Related Threat Clusters
-
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Data Destruction and Disk Wiping Techniques Targeting Organizations
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
2 articles · Updated July 22, 2026 -
Critical Vulnerabilities and Exploits Targeting Cisco, Canvas, and Microsoft Systems
A series of critical vulnerabilities have emerged, including CVE-2026-20182, which allows unauthenticated attackers to gain admin access to Cisco Catalyst SD-WAN Controllers. ShinyHunters defaced the Canvas LMS login…
2 articles · Updated May 15, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
33 articles · Updated May 19, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026 -
Vulnerability Exploitation Surpasses Credential Theft as Leading Cyber Breach Vector
The 2026 Verizon Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation has overtaken stolen credentials as the primary entry point for data breaches, accounting for 31% of incidents. This…
33 articles · Updated May 20, 2026 -
Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware
On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…
7 articles · Updated May 26, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
TeamPCP Hackers Arrested for Major Supply Chain Attacks
On August 26, 2026, Australian Federal Police arrested two men, Ruben Thomson and Louis Gaebler, linked to the TeamPCP hacking group. This group is notorious for sophisticated supply chain attacks that compromised over…
25 articles · Updated August 27, 2026
Recent Intelligence Reports
- Version Control DFIR: GitHub, GitLab, Bitbucket, and Azure DevOps Detection & Incident ... — Securityarsenal · August 28, 2026
- Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more — Grahamcluley · August 28, 2026
- How AI Coding Agents Can Accidentally Leak Your Secrets — Hackernoon · August 24, 2026
- Keyv And Cacheable Compromise — socket.dev · August 6, 2026
- GitHub, PyPI add time — Bleepingcomputer · July 26, 2026
- LevelBlue found that phishing started 65% of intrusions — www.levelblue.com · July 25, 2026
- T1485 — attack.mitre.org · July 23, 2026
- Suno Hack Ai Music Data Scraping — cryptobriefing.com · July 16, 2026