T1057 - Process Discovery is a mitre_attack tracked across 12 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed February 4, 2026; most recent activity July 15, 2026.
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
The SHEETCREEP espionage campaign employs a UAE-India diplomatic-themed ISO file to deliver a C# remote access trojan (RAT) via Google Sheets as its command-and-control channel. The ISO file, named…
A new Linux malware family named Showboat has been discovered, targeting telecommunications firms primarily in the Middle East and Central Asia since mid-2022. Researchers from Lumen's Black Lotus Labs and PwC…
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
A critical vulnerability (CVE-2026-22679) in the Weaver E-cology platform is being actively exploited. This unauthenticated remote code execution flaw affects Weaver E-cology 10.0 builds released before March 12, 2026.…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
A new malvertising campaign has been identified, targeting consumers and small to medium businesses (SMBs) globally. The campaign delivers the Vidar infostealer and XMRig cryptominer through malicious ads promising…
The OkoBot malware framework has been identified as a significant threat to cryptocurrency users, specifically targeting Ledger and Trezor wallets. This multi-stage malware captures sensitive information, including…