Related Threat Clusters
-
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
Multiple Critical CVEs Exploited in Cybersecurity Attacks
A series of vulnerabilities, including CVE-2025-49144, CVE-2025-31702, and CVE-2026-46333, have been identified, affecting systems like Notepad++ and FortiWeb devices. These vulnerabilities allow for local privilege…
30 articles · Updated September 7, 2026 -
Italy Extradites Chinese Hacker Xu Zewei to the U.S. for COVID-19 Research Theft
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
51 articles · Updated April 26, 2026 -
Attackers Exploit WDigest Vulnerability to Harvest Plaintext Credentials
A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a…
3 articles · Updated July 2, 2026 -
PaperCut NG/MF Vulnerability Under Active Exploitation
On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code…
61 articles · Updated August 27, 2026 -
Exploitation of PaperCut Vulnerabilities Threatens Educational Institutions
Attackers are exploiting two recently disclosed vulnerabilities in PaperCut, CVE-2026-81578 and CVE-2026-82078, to steal credentials and gain privileged access in educational institutions across the U.S. and Europe. The…
6 articles · Updated September 5, 2026 -
ModHeader Extension Removed for Covert Data Collection
The ModHeader browser extension, used by approximately 1.6 million users across Chrome and Edge, was removed after researchers discovered a dormant data-collection capability embedded in its signed release. The…
8 articles · Updated July 14, 2026 -
Akira Ransomware Attack Exploits Disabled VPN Account
A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…
2 articles · Updated May 29, 2026 -
New Mistic Backdoor Linked to Ransomware Access Broker Activity
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
21 articles · Updated June 24, 2026 -
Vishing Campaigns Target Organizations via Microsoft Teams and New Operator Console
A vishing campaign, tracked as STAC4749, targeted North American organizations from February to June 2026, using Microsoft Teams to impersonate IT personnel and gain remote access. Attackers deployed a modular toolset,…
9 articles · Updated July 29, 2026
Recent Intelligence Reports
- CVE-2020 — Sploitus · September 7, 2026
- PaperCut Flaws Exploited in Attacks on U.S. and European Schools — Securityaffairs.Co · September 5, 2026
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities — Thehackernews · September 5, 2026
- PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE — Huntress · August 28, 2026
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — Bleepingcomputer · August 13, 2026
- APRA seeks $8m Bendigo cyber control penalty — Theadviser.Au · August 11, 2026
- Unmasking The Gentlemen Ransomware — www.trendmicro.com · August 8, 2026
- New Chaos Ransomware — blog.talosintelligence.com · July 29, 2026