Related Threat Clusters
-
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
Critical Vulnerabilities in TP-Link Archer Routers Expose Users to Attacks
TP-Link has patched multiple critical vulnerabilities in its Archer NX router series, specifically affecting models NX200, NX210, NX500, and NX600. The most severe flaw, CVE-2025-15517, allows unauthenticated attackers…
11 articles · Updated March 25, 2026 -
FCC Bans Foreign-Made Consumer Routers Citing National Security Risks
On March 24, 2026, the Federal Communications Commission (FCC) banned the import of all new foreign-made consumer routers, citing unacceptable risks to U.S. national security. This decision affects routers produced…
65 articles · Updated March 24, 2026 -
TP-Link Smart Cameras Vulnerabilities Expose Users to Data Theft
TP-Link has issued security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras. The vulnerabilities, CVE-2026-9770 and CVE-2026-13230, were published on 2026-07-15 and allow attackers on the…
2 articles · Updated July 17, 2026 -
Identity-Based Attacks Target Authentication Systems and Credentials
Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…
62 articles · Updated May 29, 2026 -
Critical Vulnerabilities Found in TP-Link Tapo C520WS Cameras
Multiple high-severity vulnerabilities have been identified in TP-Link's Tapo C520WS smart security cameras. These vulnerabilities could allow adjacent attackers to trigger Denial-of-Service (DoS) conditions, crash the…
2 articles · Updated April 3, 2026
Recent Intelligence Reports
- TP — Cybersecuritynews · August 27, 2026
- TP — Gbhackers · August 27, 2026
- 130626 — support.omadanetworks.com · August 5, 2026
- TP — Hkcert · August 5, 2026
- FrostArmada — www.lumen.com · August 3, 2026
- TP — Gbhackers · July 17, 2026
- US and allies warn of Russian critical infrastructure attacks — Bleepingcomputer · July 13, 2026
- TP — Cybersecuritynews · June 2, 2026