T1005 - Data From Local System is a mitre_attack tracked across 11 threat clusters and 11 intelligence report mentions on ThreatCluster. First observed March 18, 2026; most recent activity July 15, 2026.
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
A zero-day vulnerability in Adobe Reader has been actively exploited since at least December 2025, allowing attackers to execute remote code and steal sensitive data through malicious PDF files. Security researcher…
Russian authorities used Cellebrite's forensic tools to access the iPhone of political activist Andrey Pivovarov in June 2021, despite Cellebrite's announcement in March 2021 that it would cease sales to Russia. The…
Rapid7 disclosed an access control bypass vulnerability in Adobe ColdFusion, identified as CVE-2023-29298, which affects versions 2018u16, 2021u6, and 2023. The vulnerability allows attackers to access restricted…
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
The KhangNghiem/fast-draft extension on Open VSX was found to contain multiple malicious releases that deploy a remote access trojan (RAT) and an infostealer. Versions 0.10.89, 0.10.105, 0.10.106, and 0.10.112 were…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
U.S. Immigration and Customs Enforcement (ICE) has confirmed the use of Paragon Solutions' spyware, Graphite, to combat fentanyl trafficking. The agency's budget has increased significantly, allowing for the purchase of…
The OkoBot malware framework has been identified as a significant threat to cryptocurrency users, specifically targeting Ledger and Trezor wallets. This multi-stage malware captures sensitive information, including…