T1098 - Account Manipulation is a mitre_attack tracked by ThreatCluster, appearing in 9 threat clusters built from 9 intelligence report mentions.
T1098 - Account Manipulation is a mitre_attack tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed February 12, 2026; most recent activity June 7, 2026.
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
A new software supply chain attack has been identified, attributed to the GitHub account 'BufferZoneCorp.' This campaign utilizes sleeper packages, specifically malicious Ruby gems and Go modules, to compromise…
In April 2026, AWS reported that threat actors are exploiting Amazon Cognito refresh tokens to maintain unauthorized access to applications. These tokens, which can be valid for up to 10 years, allow attackers to…
Threat actors are exploiting AWS Organizations by using compromised credentials to remove accounts from organizations. This tactic allows them to bypass Service Control Policies (SCPs) and gain unrestricted access to…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
On April 17, 2026, the Ethereum Name Service gateway eth.limo was briefly hijacked due to a social engineering attack against its domain registrar, EasyDNS. An attacker impersonated a team member to initiate an account…
Following U.S. military strikes on Iran, there is an anticipated increase in cyber warfare activities targeting U.S. operational technology and critical infrastructure. Iran is expected to retaliate with cyber attacks…
The Crazy ransomware gang has been observed exploiting legitimate employee monitoring software, specifically Net Monitor for Employees Professional, along with the SimpleHelp remote support tool. This tactic allows them…
T1098 - Account Manipulation is a mitre_attack tracked by ThreatCluster, appearing in 9 threat clusters built from 9 intelligence report mentions.
The most recent intelligence report mentioning T1098 - Account Manipulation on ThreatCluster is dated June 7, 2026. Activity was first observed February 12, 2026, giving a tracked span from then to June 7, 2026.
Across ThreatCluster reporting, T1098 - Account Manipulation most frequently co-occurs with Storm-1747, TeamPCP, Malware, Phishing, Privilege Escalation, among 12 tracked related entities.
The most significant recent cluster is “Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems” (131 articles · Updated May 14, 2026). T1098 - Account Manipulation appears across 9 threat clusters in total, listed above with sources.
T1098 - Account Manipulation appears in 9 intelligence report mentions across 9 deduplicated threat clusters, aggregated from 17,000+ monitored sources.