Related Threat Clusters
-
StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
14 articles · Updated June 25, 2026 -
AI-Driven Malware Framework Automates EDR Evasion Tactics
Sophos X-Ops analysts uncovered a threat actor utilizing AI technologies to develop a malware-testing framework aimed at evading endpoint detection and response (EDR) systems. The activity was detected on June 2, 2026,…
16 articles · Updated June 2, 2026 -
New Mistic Backdoor Linked to Ransomware Access Broker Activity
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
21 articles · Updated June 24, 2026 -
FortiBleed Campaign: AI-Driven Exploitation of Fortinet Firewalls
The FortiBleed campaign exposed valid credentials for nearly 75,000 Fortinet FortiGate firewalls across 21,632 domains. Threat actors leveraged commoditized supercomputing resources to execute massive cryptographic…
2 articles · Updated June 21, 2026 -
AI-Generated PowerShell Script Used for Active Directory Reconnaissance
A threat actor employed an AI-generated PowerShell script to conduct reconnaissance in a compromised Active Directory environment. The attack began with unauthorized access to a domain-joined Windows Server via Remote…
2 articles · Updated July 14, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1874 articles · Updated February 12, 2026 -
Akira Ransomware Uses Safe Mode to Evade EDR Detection
In early August 2026, an Akira ransomware affiliate executed an attack leveraging Safe Mode to evade endpoint detection and response (EDR) tools. The attack began with credential spraying against an exposed SonicWall…
11 articles · Updated August 12, 2026 -
Adaptavist Group Breach: Ransomware Claims Major Data Theft
The Adaptavist Group, a UK enterprise software consultancy, is investigating a security breach that occurred in late March 2026, when an attacker gained unauthorized access using stolen credentials. CEO Simon…
4 articles · Updated April 21, 2026
Recent Intelligence Reports
- Akira ransomware attacker uses Safe Mode reboot to evade EDR | news — Scworld · August 12, 2026
- Unmasking The Gentlemen Ransomware — www.trendmicro.com · August 8, 2026
- Attacker Used AI to Build Custom PowerShell Recon Malware — Securityaffairs.Co · July 14, 2026
- StrikeShark Campaign Uses New SharkLoader Malware to Deploy Cobalt Strike Beacon — Gbhackers · June 25, 2026
- Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
- Nation — Infostealers · June 21, 2026
- Attackers Use AI Tools to Automate Active Directory Attacks | Let's Data Science — Letsdatascience · June 3, 2026
- Pointing a Cursor at evading detection — News.Sophos · June 2, 2026