T1003.006 - DCSync is a mitre_attack tracked across 5 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 17, 2025; most recent activity June 24, 2026.
A new macOS malware named 'Gaslight' has been identified, attributed to North Korean threat actors. This malware employs prompt injection techniques to confuse AI-assisted malware analysis tools, embedding 38 fake…
A security researcher, known as Chaotic Eclipse, has publicly released exploit code for a zero-day vulnerability in Windows, dubbed BlueHammer, allowing local privilege escalation to SYSTEM or elevated administrator…
Mandiant has released rainbow tables that can crack credentials using the Net-NTLMv1 protocol within 12 hours. This legacy Microsoft authentication protocol has been known to expose users to credential theft for over 20…
Since mid-2024, the threat group UNC1549 has conducted targeted cyber campaigns against the aerospace, aviation, and defense industries, particularly focusing on entities in the Middle East. Mandiant has documented…
Mandiant has identified a surge in targeted campaigns by the threat group UNC1549, suspected to be linked to Iran, focusing on the aerospace, aviation, and defense sectors in the Middle East. Since mid-2024, these…