Related Threat Clusters
-
CISA Issues Urgent Warning on Actively Exploited LiteSpeed cPanel Plugin Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin, which allows attackers with FTP or web…
5 articles · Updated June 16, 2026 -
North Korean PurpleDelta Network Exploits Remote Hiring for Fraudulent Employment
Insikt Group has identified PurpleDelta, a North Korean IT worker network, employing over 22 fabricated personas to apply for jobs at more than 1,100 companies, likely securing positions at ten or more organizations.…
3 articles · Updated August 19, 2026 -
cPanel and WHM Critical Auth Bypass Vulnerability Patched
A critical authentication vulnerability affecting all supported versions of cPanel and WHM was disclosed on April 28, 2026. This flaw allows attackers to gain unauthorized access to the control panel, posing significant…
69 articles · Updated April 29, 2026 -
Crypto Trader Arrested for Laundering Hacking Proceeds in Major Cybercrime Case
Srikrishna, a notorious hacker, continued his criminal activities despite multiple FIRs since 2017. He collaborated with crypto trader Robin Khandelwal to launder proceeds from hacking operations, including stealing…
2 articles · Updated June 5, 2026 -
Scammers Exploit Microsoft Email System for Phishing Attacks
Cybercriminals have discovered a method to exploit Microsoft's internal email system, specifically the [email protected] address, to send phishing emails that appear legitimate. This vulnerability…
8 articles · Updated May 21, 2026 -
EasyDNS Suffers Social Engineering Attack, Briefly Hijacking eth.limo Domain
On April 17, 2026, the Ethereum Name Service gateway eth.limo was briefly hijacked due to a social engineering attack against its domain registrar, EasyDNS. An attacker impersonated a team member to initiate an account…
6 articles · Updated April 20, 2026 -
Operation DoppelBrand Targets Fortune 500 Firms for Credential Theft
Operation DoppelBrand is a phishing campaign identified by SOCRadar that targets major financial and technology firms, including Wells Fargo and USAA. The campaign, attributed to the financially motivated threat actor…
6 articles · Updated February 16, 2026 -
Over 10,000 Linux Servers Infected by SystemBC Botnet Variant
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting…
6 articles · Updated February 4, 2026
Recent Intelligence Reports
- PurpleDelta's Fraudulent Employment Operations — Recordedfuture · August 18, 2026
- CISA warns of another cPanel plugin flaw exploited in attacks — Bleepingcomputer · June 16, 2026
- ED arrests crypto trader Robin Khandelwal for laundering Sriki's hacking proceeds — Newindianexpress · June 5, 2026
- Scammers are using an internal Microsoft account to distribute spam — Zamin.Uz · May 21, 2026
- Namecheaps Email Hacked To Send Metamask Dhl Phishing Emails — www.bleepingcomputer.com · May 21, 2026
- Scammers are abusing an internal Microsoft account to send spam links — Techcrunch · May 21, 2026
- cPanel, WHM emergency update fixes critical auth bypass bug — Bleepingcomputer · April 29, 2026
- EasyDNS accepts responsibility for eth.limo hijack, its first social engineering breach in 28 years — Theblock.Co · April 19, 2026