Related Threat Clusters
-
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts
Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62%…
5 articles · Updated August 18, 2026 -
ACSC Issues Critical Alert on Exploited CMS Vulnerabilities
The Australian Cyber Security Centre (ACSC) has issued a second alert in two months regarding a large-scale hacking campaign exploiting unpatched vulnerabilities in content management systems (CMS). The campaign targets…
10 articles · Updated July 9, 2026 -
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…
12 articles · Updated August 7, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026 -
Fake CAPTCHA Scams Evolve into Malware Delivery Systems
A new wave of scams utilizing fake CAPTCHA prompts has emerged, allowing attackers to install malware without traditional download methods. Known as 'ClickFix,' this tactic tricks users into executing malicious scripts…
17 articles · Updated May 24, 2026 -
DeepLoad Malware Campaign Uses AI for Credential Theft and Evasion
A new malware strain named 'DeepLoad' has been identified, capable of stealing credentials from enterprise networks immediately upon infection. The malware employs AI-generated code to obfuscate its logic, making it…
9 articles · Updated March 30, 2026 -
LeakNet Ransomware Expands Tactics with ClickFix and Deno Loader
LeakNet, a ransomware group, has adopted new tactics involving ClickFix social engineering and a Deno-based fileless loader. This shift allows them to gain initial access through compromised websites, prompting users to…
7 articles · Updated March 18, 2026
Recent Intelligence Reports
- Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines — Theregister · August 31, 2026
- TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks — Gbhackers · August 31, 2026
- CRPx0 - Threat Actor Profile — Kelacyber · August 26, 2026
- Hackers litter NPM with packages that don't infect computers — Cybernews · August 25, 2026
- Crooks Push Mac Malware Through Fake OpenAI Codex Ads — Ground.News · August 25, 2026
- PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2 — Gbhackers · August 25, 2026
- Malware-as-a-Service Cocktail: ErrTraffic, Cruciferra, and EDR Evasion — Socprime · August 21, 2026
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra — Infosecurity-Magazine · August 19, 2026