Related Threat Clusters
-
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
The Russian Foreign Intelligence Service (SVR) has been exploiting multiple vulnerabilities, including the SolarWinds breach, to compromise U.S. and allied networks. The SolarWinds attack, which began in September 2019,…
2 articles · Updated May 24, 2026 -
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
On July 1, 2026, security firm SlowMist identified a fake trading bot on GitHub designed to spread malware targeting Polymarket users and DeFi developers. The bot, named 'polymarket-arbitrage-bot', was promoted as a…
2 articles · Updated July 1, 2026 -
Chinese Hackers Exploit Microsoft 365 for 18 Months; Oracle PeopleSoft Vulnerability Targeted
Chinese hackers infiltrated Microsoft 365 environments, maintaining access for 18 months before detection. The attack exploited vulnerabilities to harvest sensitive data from various organizations. Simultaneously, a new…
12 articles · Updated June 13, 2026 -
Escalating Cyber Warfare Threats Amid Geopolitical Tensions
In recent months, cyber warfare has intensified due to rising geopolitical tensions, particularly involving North Korea, Iran, and Russia. North Korean hackers have infiltrated U.S. companies by embedding operatives as…
2 articles · Updated April 9, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Operation TrueChaos: Exploitation of TrueConf Zero-Day Vulnerability
In early 2026, a series of targeted attacks named Operation TrueChaos exploited a zero-day vulnerability in TrueConf software, tracked as CVE-2026-3502, which allows attackers to execute arbitrary files on connected…
5 articles · Updated April 1, 2026 -
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted…
324 articles · Updated July 27, 2026 -
75% of Cyber Attacks on UK Infrastructure Linked to Hostile States, NCSC Reports
The UK's National Cyber Security Centre (NCSC) reported that 75% of over 200 cyber incidents affecting critical national infrastructure (CNI) in the past year were linked to hostile state actors, including Russia,…
18 articles · Updated June 17, 2026
Recent Intelligence Reports
- July 30 blog post — www.anthropic.com · August 31, 2026
- Incident Report Unsanctioned Agent Behaviour During Cyber Testing — www.aisi.gov.uk · August 31, 2026
- Version Control DFIR: GitHub, GitLab, Bitbucket, and Azure DevOps Detection & Incident ... — Securityarsenal · August 28, 2026
- 2026 04 02 Incident Report Litellm Telnyx Supply Chain Attack — blog.pypi.org · August 28, 2026
- Australian cops cuff alleged TeamPCP masterminds — Theregister · August 28, 2026
- Australian police arrest two men accused of widespread open — Straitstimes · August 27, 2026
- Australian police arrest two men accused of widespread open — Straitstimes · August 27, 2026
- Tracker — www.globenewswire.com · August 27, 2026