Related Threat Clusters
-
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
DPRK-Linked Malware Targeting Job Seekers via Wellfound
A cybersecurity incident involved a fake job interview scheme on Wellfound, where an operator named 'Felix' from 'HyperHive' targeted an individual using a social engineering tactic referencing their real CV. The attack…
2 articles · Updated April 7, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
22 articles · Updated August 30, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
APT41 Exploits Cloud Services with New Zero-Detection ELF Backdoor
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
6 articles · Updated April 13, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
UAT-7810 Expands Malware Arsenal to Enhance ORB Network
The China-linked threat actor UAT-7810 is evolving its malware toolkit, notably introducing LONGLEASH, an upgraded version of the SHORTLEASH backdoor. This group exploits known vulnerabilities in unpatched Ruckus…
12 articles · Updated July 7, 2026 -
North Korea's Lazarus Group Exploits Crypto Gaps, $6.75 Billion Stolen
In 2025 and the first half of 2026, North Korea's Lazarus Group has been a major threat in the cryptocurrency sector, responsible for approximately $6.75 billion in theft. The group has exploited vulnerabilities in the…
4 articles · Updated July 27, 2026
Recent Intelligence Reports
- Hackers Use ClickFix Lures to Deploy MacSync Stealer and Bypass macOS Security. — Gbhackers · September 10, 2026
- gimmeSH exploit — Sploitus · September 9, 2026
- MacOSThreatTrack exploit — Sploitus · September 9, 2026
- New Xcsset Malware Adds New Obfuscation Persistence Techniques To Infect Xcode Projects — www.microsoft.com · September 9, 2026
- Tr Dprk Apts Ted Backdoor Curlrat Target South Korean Media Automotive Sectors — www.rapid7.com · September 8, 2026
- StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack — Sansec · September 5, 2026
- Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd) — Isc.Sans.Edu · September 3, 2026
- ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd) — Isc.Sans.Edu · September 3, 2026