T1189 - Drive-by Compromise is a mitre_attack tracked across 50 threat clusters and 70 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity July 16, 2026.
Google has issued an emergency update to address a high-severity zero-day vulnerability, CVE-2025-13223, in its Chrome browser. This flaw, linked to the V8 JavaScript engine, allows attackers to execute arbitrary code…
The Google Threat Intelligence Group has identified DarkSword, a full-chain iOS exploit affecting versions 18.4 to 18.7. This exploit leverages multiple zero-day vulnerabilities, including CVE-2025-31277 and…
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the…
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
Google has issued an emergency update to address a zero-day vulnerability in Chrome that is actively being exploited. This patch affects approximately 2 billion Chrome users, highlighting the ongoing challenges faced by…
A recent report from UK intelligence reveals that over 100 governments now have access to commercial spyware tools, a significant increase from 80 in 2023. These tools, such as NSO Group's Pegasus and Paragon's…
On March 21, 2026, Ledger CTO Charles Guillemet issued a security alert regarding a critical update for the Chrome web browser, addressing 26 vulnerabilities, including 4 critical and 22 high severity issues. These…
A recent report by The Media Trust reveals that online advertisements accounted for over 60% of malware distribution in 2025, surpassing email as the leading channel. This shift in cybercriminal tactics has resulted in…
The art-template npm package, a popular JavaScript templating library, was compromised to deliver a sophisticated iOS exploit targeting Safari users. Discovered on May 20, 2026, the attack involved a watering-hole…