Related Threat Clusters
-
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
Cybercrime Surge of 245% Linked to Iran War Escalation
Since the onset of the Iran war, cybercrime has surged by 245%, as reported by Akamai. The banking and fintech sectors are the most affected, accounting for 40% of the malicious traffic, followed by e-commerce (25%) and…
2 articles · Updated March 16, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
Mirage Kitten Malware Targets Middle East and Africa with New Toolset
The Mirage Kitten APT group has deployed a sophisticated malware suite, including the NightLedger backdoor, across the Middle East and Africa. This campaign has successfully infiltrated sensitive sectors such as…
2 articles · Updated July 30, 2026 -
Showboat Malware Targets Telecoms in China-Aligned Cyber Espionage Campaign
A new Linux malware family named Showboat has been discovered, targeting telecommunications firms primarily in the Middle East and Central Asia since mid-2022. Researchers from Lumen's Black Lotus Labs and PwC…
9 articles · Updated May 21, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Russian-Speaking Handler Directs Arson Attacks on UK Prime Minister's Properties
Two men, Roman Lavrynovych and Stanislav Carpiuc, were convicted of arson targeting properties linked to UK Prime Minister Keir Starmer. The attacks, occurring in May 2025, were allegedly orchestrated by a…
12 articles · Updated June 15, 2026 -
US Charges Russian Hacker for Facilitating Void Blizzard Cyber Espionage Campaign
Denis Obrezko, a 36-year-old Russian national, was arrested in Thailand and extradited to the US, where he faces charges for facilitating a cyber espionage campaign linked to the group Void Blizzard. This group has…
8 articles · Updated June 10, 2026 -
Massive Campaign of Fake Chrome VPN Extensions Compromises User Traffic
Over 737 fraudulent Chrome extensions masquerading as VPN services have been discovered, routing user traffic through SOCKS5 proxies controlled by a single provider. The extensions, which impersonate reputable brands…
4 articles · Updated August 12, 2026
Recent Intelligence Reports
- Mirax report — www.cleafy.com · September 2, 2026
- Fake Software Update Installs a Real Crypto Wallet — Itsecurityguru · September 2, 2026
- Pwning The Ai Stack — www.vulncheck.com · September 2, 2026
- Chinese state-sponsored hackers — thenationaldesk.com · August 27, 2026
- Windows 10 Finger Command Can Be Abused To Download Or Steal Files — www.bleepingcomputer.com · August 18, 2026
- New Malware turns Microsoft cloud into its control center — Csoonline · August 18, 2026
- New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies — Infosecurity-Magazine · August 14, 2026
- AvosLocker — www.sophos.com · August 12, 2026