Related Threat Clusters
-
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical Check Point VPN Vulnerability Exploited by Ransomware Gang
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The…
46 articles · Updated June 8, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
AI-Driven Malware Framework Automates EDR Evasion Tactics
Sophos X-Ops analysts uncovered a threat actor utilizing AI technologies to develop a malware-testing framework aimed at evading endpoint detection and response (EDR) systems. The activity was detected on June 2, 2026,…
16 articles · Updated June 2, 2026 -
Vect and TeamPCP Form Alliance for Ransomware Operations
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
8 articles · Updated July 2, 2026 -
PCPJack Malware Targets TeamPCP Victims for Credential Theft
The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…
11 articles · Updated May 7, 2026 -
SnappyClient Malware Implant Targets Crypto Wallets with Advanced Evasion Techniques
The SnappyClient malware implant, first identified in December 2025, poses a significant threat to Windows users, particularly targeting cryptocurrency wallets. This C++-based command-and-control (C2) implant enables…
3 articles · Updated March 19, 2026 -
Microsoft Teams Vishing Campaign Deploys GoGRPC Backdoor
A vishing campaign utilizing Microsoft Teams has been identified, targeting organizations through fake IT support calls. Attackers persuade victims to open Quick Assist links, enabling remote access to systems. The…
4 articles · Updated July 28, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1836 articles · Updated February 12, 2026 -
Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia
Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian…
2 articles · Updated June 9, 2026
Recent Intelligence Reports
- North Korean Hackers Collaborate — www.infosecurity-magazine.com · August 11, 2026
- Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor - Zscaler, Inc. — Zscaler · July 28, 2026
- Weekly Threat Bulletin February 11th 2026 — www.f5.com · July 2, 2026
- A Qilin ransomware affiliate exploited a Check Point VPN zero — Thenextweb · June 8, 2026
- Hacktivists are broadening their scope beyond political motivation — Securelist · June 8, 2026
- Pointing a Cursor at evading detection — News.Sophos · June 2, 2026
- Threat Actor Uses AI to Build EDR Evasion Tools — Infosecurity-Magazine · June 2, 2026
- Pointing a Cursor at evading detection — News.Sophos · June 2, 2026