Related Threat Clusters
-
CISA Warns U.S. After Cyberattack on Poland's Energy Grid Linked to Russian Hackers
A cyberattack targeting Poland's energy grid in December has been linked to a Russian government-affiliated hacking group. The attack affected 30 wind and photovoltaic farms and prompted the Cybersecurity and…
9 articles · Updated February 10, 2026 -
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Cisco SD-WAN Zero-Day Exploited by Threat Actor Since 2023
A cyber threat actor has been exploiting a zero-day vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controller since 2023. This vulnerability allows unauthenticated remote attackers to bypass authentication and…
104 articles · Updated February 25, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
The Russian Foreign Intelligence Service (SVR) has been exploiting multiple vulnerabilities, including the SolarWinds breach, to compromise U.S. and allied networks. The SolarWinds attack, which began in September 2019,…
2 articles · Updated May 24, 2026 -
Cyber Attack on Polish Energy Facilities by Russian-Linked Groups
Russian-linked cyber groups have targeted multiple energy facilities in Poland, exploiting default ICS credentials. The attacks have led to significant disruptions in operations, with Poland's CERT releasing a report…
2 articles · Updated February 3, 2026 -
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and…
30 articles · Updated August 14, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026
Recent Intelligence Reports
- BleepingComputer — www.bleepingcomputer.com · September 1, 2026
- AI Model Evaluator METR Hit by Credential Theft, Probing — Darkreading · September 1, 2026
- Novocure Data Breach Affects More Than 1 400 Cancer Patients — www.bleepingcomputer.com · September 1, 2026
- 2026 08 31 Security Update — metr.org · September 1, 2026
- Chinese Fire Ant hackers turn Cisco routers into spying platforms — Bleepingcomputer · August 31, 2026
- Anthropic warns: attackers are hijacking active Claude sessions and using up other people's limits — Mezha.Ua · August 31, 2026
- Anthropic signs out Claude users after infostealers steal sessions — Feeds.4Sysops · August 31, 2026
- Breaking: Claude Massive Account Theft Incident — Eu.36Kr · August 31, 2026