Related Threat Clusters
-
China-linked Cyber Group Expands Targeting to Southeastern Europe
A sophisticated threat actor known as UAT-7290, tracked by Cisco Talos, has expanded its operations to target telecommunications providers in Southeastern Europe. This group, which has been active since at least 2022,…
1 article · Updated January 8, 2026 -
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
62 articles · Updated July 15, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Belarus-Aligned Ghostwriter Group Targets Ukraine with Phishing Campaign
A phishing campaign targeting Ukrainian government organizations has been attributed to the Belarus-aligned Ghostwriter group, also known as UAC-0057. The campaign involves sending emails with PDF attachments that lead…
3 articles · Updated May 22, 2026 -
Sandworm Targets Critical Infrastructure with Aggressive OT Attacks
The Russian state-sponsored group Sandworm has intensified its cyber operations against industrial and critical infrastructure, utilizing pre-compromised operational technology (OT) environments instead of zero-day…
5 articles · Updated May 14, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
FrostyNeighbor Cyberespionage Campaign Targets Ukrainian and Polish Governments
The Belarus-aligned cyber group FrostyNeighbor has launched a targeted campaign against government organizations in Ukraine and Poland since March 2026. Utilizing spearphishing techniques, the group delivers malicious…
8 articles · Updated May 14, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026
Recent Intelligence Reports
- PentestingEverything exploit — Sploitus · September 8, 2026
- Recorded Future: 215 CVEs Exploited in H1 2026, AsyncRAT Leads Malware Data — Technadu · September 4, 2026
- Attackers Turn Trusted Node Js Runtime Into Malware Delivery Tool In Targeted Attacks — cybernoz.com · September 3, 2026
- Node Js Returns Ransomware — www.security.com · September 3, 2026
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks — Thehackernews · September 3, 2026
- Node.js: Old Technique Makes a Comeback — Security · September 3, 2026
- H1 2026 Malware Vulnerability Trends — Recordedfuture · September 3, 2026
- 001 — attack.mitre.org · September 2, 2026