Remote Desktop Protocol is a mitre_attack tracked across 17 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity July 21, 2026.
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
Russian state-aligned threat groups are increasingly exploiting Remote Desktop Protocol (RDP), Virtual Private Networks (VPNs), and supply chain vulnerabilities to gain initial access to networks across various sectors,…
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
In March 2026, Latin America experienced a significant increase in cyberattacks, particularly against government agencies. Organizations in the region faced an average of 3,050 attacks per week, with government entities…
Kaspersky's research reveals that The Gentlemen ransomware group, active since mid-2025, is expanding its operations with new custom-built malware tools. This group targets various industries, including healthcare and…
A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator…
In June 2026, a series of ransomware attacks were reported in Colombia and Mexico, where attackers exploited misconfigured corporate printers and remote desktop services to encrypt data using BitLocker. The attackers…
The Crazy ransomware gang has been observed exploiting legitimate employee monitoring software, specifically Net Monitor for Employees Professional, along with the SimpleHelp remote support tool. This tactic allows them…
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…