Related Threat Clusters
-
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Critical Cisco IMC Vulnerability Allows Full Admin Access via Authentication Bypass
Cisco Systems has disclosed a critical authentication bypass vulnerability, CVE-2026-20093, affecting its Integrated Management Controller (IMC) with a CVSS score of 9.8. This flaw allows unauthenticated remote…
6 articles · Updated April 2, 2026 -
Surge in Exploited CVEs and Malware Activity in H1 2026
In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report…
2 articles · Updated September 4, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Rhysida and Interlock Ransomware Groups Exploit Shared Malware Ecosystem
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…
3 articles · Updated June 16, 2026 -
ShinyHunters Target SSO Accounts in Voice Phishing Attacks
The ShinyHunters extortion gang has claimed responsibility for a series of voice phishing attacks targeting single sign-on (SSO) accounts at major platforms including Okta, Microsoft, and Google. In these attacks,…
191 articles · Updated January 25, 2026
Recent Intelligence Reports
- H1 2026 Malware Vulnerability Trends — Recordedfuture · September 3, 2026
- Interlock and Rhysida: AI in the Ransomware Ecosystem — Socprime · June 17, 2026
- Cisco says critical Webex Services flaw requires customer action — Bleepingcomputer · April 16, 2026
- Critical Cisco Server Flaw Enables Full Administrative Takeover, Urgent Patching Advised — Linkedin · April 2, 2026
- Possible ShinyHunters Cisco Breach Exposing 3M Records, Tied to Trivy Compromise — Technadu · April 2, 2026
- Critical Cisco IMC auth bypass gives attackers Admin access — Bleepingcomputer · April 2, 2026
- Interlock Ransomware Leveraged Cisco FMC Zero — Thecyberexpress · March 19, 2026
- AWS Warns Hackers Have Abused Cisco Firewall Zero — Infosecurity-Magazine · March 19, 2026