Related Threat Clusters
-
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
China-linked Bronze Butler Exploits Motex Lanscope Zero-Day Vulnerability
China-linked cyber-espionage group Bronze Butler, also known as Tick, exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw…
2 articles · Updated November 3, 2025 -
State-Sponsored Hackers Compromise Notepad++ Update Mechanism
Notepad++ has been hijacked by state-sponsored hackers, specifically a likely Chinese threat actor. The attackers compromised the software's update mechanism between June and December 2025, allowing them to redirect…
100 articles · Updated February 2, 2026 -
China-linked Hackers Exploit Lanscope Zero-Day to Deploy Gokcpdoor Malware
Cyber-espionage group Bronze Butler, also known as Tick, has exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw was used…
2 articles · Updated November 3, 2025 -
LOTUSLITE Malware Targets US Government Organizations
Acronis researchers have identified a malware campaign named LOTUSLITE that targets US government-related organizations using politically themed emails with ZIP attachments to install a backdoor for ongoing access. This…
1 article · Updated January 22, 2026 -
PDFSider Malware Targets Fortune 100 Finance Firm with Covert Backdoor Access
A new malware strain named PDFSider has been deployed on the network of a Fortune 100 company in the finance sector. The attackers utilized social engineering tactics to gain remote access and installed an encrypted…
2 articles · Updated January 19, 2026 -
LinkedIn Messaging Used in Phishing Campaign to Distribute Malware
A phishing campaign is utilizing LinkedIn private messages to deliver Remote Access Trojans (RATs) through a legitimate open-source penetration testing tool. Cybersecurity researchers from ReliaQuest have identified…
9 articles · Updated January 20, 2026 -
Chinese Hackers Target US Officials with Venezuelan Phishing Campaign
A Chinese-linked cyberespionage group, known as 'Mustang Panda', targeted US government and policy officials using Venezuela-themed phishing emails. This campaign occurred shortly after the US operation to topple former…
11 articles · Updated January 15, 2026
Recent Intelligence Reports
- Notepad++ hijacking linked to Chinese Lotus Blossom crew — Theregister · February 2, 2026
- LOTUSLITE backdoor targets US policy bodies with lures — Itbrief.Au · January 22, 2026
- Threat Actors Leverage LinkedIn Messaging To Deliver Sophisticated Malware — Linkedin · January 20, 2026
- New PDFSider Windows malware deployed on Fortune 100 firm's network — Bleepingcomputer · January 19, 2026
- Researchers Uncover PDFSIDER Malware Built for Long-Term, Covert System Access — Infosecurity-Magazine · January 19, 2026
- Chinese spies used Maduro's capture as a lure to phish US govt agencies — Theregister · January 15, 2026
- Chinese Hackers Exploiting WSUS Remote Code Execution Vulnerability to Deploy ... — Gbhackers · November 21, 2025
- New China-linked attacks involve zero-day Motex Lanscope bug exploitation — Scworld · November 3, 2025