Related Threat Clusters
-
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Google has issued an emergency update to address a high-severity zero-day vulnerability, CVE-2025-13223, in its Chrome browser. This flaw, linked to the V8 JavaScript engine, allows attackers to execute arbitrary code…
54 articles · Updated November 24, 2025 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Escalating Cyber Warfare Threats Amid Geopolitical Tensions
In recent months, cyber warfare has intensified due to rising geopolitical tensions, particularly involving North Korea, Iran, and Russia. North Korean hackers have infiltrated U.S. companies by embedding operatives as…
2 articles · Updated April 9, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
Kimsuky Expands AI Capabilities for Cyberattacks
The North Korean hacking group Kimsuky has developed local AI tools to enhance its cyberattack capabilities, as reported by Genians Security Center on August 10, 2026. The group is utilizing large language models (LLMs)…
49 articles · Updated August 10, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
Ripple Shares North Korean Threat Intelligence to Combat Evolving Cyber Attacks
On May 5, 2026, Ripple announced it will share internal threat intelligence regarding North Korean hackers with Crypto ISAC, aimed at enhancing security across the cryptocurrency industry. This initiative follows a…
19 articles · Updated May 5, 2026 -
Kelp DAO and Aave Resume Operations After $292 Million Exploit
On April 18, 2026, Kelp DAO suffered a significant cyberattack attributed to North Korea's Lazarus Group, resulting in the theft of approximately 116,500 rsETH tokens worth $292 million. The attackers exploited a…
9 articles · Updated May 14, 2026
Recent Intelligence Reports
- Communication Channel Identity Risks — unit42.paloaltonetworks.com · August 31, 2026
- Microsoft Security Chief Taesoo Kim: "AI Advancement Shifts the Game in Favor of Defense ... — Finance.Biggo · August 30, 2026
- Kim Taesu says AI tilts cyber defense to advantage, urges Korea to grow security industry — Biz.Chosun · August 29, 2026
- Data Breach — www.techtarget.com · August 27, 2026
- Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense — Recordedfuture · August 25, 2026
- Ukraine war live: Putin passes law to seize warehouses if they face Kyiv drone attack — Independent · August 25, 2026
- Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense — Recordedfuture · August 25, 2026
- abcnews.com.np — abcnews.com.np · August 23, 2026