Related Threat Clusters
-
Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
8 articles · Updated November 12, 2025 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Resurgence of Exploitation Attempts on GlobalProtect and CitrixBleed Vulnerabilities
Between June 29 and July 6, 2026, GreyNoise observed a significant increase in exploitation attempts targeting Palo Alto GlobalProtect CVE-2019-1579, with over 120 malicious hosts detected on July 6. This activity was…
2 articles · Updated July 8, 2026 -
Critical Ivanti EPMM Vulnerabilities Under Active Exploitation
Two critical vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM), CVE-2026-1281 and CVE-2026-1340, have been actively exploited in the wild, allowing unauthenticated remote code execution (RCE) with a CVSS score…
64 articles · Updated January 29, 2026 -
CitrixBleed 2 Exploited by Initial Access Broker for DragonForce Ransomware Attacks
In the first half of 2026, multiple organizations were targeted by an Initial Access Broker exploiting the CitrixBleed 2 vulnerability (CVE-2025-5777). Attackers gained access through the Citrix NetScaler gateway,…
2 articles · Updated July 10, 2026 -
Anubis Ransomware Attack Disrupts Adriatic Port Authority Operations
The Anubis ransomware group launched a cyberattack on the Adriatic Port Authority, crippling operations and causing significant disruptions in maritime logistics. The attack, attributed to Anubis in January 2026,…
8 articles · Updated June 15, 2026 -
Zero-Day Exploits Target Cisco ISE and Citrix Vulnerabilities
Amazon reported that a threat actor is exploiting two critical vulnerabilities, CVE-2025-20337 and CVE-2025-5777, in Cisco ISE and Citrix products as zero-days. These vulnerabilities have been identified as being…
2 articles · Updated November 13, 2025 -
APT Exploits Zero-Day Vulnerabilities in Cisco and Citrix Systems
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
16 articles · Updated November 18, 2025 -
OpenAI Launches GPT-5.4-Cyber Amidst Cybersecurity Arms Race
OpenAI has introduced GPT-5.4-Cyber, a specialized AI model for defensive cybersecurity, available only to vetted professionals through its Trusted Access for Cyber (TAC) program. This model is designed to facilitate…
1357 articles · Updated April 14, 2026 -
Cisco ASA Zero-Day Exploited in State-Espionage Campaign
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
27 articles · Updated December 18, 2025
Recent Intelligence Reports
- CitrixBleed 2 (CVE-2025-5777) 7Steps to Dragonforce Ransomware — Huntress · July 9, 2026
- GreyNoise documented active exploitation — www.greynoise.io · July 6, 2026
- The Anubis Ransomware Attack On The Adriatic Port Authority — www.resecurity.com · June 26, 2026
- Low-skilled Attacker Uses Claude and Codex to Breach Firms | Let's Data Science — Letsdatascience · June 17, 2026
- Adriatic Port Cyber — Infosecurity-Magazine · June 15, 2026
- Ivanti EPMM Zero-Day Flaws: RCE Attacks and Critical Patches — Technadu · January 30, 2026
- CISA catalog of attacked vulnerabilities grew by 20 percent in 2025 — Heise.De · January 6, 2026
- CISA Known Exploited Vulnerabilities Soared 20% in 2025 — Thecyberexpress · January 5, 2026