Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
MonikerLink RCE Vulnerability in Outlook Exploited with PoC Release
The MonikerLink vulnerability in Microsoft Outlook allows for remote code execution via malicious hyperlinks in emails. Discovered by Check Point Research, a proof-of-concept exploit has been released, potentially…
2 articles · Updated December 1, 2025 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
FBI Seizes Iranian Hacktivist Group Websites After Stryker Cyberattack
The FBI has seized two websites linked to the Iranian hacktivist group Handala following their cyberattack on Stryker Corporation, a U.S. medical technology firm. The attack, which occurred on March 11, 2026, involved…
21 articles · Updated March 19, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
Harvester APT Group Unveils New GoGra Linux Backdoor Using Microsoft Graph API
The Harvester APT group has launched a Linux variant of its GoGra backdoor, utilizing the Microsoft Graph API and Outlook mailboxes for covert command-and-control operations. This malware is designed to evade…
13 articles · Updated April 22, 2026
Recent Intelligence Reports
- AI can be made to read an email much differently than you do — Csoonline · August 27, 2026
- Hidden Prompts Trick AI Into False Email Summaries — Darkreading · August 25, 2026
- Trend Micro's TrendAI — www.trendmicro.com · August 15, 2026
- Data analyst sent to prison for stealing data, extorting employer — Bleepingcomputer · August 14, 2026
- ZDI August 2026 analysis — www.zerodayinitiative.com · August 13, 2026
- Microsoft wants you to ditch SMS passwords as AI makes phishing harder to stop — Digitaltrends · August 13, 2026
- Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely — Gbhackers · August 12, 2026
- CSS attacks still break webmail defenses and steal passwords, tokens — Feeds.4Sysops · August 9, 2026