Related Threat Clusters
-
Critical cPanel Vulnerability Exploited in Southeast Asia Cyber Attacks
A sophisticated cyber campaign has exploited a critical cPanel vulnerability (CVE-2026-41940) to breach government and military servers in Southeast Asia, particularly targeting Indonesia. The attackers utilized a…
3 articles · Updated May 4, 2026 -
Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
67 articles · Updated June 18, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets
The Chinese-speaking threat group CL-STA-1062 has been actively deploying a new .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. This campaign utilizes…
6 articles · Updated June 26, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Rapid7 Reports State-Sponsored Espionage in Global Telecoms
Rapid7 Labs has identified a sustained espionage campaign by a China-nexus threat actor, Red Menshen, targeting global telecommunications infrastructure. The research, titled 'Sleeper Cells in the Telecom Backbone,'…
4 articles · Updated March 26, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
8 articles · Updated August 30, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
FBI Warns of Russian Hackers Targeting Signal Backup Recovery Keys
The FBI and CISA have issued a warning regarding a phishing campaign by Russian intelligence services targeting Signal users to steal Backup Recovery Keys. This escalation allows attackers to access victims' historical…
15 articles · Updated June 26, 2026
Recent Intelligence Reports
- Chinese Fire Ant hackers turn Cisco routers into spying platforms — Bleepingcomputer · August 31, 2026
- Sygnia Reveals New Activity by China — Sg.Finance.Yahoo · August 30, 2026
- PavinLoader Malware Spreads via ClickFix and Fake Download Campaigns — Technadu · August 25, 2026
- Crooks push Mac malware through fake OpenAI Codex ads — Theregister · August 25, 2026
- Siemens PLCs Targeted by Cybercriminals — Industryweek · August 20, 2026
- From Fake Interview To Signed Clickonce Three Payload Windows Chain — haveibeensquatted.com · August 20, 2026
- Feds Confirm AI Is Writing Exploits for Siemens PLCs Used in Water and Energy — Techtimes · August 20, 2026
- New Spicerat Sneakychef — blog.talosintelligence.com · August 19, 2026