Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
EU Sanctions Russia Over Ongoing Cyber Espionage Campaign
The European Union has condemned and sanctioned Russia for a prolonged cyber espionage campaign targeting its member states. The campaign, orchestrated by the 16th Centre of the FSB, has involved infiltrating government…
172 articles · Updated July 13, 2026 -
Iranian Hackers Target US Aviation with New Malware and SEO Poisoning
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
6 articles · Updated May 26, 2026 -
Russian Hackers Target US Nuclear Scientists and Defense Contractors
Russian hackers have been conducting a year-long cyber-espionage campaign targeting US nuclear scientists, defense contractors, and government employees. The hackers utilized a rare software exploit that allows them to…
15 articles · Updated July 24, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits
Recent reports indicate a significant rise in the exploitation of edge devices, such as VPN gateways and firewalls, by state-sponsored actors. These devices have become the primary attack vector for espionage…
3 articles · Updated July 22, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026
Recent Intelligence Reports
- Extend your data perimeter to the AWS Management Console with Private Access — Aws.Amazon · August 28, 2026
- FBI says Chinese hacking group targeted US government agencies for years — Uk.News.Yahoo · August 26, 2026
- FBI disables China-linked hacking tools used against US agencies - Nextgov/FCW — Nextgov · August 26, 2026
- Securelist — securelist.com · August 26, 2026
- UK Space Cybersecurity Market (2024-2029) — Marketsandmarkets · August 22, 2026
- AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn — Cybersecuritydive · August 19, 2026
- Datavault AI will acquire CyberCatch in an all-cash transaction — Portalerp · August 15, 2026
- Lazarus Group Hacked Defense Workers With Windows Kernel Zero — Techtimes · August 13, 2026