azure tenants — Theregister · August 17, 2026