Related Threat Clusters
-
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Exploitation of Client Software Vulnerabilities and User Execution Techniques
Recent cybersecurity reports detail the exploitation of software vulnerabilities in client applications, particularly targeting web browsers and Microsoft Office. Adversaries utilize techniques such as Drive-by…
2 articles · Updated June 8, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Critical Vulnerabilities Discovered in Mozilla Products
Multiple vulnerabilities have been identified in Mozilla products, with the most severe allowing for arbitrary code execution. Exploitation could enable attackers to install programs, access, modify, or delete data, and…
44 articles · Updated April 8, 2026 -
Cyber Adversaries Exploit File Enumeration and Data Collection Techniques
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
2 articles · Updated April 22, 2026 -
Chrome Vulnerabilities Allow Arbitrary Code Execution and System Crashes
Google has released a critical security update for Chrome, addressing two high-severity vulnerabilities that could allow arbitrary code execution and denial-of-service attacks. Users on Windows, macOS, and Linux are…
503 articles · Updated February 4, 2026
Recent Intelligence Reports
- T1189 — attack.mitre.org · August 7, 2026
- 002 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- T1203 · Exploitation for Client Execution — attack.mitre.org · June 8, 2026
- T1082 — attack.mitre.org · April 24, 2026
- T1083 — attack.mitre.org · April 22, 2026