Related Threat Clusters
-
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Onelogon Attack Exploits Microsoft Zerologon Patch Flaw
German researchers have discovered a new vulnerability named Onelogon, which exploits the previously patched Zerologon flaw (CVE-2020-1472) in Microsoft's Active Directory. The Onelogon attack can be executed using two…
2 articles · Updated August 12, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Managing Vulnerability Overload in Cybersecurity
In 2024, over 40,000 CVEs were published, creating a significant challenge for security teams managing vulnerabilities. Organizations often treat vulnerability data as a compliance task rather than a strategic asset,…
2 articles · Updated November 26, 2025 -
Data Breach Exposes Iranian Cybersecurity Academy's Student Information
The Ravin Academy, a training institution for Iranian state hackers, experienced a data breach that revealed the personal information of over 1,000 individuals associated with the academy. The leak was made public by…
2 articles · Updated October 30, 2025 -
Data Leak Exposes Iranian Cybersecurity Academy Trainees
The Ravin Academy, a training institution for Iranian state hackers, experienced a data breach that revealed the identities of over 1,000 individuals associated with the academy. The leak was publicized by…
2 articles · Updated October 30, 2025 -
Bactor Ransomware Identified in Cybersecurity Monitoring
CYFIRMA Research and Advisory Team has identified Bactor Ransomware while monitoring underground forums. This ransomware targets Windows systems and affects multiple industries and technologies. The findings are part of…
5 articles · Updated November 20, 2025 -
Emergence of New Ransomware Variants: Bactor, ChickenKiller, and Midnight
Multiple ransomware strains, including Bactor, ChickenKiller, and Midnight, have been identified by CYFIRMA Research and Norton. Bactor and ChickenKiller ransomware target Windows systems, while Midnight ransomware has…
7 articles · Updated November 27, 2025
Recent Intelligence Reports
- Onelogon attack defeats Microsoft's Zerologon patch — Itnews.Au · August 12, 2026
- MITRE ATT&CK - MuddyWater — attack.mitre.org · July 8, 2026
- Operation Escaneo: Infrastructure Exposure, TTP Analysis, and Attribution Assessment of an ... — Cloudsek · June 17, 2026
- Weekly Intelligence Report – 06 February 2026 — Cyfirma · February 5, 2026
- Weekly Intelligence Report – 28 November 2025 — Cyfirma · November 27, 2025
- The nexus of risk and intelligence: How vulnerability — Csoonline · November 19, 2025
- Data Leak Outs Hacker Students of Iran's MOIS Training Academy — Darkreading · October 30, 2025