T1083 - File And Directory Discovery is a mitre_attack tracked by ThreatCluster, appearing in 12 threat clusters built from 13 intelligence report mentions.
T1083 - File And Directory Discovery is a mitre_attack tracked across 12 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed February 25, 2026; most recent activity July 25, 2026.
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
The Chinese-speaking threat group CL-STA-1062 has been actively deploying a new .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. This campaign utilizes…
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
The Clop ransomware gang is actively exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM systems, allowing unauthenticated remote code execution. This exploitation involves deploying JSP…
A new cyber threat identified by Huntress involves a fake background removal website that tricks users into executing malicious commands. Dubbed BackgroundFix, this site masquerades as a free image-editing service,…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A cyberattack utilizing the Hermes AI agent targeted Thailand's Ministry of Finance between July 9 and July 13, 2026. Researchers from Hunt.io discovered exposed directories containing 585 files, including exploit code…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
A new data extortion group named Helix has emerged, utilizing identity-focused tactics such as vishing and device code phishing to exploit Microsoft 365 environments. The group primarily targets SharePoint, employing…
A new modular malware named TELEPUZ has been detected spreading since late April 2026. It uses ClickFix lures to trick users into executing malicious commands. The malware is lightweight and modular, likely developed by…
T1083 - File And Directory Discovery is a mitre_attack tracked by ThreatCluster, appearing in 12 threat clusters built from 13 intelligence report mentions.
The most recent intelligence report mentioning T1083 - File And Directory Discovery on ThreatCluster is dated July 25, 2026. Activity was first observed February 25, 2026, giving a tracked span from then to July 25, 2026.
Across ThreatCluster reporting, T1083 - File And Directory Discovery most frequently co-occurs with Apt18, Apt28, APT3, Apt32, Apt37, among 12 tracked related entities.
The most significant recent cluster is “Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation” (22 articles · Updated April 15, 2026). T1083 - File And Directory Discovery appears across 12 threat clusters in total, listed above with sources.
T1083 - File And Directory Discovery appears in 13 intelligence report mentions across 12 deduplicated threat clusters, aggregated from 17,000+ monitored sources.