T1090 - Proxy is a mitre_attack tracked across 29 threat clusters and 37 intelligence report mentions on ThreatCluster. First observed February 4, 2026; most recent activity July 24, 2026.
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
Since the onset of the Iran war, cybercrime has surged by 245%, as reported by Akamai. The banking and fintech sectors are the most affected, accounting for 40% of the malicious traffic, followed by e-commerce (25%) and…
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
A new Linux malware family named Showboat has been discovered, targeting telecommunications firms primarily in the Middle East and Central Asia since mid-2022. Researchers from Lumen's Black Lotus Labs and PwC…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
Two men, Roman Lavrynovych and Stanislav Carpiuc, were convicted of arson targeting properties linked to UK Prime Minister Keir Starmer. The attacks, occurring in May 2025, were allegedly orchestrated by a…
Denis Obrezko, a 36-year-old Russian national, was arrested in Thailand and extradited to the US, where he faces charges for facilitating a cyber espionage campaign linked to the group Void Blizzard. This group has…
On March 11, 2026, international law enforcement agencies executed Operation Lightning, dismantling the SocksEscort proxy network, which had compromised over 369,000 routers and IoT devices across 163 countries. The…
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…