Related Threat Clusters
-
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
The Russian Foreign Intelligence Service (SVR) has been exploiting multiple vulnerabilities, including the SolarWinds breach, to compromise U.S. and allied networks. The SolarWinds attack, which began in September 2019,…
2 articles · Updated May 24, 2026 -
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and…
30 articles · Updated August 14, 2026 -
SUNBURST Backdoor Exploits SolarWinds Supply Chain Vulnerability
The SUNBURST backdoor, discovered by FireEye, exploits trojanized updates to SolarWinds Orion software, affecting numerous public and private organizations globally. The attack vector involves a malicious DLL,…
2 articles · Updated June 16, 2026 -
Chinese State Actor Compromises Notepad++ Update Infrastructure
Between June and December 2025, the Chinese state group Lotus Blossom compromised the shared hosting provider for Notepad++, redirecting update traffic to deliver malicious installers to targeted users. The attackers…
2 articles · Updated March 19, 2026 -
Congressional Hearing on Microsoft’s Security Culture Post-SolarWinds Breach
During a House Homeland Security Committee hearing on April 28, 2026, Microsoft faced scrutiny over its handling of security vulnerabilities that contributed to the SolarWinds cyberattack. A ProPublica investigation…
6 articles · Updated April 28, 2026 -
Critical MOVEit Vulnerabilities Expose Organizations to Data Breaches
Progress Software has issued urgent advisories regarding critical vulnerabilities in its MOVEit Automation platform, specifically CVE-2026-4670 and CVE-2026-5174. These vulnerabilities allow attackers to bypass…
11 articles · Updated May 4, 2026 -
Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
38 articles · Updated June 10, 2026 -
Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files
A critical vulnerability in FFmpeg's MagicYUV decoder, tracked as CVE-2026-8461, allows attackers to exploit heap out-of-bounds writes to crash systems or execute remote code. Discovered by JFrog, the flaw affects a…
9 articles · Updated June 23, 2026 -
Active Exploitation of SolarWinds Serv-U Flaw CVE-2026-28318
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of a high-severity vulnerability in SolarWinds Serv-U, tracked as CVE-2026-28318. This flaw allows…
13 articles · Updated June 5, 2026 -
Critical Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)
The SolarWinds Orion API is vulnerable to an authentication bypass, allowing remote attackers to execute API commands without authentication. This vulnerability, identified as CVE-2020-10148, can be exploited by…
3 articles · Updated June 17, 2026
Recent Intelligence Reports
- Data Breach — www.techtarget.com · August 27, 2026
- Unpacking The Moveit Breach Statistics And Analysis — www.emsisoft.com · August 18, 2026
- Shell and Philips Confirm Investigation as Cl0p Claimed Data Theft — Technadu · August 14, 2026
- Zero-Knowledge Proofs — Fdd · August 4, 2026
- ISACA’s latest research — www.isaca.org · July 28, 2026
- Navigating Cyber Supply Chain Disputes: Litigation Risk for Customers and IT Suppliers — Freshfields · July 23, 2026
- Hole in widely — Csoonline · June 24, 2026
- CVE-2020-10148 — kb.cert.org · June 17, 2026