Related Threat Clusters
-
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
On April 24, 2026, CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. The affected products include SimpleHelp remote management software, Samsung MagicINFO 9 Server, and…
3 articles · Updated April 26, 2026 -
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
54 articles · Updated July 2, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
EU Sanctions Iranian Cyber Group for Election Interference and Data Breaches
On March 17, 2026, the Council of the European Union sanctioned Emennet Pasargad, an Iranian cyber front, for its involvement in cyberattacks, including interference in the 2020 US election. The group was linked to…
2 articles · Updated March 17, 2026 -
cPanel and WHM Critical Auth Bypass Vulnerability Patched
A critical authentication vulnerability affecting all supported versions of cPanel and WHM was disclosed on April 28, 2026. This flaw allows attackers to gain unauthorized access to the control panel, posing significant…
69 articles · Updated April 29, 2026 -
Pro-Iran Hacktivist Group Launches DDoS Attack on Canonical's Ubuntu Infrastructure
On April 30, 2026, a coordinated DDoS attack targeted Canonical, the company behind the Ubuntu Linux distribution, disrupting its web infrastructure and preventing users from accessing updates. The attack was claimed by…
14 articles · Updated May 1, 2026 -
US and Allies Dismantle Major IoT Botnets Behind Record DDoS Attacks
On March 20, 2026, the U.S. Justice Department, in collaboration with law enforcement from Canada and Germany, announced the dismantling of four significant botnets: Aisuru, KimWolf, JackSkid, and Mossad. These botnets…
31 articles · Updated March 20, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
Surge in DDoS Attacks Over 1 Tbps Amidst Botnet Resurgence
In the first half of 2026, Cloudflare reported a significant increase in DDoS attacks, particularly those exceeding 1 Tbps, with 935 such attacks mitigated, marking a 519% rise from Q1. April 2026 saw the peak of DDoS…
18 articles · Updated August 11, 2026 -
Seiko SkyBridge IoT Routers Face Permanent OS Injection Vulnerability
Seiko Solutions' SkyBridge MB-A100 and MB-A110 routers are affected by a high-severity OS command injection vulnerability (CVE-2026-50043) disclosed on July 1, 2026. The flaw allows authenticated attackers to execute…
2 articles · Updated July 4, 2026
Recent Intelligence Reports
- Calix GigaSpire Flaw Lets Strangers Control Your Home Firewall: No Patch — Techtimes · August 25, 2026
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs — Bleepingcomputer · August 19, 2026
- Mirai botnet — thehackernews.com · August 14, 2026
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — Infosecurity-Magazine · August 14, 2026
- Botnets before the ballots: US midterms at risk? | perspective — Scworld · August 13, 2026
- Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs — Fortinet · August 13, 2026
- Aisuru botnet. — www.cloudflare.com · August 12, 2026
- Major DDoS Attacks Are Booming, But US No Longer the Most Targeted Country — Uk.Pcmag · August 11, 2026