Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026 -
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware
A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…
7 articles · Updated July 4, 2026 -
Dark Caracal Unveils GoCaracal Malware for Cyber Espionage
The Lebanon-linked Dark Caracal threat group has introduced a new malware framework named GoCaracal, enhancing its cyberespionage capabilities. Discovered by Arctic Wolf during an intrusion investigation in Venezuela,…
13 articles · Updated August 26, 2026 -
JDY Botnet Grows to 1,500 Devices for Rapid Vulnerability Mapping
The JDY botnet, linked to Chinese state-sponsored actors, has expanded to over 1,500 compromised small office and IoT devices, primarily in the U.S. and Brazil. This botnet scans for newly disclosed vulnerabilities…
12 articles · Updated June 10, 2026 -
Supply Chain Attack Compromises DAEMON Tools with Malicious Backdoor
A supply chain attack has compromised the DAEMON Tools software installers, which began on April 8, 2026. Kaspersky identified that these trojanized installers, signed with legitimate digital certificates, have affected…
26 articles · Updated May 5, 2026 -
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks
In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to…
10 articles · Updated August 20, 2026 -
US Designates Brazil's PCC and CV as Terrorist Organizations, Heightening Compliance Risks
On May 28, 2026, the US Department of State designated Brazil's PCC and CV as Specially Designated Global Terrorists (SDGTs) and announced their Foreign Terrorist Organization (FTO) status effective June 5, 2026. This…
2 articles · Updated June 18, 2026 -
Russian Hackers Cause $2.5 Billion Cyberattack on Jaguar Land Rover
In August 2025, a ransomware attack attributed to Russian hackers severely disrupted Jaguar Land Rover's operations, forcing a five-week production halt and costing the UK economy approximately $2.5 billion. The attack…
16 articles · Updated June 26, 2026
Recent Intelligence Reports
- Dark Caracal Adds New Malware to Cyber Espionage Arsenal — Darkreading · August 26, 2026
- Spyware scam targeting Indeed users – infected interview apps — Heise.De · August 26, 2026
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes — Bleepingcomputer · August 25, 2026
- Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense — Recordedfuture · August 25, 2026
- Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense — Recordedfuture · August 25, 2026
- ANPD Monitors 22 Social Networks and AI Apps for Deepfakes and Virtual Crimes — Ground.News · August 22, 2026
- Disrupting A Grandoreiro Malware Operation — www.interpol.int · August 20, 2026
- 'Grandoreiro' Malware Resurfaces With Mexico Campaign — Darkreading · August 20, 2026