Related Threat Clusters
-
China-linked Cyber Group Expands Targeting to Southeastern Europe
A sophisticated threat actor known as UAT-7290, tracked by Cisco Talos, has expanded its operations to target telecommunications providers in Southeastern Europe. This group, which has been active since at least 2022,…
1 article · Updated January 8, 2026 -
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
Telecommunications providers in South Asia and Southeastern Europe have been targeted by the China-linked threat operation UAT-7290 in a series of cyberespionage attacks. The intrusions involved extensive reconnaissance…
1 article · Updated January 9, 2026 -
Cisco Fixes Critical AsyncOS Vulnerability Under Attack
Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…
11 articles · Updated January 15, 2026 -
CISA Directs Agencies to Address Gogs RCE Vulnerability Exploited in Zero-Day Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that government agencies secure their systems against a critical Gogs vulnerability, tracked as CVE-2025-8110. This remote code execution…
6 articles · Updated January 12, 2026 -
Cisco Secure Email Gateway Targeted by Advanced Persistent Threat
Cisco Talos reported that the Secure Email Gateway is under attack due to a zero-day vulnerability. The campaign is attributed to UAT-9686, an advanced persistent threat actor believed to have connections to China.…
2 articles · Updated January 16, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Google has issued an emergency update to address a high-severity zero-day vulnerability, CVE-2025-13223, in its Chrome browser. This flaw, linked to the V8 JavaScript engine, allows attackers to execute arbitrary code…
54 articles · Updated November 24, 2025 -
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
The China-aligned threat group SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange and IIS server vulnerabilities, specifically the ProxyLogon vulnerability chain, to conduct cyberespionage. This group has…
2 articles · Updated May 5, 2026 -
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
2 articles · Updated June 17, 2026 -
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…
9 articles · Updated June 13, 2026
Recent Intelligence Reports
- ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool — Securityaffairs.Co · August 31, 2026
- Governor Abbott, National Cyber Director Launch Project Watershed 250 To Defend Texas ... — Gov.Texas · August 31, 2026
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — Thehackernews · August 31, 2026
- China — Securityaffairs.Co · August 31, 2026
- ValleyRAT masquerading as adware — Securelist · August 31, 2026
- Seqrite Uncovers China-Linked Cyber Espionage Campaign Targeting India's Tax Ecosystem — Itvoice.In · August 31, 2026
- As the rivalry between the United States and China for dominance in Artificial Intelligence (AI) int.. — Mk.Co.Kr · August 30, 2026
- US Officials Revise China Hacking Claims, Say Agencies Were Targeted — Freepressjournal.In · August 29, 2026