Havoc is a malware family tracked across 8 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed February 4, 2026; most recent activity July 23, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
In early 2026, a series of targeted attacks named Operation TrueChaos exploited a zero-day vulnerability in TrueConf software, tracked as CVE-2026-3502, which allows attackers to execute arbitrary files on connected…
The SnappyClient malware implant, first identified in December 2025, poses a significant threat to Windows users, particularly targeting cryptocurrency wallets. This C++-based command-and-control (C2) implant enables…
Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian…
A low-skilled attacker known as 'Poisson' executed a credential theft campaign against a small French automotive business, compromising four machines. The attack utilized a multi-stage malware chain, including a…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
The cyber threat group Amaranth-Dragon has leveraged a critical vulnerability in WinRAR, identified as CVE-2025-8088, to gain persistent control over systems belonging to Southeast Asian governments. This exploitation…
The SloppyLemming threat group has conducted a series of cyberattacks from January 2025 to January 2026, focusing on government entities and critical infrastructure in Pakistan and Bangladesh. This campaign,…