Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
The China-aligned threat group SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange and IIS server vulnerabilities, specifically the ProxyLogon vulnerability chain, to conduct cyberespionage. This group has…
2 articles · Updated May 5, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Data Destruction and Disk Wiping Techniques Targeting Organizations
Adversaries are employing data destruction and disk wiping techniques to disrupt organizational operations. Techniques include overwriting files and disk data, with malware exhibiting worm-like propagation capabilities.…
2 articles · Updated July 22, 2026 -
QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor to Windows Users
A supply chain attack targeting the QuickFox VPN application has been uncovered, affecting Windows users. The attack, attributed to the Chinese state-sponsored group Mustang Panda, involved a trojanized version of the…
14 articles · Updated August 6, 2026 -
UAT-10147 Cybercrime Group Integrates AI for Large-Scale Attacks
In early 2026, Cisco Talos identified UAT-10147, a Chinese-speaking cybercrime group targeting vulnerable web servers across multiple countries, including Brazil, China, and Canada. The group employs agentic AI to…
10 articles · Updated August 20, 2026 -
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
229 articles · Updated July 1, 2026 -
Russian Drone Attack on Chernobyl's New Safe Confinement Raises Nuclear Safety Concerns
On February 14, 2025, a Russian drone struck the New Safe Confinement (NSC) at the Chernobyl Nuclear Power Plant, damaging its structure and raising alarms about potential radiation leaks. The NSC, designed to contain…
146 articles · Updated April 14, 2026 -
Active Exploitation of Critical Vulnerabilities in Lantronix and Ubiquiti Devices
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of critical vulnerabilities in Lantronix EDS5000-series devices and Ubiquiti's UniFi OS. The Lantronix vulnerability,…
6 articles · Updated June 25, 2026
Recent Intelligence Reports
- Microsoft Security Intelligence — www.microsoft.com · September 2, 2026
- ValleyRAT masquerading as adware — Securelist · August 31, 2026
- Windows Defender Driver Abuse Enables Kernel — Gbhackers · August 21, 2026
- UAT-10147 deploys SPECTRE: A cross — Blog.Talosintelligence · August 20, 2026
- August 2026 Patch Tuesday analysis — www.automox.com · August 13, 2026
- AvosLocker — www.sophos.com · August 12, 2026
- MITRE ATT&CK T1688 — attack.mitre.org · August 12, 2026
- Powercat Malware Campaign Fake Game Cheats Deliver Infostealer Targeting Discord Roblox And Crypto Wallets — www.threatlocker.com · August 6, 2026