Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and…
30 articles · Updated August 14, 2026 -
Iranian Hackers Target US Aviation with New Malware and SEO Poisoning
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
6 articles · Updated May 26, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
Mirage Kitten Malware Targets Middle East and Africa with New Toolset
The Mirage Kitten APT group has deployed a sophisticated malware suite, including the NightLedger backdoor, across the Middle East and Africa. This campaign has successfully infiltrated sensitive sectors such as…
2 articles · Updated July 30, 2026 -
Clop Ransomware Exploits Critical Vulnerability in Windchill and FlexPLM
The Clop ransomware gang is actively exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM systems, allowing unauthenticated remote code execution. This exploitation involves deploying JSP…
28 articles · Updated July 24, 2026 -
Nimbus Manticore APT Targets Aerospace Sector with Fake Job Schemes
The Iranian-aligned threat group Nimbus Manticore has launched a cyber campaign targeting aerospace and defense organizations. This operation utilizes a fake recruitment portal to distribute custom malware via a…
2 articles · Updated June 2, 2026 -
TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign
TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent…
3 articles · Updated July 30, 2026 -
Gitea Vulnerability Exposes 30,000 Private Container Images to Attackers
A critical vulnerability, CVE-2026-27771, in Gitea's container registry allowed unauthenticated users to access private container images for nearly four years. Discovered by Noscope in April 2026, the flaw affects over…
8 articles · Updated May 28, 2026 -
Car Bomb Kills Senior Russian General in Moscow Region
A car bomb explosion in Balashikha, Moscow, killed Colonel Damir Davydov, head of the Russian military's missile and artillery supply. The attack occurred at approximately 5:30 AM on June 10, 2026, as Davydov was…
4 articles · Updated June 10, 2026
Recent Intelligence Reports
- Securelist — securelist.com · August 26, 2026
- UK Space Cybersecurity Market (2024-2029) — Marketsandmarkets · August 22, 2026
- Clop Windchill Flexplm Exploitation — ransom-isac.org · August 18, 2026
- CVE-2026-12569 — ransom-isac.com · August 17, 2026
- Cyber gang claims to have breached dozens of multinationals, stolen data — Computing · August 14, 2026
- Lazarus Group Hacked Defense Workers With Windows Kernel Zero — Techtimes · August 13, 2026
- Lazarus Group Exploited Windows Zero — Finance.Biggo · August 12, 2026
- Attacker phished way into US defense supplier's Microsoft 365 account — Theregister · August 7, 2026