T1136.001 - Local Account is a mitre_attack tracked by ThreatCluster, appearing in 8 threat clusters built from 8 intelligence report mentions.
T1136.001 - Local Account is a mitre_attack tracked across 8 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 16, 2026.
On March 11, 2026, medical technology firm Stryker experienced a significant cyberattack attributed to the Iran-linked hacking group Handala. The attack exploited vulnerabilities in Stryker's Microsoft Intune endpoint…
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
ConnectWise ScreenConnect has been compromised by two critical vulnerabilities, CVE-2024-1708 and CVE-2024-1709, which allow attackers to bypass authentication and execute remote code. The vulnerabilities were disclosed…
In March 2026, the Trigona ransomware group, which operates as a Ransomware-as-a-Service (RaaS), utilized a newly developed custom tool named 'uploader_client.exe' to enhance their data exfiltration capabilities. This…
In June 2026, a new ransomware family named Spirals executed a double extortion attack against an IT services company in South Asia, completing the operation in under 24 hours. The attackers gained initial access by…
The Russian hacker group Curly COMrades is exploiting Microsoft Hyper-V on compromised Windows machines to create hidden Alpine Linux-based virtual machines. These virtual environments allow the group to bypass endpoint…
Bitdefender announced new features in GravityZone, a cybersecurity platform, aimed at improving threat detection and response capabilities for organizations. The update includes Proactive Hardening and Attack Surface…
The Russian hacker group Curly COMrades is utilizing Microsoft Hyper-V to create hidden Alpine Linux-based virtual machines on compromised Windows systems, allowing them to bypass endpoint detection and maintain…
T1136.001 - Local Account is a mitre_attack tracked by ThreatCluster, appearing in 8 threat clusters built from 8 intelligence report mentions.
The most recent intelligence report mentioning T1136.001 - Local Account on ThreatCluster is dated July 16, 2026. Activity was first observed November 4, 2025, giving a tracked span from then to July 16, 2026.
Across ThreatCluster reporting, T1136.001 - Local Account most frequently co-occurs with Authentication Bypass, Data Breach, Malware, Ransomware, Zero-day Exploit, among 12 tracked related entities.
The most significant recent cluster is “CISA Urges Endpoint Security Enhancements After Stryker Cyberattack” (45 articles · Updated March 19, 2026). T1136.001 - Local Account appears across 8 threat clusters in total, listed above with sources.
T1136.001 - Local Account appears in 8 intelligence report mentions across 8 deduplicated threat clusters, aggregated from 17,000+ monitored sources.