Related Threat Clusters
-
Critical Cisco FMC Vulnerabilities Under Active Exploitation
Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079,…
12 articles · Updated September 9, 2026 -
AI-Driven Exploitation of PaperCut Vulnerabilities Compromises 440 Servers Globally
A Russian-speaking threat actor has exploited vulnerabilities CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF software, compromising at least 440 instances across 395 organizations in 48 countries. The campaign…
8 articles · Updated September 9, 2026 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
A critical pre-authentication remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was disclosed on April 8, 2026, and exploited within 9 hours and 41 minutes. The vulnerability,…
16 articles · Updated April 12, 2026 -
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted…
325 articles · Updated July 27, 2026 -
Cybercrime Surge of 245% Linked to Iran War Escalation
Since the onset of the Iran war, cybercrime has surged by 245%, as reported by Akamai. The banking and fintech sectors are the most affected, accounting for 40% of the malicious traffic, followed by e-commerce (25%) and…
2 articles · Updated March 16, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
Resurgence of KV Botnet Linked to Chinese State Actors
Chinese operatives have revived the KV-botnet, a covert data transfer network previously dismantled by the FBI in January 2024. The botnet, which primarily exploits vulnerable routers and IoT devices, has seen a…
2 articles · Updated June 11, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026
Recent Intelligence Reports
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances — Thehackernews · September 10, 2026
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline — Thehackernews · September 10, 2026
- Cisco FMC vulnerability exploited by state hackers, ransomware gangs — Cybernews · September 10, 2026
- Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks — Securityweek · September 10, 2026
- LG Smart TV Security Flaws: What Owners Need to Know — Thepcenthusiast · September 8, 2026
- APTSimulator exploit — Sploitus · September 8, 2026
- Make-and — Sploitus · September 7, 2026
- Agentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80 — Techtimes · September 3, 2026