AppleJeus is a malware family tracked across 10 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed January 30, 2026; most recent activity July 23, 2026.
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Radiant Capital, a decentralized lending protocol, is winding down operations after failing to recover from a $50 million hack attributed to a North Korean state-sponsored group, the Lazarus Group. The exploit occurred…
On April 1, 2026, the Drift Protocol on Solana was exploited, resulting in over $270 million in losses, primarily in USDC. North Korean state hackers executed 31 withdrawals in a rapid 12-minute window, leading to a…
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
A new malware campaign is targeting macOS users with the AMOS-linked Atomic Stealer, exploiting fake software update pages and the built-in Script Editor application. Victims are tricked into executing malicious…
On April 1, 2026, Drift Protocol, a decentralized exchange on the Solana blockchain, confirmed it was under an active attack, resulting in an estimated loss of $270 million to $285 million. The exploit involved…
CrowdStrike has reclassified the North Korea-linked intrusion set LABYRINTH CHOLLIMA into three distinct units: GOLDEN CHOLLIMA and PRESSURE CHOLLIMA, which focus on cryptocurrency theft, and the core LABYRINTH CHOLLIMA…
Fireblocks disrupted a North Korea-linked job recruitment scam that targeted crypto firms by using fake interviews and assignments to install malware. The hackers impersonated recruiters and conducted interviews via…