Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Critical Memory Overread Vulnerability in Citrix NetScaler Exploited
Citrix NetScaler ADC and Gateway are affected by CVE-2026-3055, a critical vulnerability due to insufficient input validation during SAML authentication, leading to memory overread. Exploitation attempts have surged,…
2 articles · Updated May 29, 2026 -
GCHQ Warns of Escalating Russian Cyber Threats to UK Infrastructure
In a recent speech, Anne Keast-Butler, head of GCHQ, warned that Russia is engaging in daily hybrid warfare against the UK, targeting critical infrastructure, democratic processes, supply chains, and public trust. She…
75 articles · Updated May 26, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
17 Iranians Charged in Cyber Theft Campaign Targeting U.S. Institutions
The U.S. Department of Justice has unsealed a superseding indictment against 17 Iranian nationals linked to the Mabna Institute, alleging a coordinated cyber theft campaign on behalf of Iran's Islamic Revolutionary…
55 articles · Updated August 18, 2026
Recent Intelligence Reports
- Terror handlers turn to porn sites to evade surveillance in J-K — M.Rediff · August 30, 2026
- Moscow tests Europe's borders ahead of key elections — En.Vijesti.Me · August 30, 2026
- RSA Conference Panel Tackles Huawei Security Risks — www.techtarget.com · August 27, 2026
- Tortoiseshell: New Toolset and Operational Infrastructure Exposed | Group — Group-Ib · August 26, 2026
- Interpol's Jackal IV Disrupts West African Crime Infrastructure — Darkreading · August 26, 2026
- Interpol arrest suspected black axe scammers, identify hundreds for cyber crimes across West Africa — Bbc · August 26, 2026
- Ukraine war live: Putin passes law to seize warehouses if they face Kyiv drone attack — Independent · August 25, 2026
- Can an underwater attack disrupt the EU? Take our poll — Aol · August 24, 2026