Related Threat Clusters
-
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
2 articles · Updated June 17, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
CitrixBleed 2 Exploited by Initial Access Broker for DragonForce Ransomware Attacks
In the first half of 2026, multiple organizations were targeted by an Initial Access Broker exploiting the CitrixBleed 2 vulnerability (CVE-2025-5777). Attackers gained access through the Citrix NetScaler gateway,…
2 articles · Updated July 10, 2026 -
SonicWall SSL VPN Vulnerability CVE-2024-12802 Actively Exploited Despite Patching
A wave of attacks exploiting CVE-2024-12802, an authentication bypass vulnerability in SonicWall SSL VPN appliances, began in February 2026. Despite a firmware patch issued in 2025, attackers were able to bypass…
6 articles · Updated May 19, 2026 -
LockBit Ransomware Targets ICBC Financial Services and U.S. Bank
On November 8, 2025, the LockBit ransomware group attacked ICBC Financial Services, disrupting U.S. Treasury trading operations. The attack exploited a vulnerability in Citrix NetScaler, leading to a $9 billion…
10 articles · Updated August 20, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Shift in Ransomware Tactics Targeting Cloud Assets
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…
56 articles · Updated November 19, 2025
Recent Intelligence Reports
- ICBC Financial Services — www.resecurity.com · August 20, 2026
- Storm-0501 — attack.mitre.org · August 18, 2026
- Mandiant and Google's Threat Intelligence Group documented — cloud.google.com · July 29, 2026
- CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware — Huntress · July 9, 2026
- Threat Spotlight Vpn Exploitation When Patched Doesnt Mean Protected — reliaquest.com · May 19, 2026
- Weekly Intelligence Report – 06 February 2026 — Cyfirma · February 5, 2026
- Stolen VPN Credentials Most Common Ransomware Attack Vector — Thecyberexpress · November 20, 2025