Related Threat Clusters
-
CISA Directs Agencies to Address Gogs RCE Vulnerability Exploited in Zero-Day Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that government agencies secure their systems against a critical Gogs vulnerability, tracked as CVE-2025-8110. This remote code execution…
6 articles · Updated January 12, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Critical Memory Overread Vulnerability in Citrix NetScaler Exploited
Citrix NetScaler ADC and Gateway are affected by CVE-2026-3055, a critical vulnerability due to insufficient input validation during SAML authentication, leading to memory overread. Exploitation attempts have surged,…
2 articles · Updated May 29, 2026 -
GCHQ Warns of Escalating Russian Cyber Threats to UK Infrastructure
In a recent speech, Anne Keast-Butler, head of GCHQ, warned that Russia is engaging in daily hybrid warfare against the UK, targeting critical infrastructure, democratic processes, supply chains, and public trust. She…
75 articles · Updated May 26, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026
Recent Intelligence Reports
- Moscow tests Europe's borders ahead of key elections — En.Vijesti.Me · August 30, 2026
- Berlin being 'blackmailed' after cyberattack — www.thelocal.de · August 29, 2026
- Baltic Nations Form Task Force Against Hybrid Threats — Kyivpost · August 29, 2026
- Germany news: Baltic summit plans hybrid-threat task force — Dw · August 29, 2026
- Ransomware Group Says It Stole Berlin Data, Offers It for Auction — Usnews · August 29, 2026
- Hacktivism Evolves from Digital Defacer into Asymmetric Warfare Threat Actor — Asisonline · August 28, 2026
- Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations — Infosecurity-Magazine · August 28, 2026
- Reuters: Russian — Meduza · August 27, 2026