Related Threat Clusters
-
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
Critical Zoom Vulnerabilities Enable Remote Code Execution via AI-Driven Exploits
A critical zero-click vulnerability in Zoom's annotation feature, dubbed 'Zoomsday,' allows attackers to remotely execute code on participants' devices during meetings without user interaction. Discovered by A Security…
46 articles · Updated August 11, 2026 -
Gentlemen Ransomware Uses Advanced Techniques for Network Attacks
The Gentlemen ransomware, a Go-based RaaS, has been active since mid-2025 and employs aggressive propagation methods. It utilizes 21 remote execution techniques, including PsExec, WMIC, and PowerShell Remoting, to…
3 articles · Updated July 6, 2026 -
Spring Ring: Coordinated Vishing Campaign Exploits Microsoft Teams
Between January and April 2026, a coordinated voice phishing campaign named Spring Ring targeted over 150 employees across more than 10 companies using fake IT support accounts on Microsoft Teams. Attackers registered…
38 articles · Updated August 31, 2026 -
Microsoft Teams Exploited for Helpdesk Impersonation Attacks
Cyber attackers are increasingly using Microsoft Teams to impersonate IT helpdesk staff, employing social engineering tactics to gain remote access to enterprise systems. This method, known as 'cross-tenant helpdesk…
51 articles · Updated April 20, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026
Recent Intelligence Reports
- Impersonating IT support: how threat actors turn a remote session into enterprise — Blogs.Microsoft · September 2, 2026
- Storm-0501 — attack.mitre.org · August 18, 2026
- M1030 — attack.mitre.org · August 13, 2026
- Go-Based Gentlemen Ransomware Uses PsExec, WMIC, and PowerShell Remoting for ... — Gbhackers · July 6, 2026
- External Remote Services — attack.mitre.org · June 3, 2026
- Microsoft: Teams increasingly abused in helpdesk impersonation attacks — Bleepingcomputer · April 20, 2026