Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular command-and-control (C2) framework built on a .NET foundation, utilizing various compilati...
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering malware including SHARDLOADER, MINIRECON, and ZOHOMURK. These campaigns employed DLL...
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by Compromise and Phishing to execute malicious code, often without user interaction. Notabl...