T1134 - Access Token Manipulation is a mitre_attack tracked by ThreatCluster, appearing in 15 threat clusters built from 14 intelligence report mentions.
T1134 - Access Token Manipulation is a mitre_attack tracked across 15 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed February 11, 2026; most recent activity July 26, 2026.
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
A critical missing authorization vulnerability (CVE-2026-66012) has been identified in SiYuan versions prior to 3.7.2, allowing remote unauthenticated attackers to bypass authentication on the POST /mcp kernel endpoint.…
A maximum-severity vulnerability in SimpleHelp's RMM software, tracked as CVE-2026-48558, has been exploited to deliver two new malware families: TaskWeaver and Djinn Stealer. The flaw allows unauthenticated attackers…
On July 21, 2026, Microsoft released manual remediation guidance for Windows Server Update Services (WSUS) administrators facing synchronization issues. The problem, which began on July 13, 2026, has prevented the…
In 2026, the average time from vulnerability disclosure to exploitation has drastically decreased to around 8 hours, down from 53 days in 2024. This rapid weaponization is attributed to advancements in AI, which can…
In June 2026, a new ransomware family named Spirals executed a double extortion attack against an IT services company in South Asia, completing the operation in under 24 hours. The attackers gained initial access by…
The ModHeader browser extension, used by approximately 1.6 million users across Chrome and Edge, was removed after researchers discovered a dormant data-collection capability embedded in its signed release. The…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
Kaspersky has identified a significant vulnerability in the Windows Remote Procedure Call (RPC) architecture, named PhantomRPC, which allows attackers to escalate privileges locally to SYSTEM level. This vulnerability…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
T1134 - Access Token Manipulation is a mitre_attack tracked by ThreatCluster, appearing in 15 threat clusters built from 14 intelligence report mentions.
The most recent intelligence report mentioning T1134 - Access Token Manipulation on ThreatCluster is dated July 26, 2026. Activity was first observed February 11, 2026, giving a tracked span from then to July 26, 2026.
Across ThreatCluster reporting, T1134 - Access Token Manipulation most frequently co-occurs with Data Breach, Denial of Service, Malware, Phishing, Ransomware, among 12 tracked related entities.
The most significant recent cluster is “Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation” (22 articles · Updated April 15, 2026). T1134 - Access Token Manipulation appears across 15 threat clusters in total, listed above with sources.
T1134 - Access Token Manipulation appears in 14 intelligence report mentions across 15 deduplicated threat clusters, aggregated from 17,000+ monitored sources.