Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
17 articles · Updated August 30, 2026 -
Cyberattack on Polish Energy Sector Exploits Private APN Vulnerability
In December 2025, hackers breached a Polish combined heat and power (CHP) plant using a private Access Point Name (APN) to access the operational technology network. The attack, attributed to the Russian Electrum threat…
8 articles · Updated August 10, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
Iranian Cyberespionage Targets Iraqi Government Officials
In 2024, Iranian APT group BladedFeline launched a cyber campaign against Kurdish and Iraqi government officials, utilizing advanced malware tools including the Shahmaran backdoor and the Whisper backdoor. The attacks…
2 articles · Updated May 13, 2026 -
Cloud Atlas APT Group Exploits CVE-2018-0802 and Modifies termsrv.dll for RDP Access
The Cloud Atlas APT group has been observed employing a sophisticated cyber espionage campaign targeting government and commercial entities in Russia and Belarus. This campaign, active since 2025 and continuing into…
4 articles · Updated May 25, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
90-Day Vulnerability Disclosure Policy Declared Obsolete Due to AI Advancements
The traditional 90-day vulnerability disclosure policy is deemed ineffective as AI accelerates bug detection and exploitation. Security expert Himanshu Anand highlights that AI tools can convert security patches into…
2 articles · Updated May 12, 2026 -
Russian Drone Attack on Chernobyl's New Safe Confinement Raises Nuclear Safety Concerns
On February 14, 2025, a Russian drone struck the New Safe Confinement (NSC) at the Chernobyl Nuclear Power Plant, damaging its structure and raising alarms about potential radiation leaks. The NSC, designed to contain…
146 articles · Updated April 14, 2026
Recent Intelligence Reports
- Sygnia Reveals New Activity by China — Sg.Finance.Yahoo · August 30, 2026
- ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions — Cybersecuritynews · August 25, 2026
- AI — Gbhackers · August 25, 2026
- Hackers breached a small Polish energy plant via private APN last year — Bleepingcomputer · August 10, 2026
- 116557 — securelist.ru · August 10, 2026
- n8n Security: How Leaked API Keys Expose Your Encryption Key — Blog.Gitguardian · August 4, 2026
- Arch Linux freezes AUR package adoptions after malware wave — Feeds.4Sysops · August 1, 2026
- 115909 — securelist.ru · July 30, 2026