T1071 - Command And Control is a mitre_attack tracked across 13 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity December 24, 2025.
Asus has identified a critical authentication bypass vulnerability (CVE-2025-59367) affecting its DSL-AC51, DSL-AC750, and DSL-N16 router models. This flaw allows remote, unauthenticated attackers to gain full control…
WebRAT malware, a backdoor with info-stealing capabilities, is being distributed through GitHub repositories claiming to host proof-of-concept exploits for recently disclosed vulnerabilities. Initially targeting gamers…
APT24, a China-linked hacking group, has been utilizing a previously undocumented malware named BadAudio in a three-year espionage campaign. This malware has been delivered through various methods, including…
Research indicates that Russian APT group Gamaredon and North Korean Lazarus Group are collaborating by sharing operational infrastructure. This partnership marks a significant development in state-sponsored cyber…
Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…
North Korea's Lazarus Group and Russia's Gamaredon have reportedly begun collaborating in cyber operations, marking the first known instance of such cooperation. Researchers from Gen Digital indicate that the two groups…
SonicWall reported a security incident involving unauthorized access to backup firewall configuration files stored in a cloud environment. The company attributed the breach to a state-backed threat actor and engaged…
SonicWall reported unauthorized access to backup firewall configuration files in September 2025, attributed to a state-backed threat actor. The company engaged Mandiant for an investigation and communicated with…
South Korean authorities suspect that North Korea's Lazarus Group was behind a hack of Upbit, resulting in losses of approximately $30.4 million. The breach involved unusual activity in Solana tokens and led Upbit to…
Cybercriminals are utilizing the Matrix Push C2 framework to exploit browser notifications for distributing malicious links. This method involves social engineering tactics to trick users into allowing notifications,…