Related Threat Clusters
-
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows
APT28 has actively exploited a zero-day vulnerability in MSHTML affecting all Windows versions, which has a CVSS score of 8.8. The vulnerability allows for security bypass and poses significant risks to users. A patch…
4 articles · Updated March 2, 2026 -
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
50 articles · Updated July 15, 2026 -
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Active exploitation of two critical vulnerabilities has been reported: CVE-2026-20230 in Cisco Unified CM and CVE-2026-20971 in Samsung KNOX. The Cisco flaw, a server-side request forgery (SSRF), poses an immediate…
4 articles · Updated June 23, 2026 -
Critical OpenSSL Vulnerability CVE-2025-15467 Patched
OpenSSL has patched a high-severity stack buffer overflow vulnerability, tracked as CVE-2025-15467. This flaw allows unauthenticated attackers to trigger denial-of-service conditions and potentially execute remote code…
5 articles · Updated January 29, 2026 -
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
2 articles · Updated June 17, 2026 -
Urgent CISA Directive: Patch Critical Ivanti EPMM Vulnerability CVE-2026-1340 by April 11
The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. federal agencies patch a critical vulnerability in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1340, by April 11, 2026.…
23 articles · Updated April 8, 2026 -
Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
8 articles · Updated November 12, 2025 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025
Recent Intelligence Reports
- Forescout Research Tests Whether AI Can Create PLC Attacks — Itsecurityguru · September 1, 2026
- Social Engineering %28security%29 — en.wikipedia.org · September 1, 2026
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars — Securityweek · September 1, 2026
- Pwning The Ai Stack — www.vulncheck.com · September 1, 2026
- SemiAnalysis Discovers Critical Security Vulnerabilities in Neocloud Infrastructure — Kucoin · August 30, 2026
- New research raises questions around Log4j 2 LogEvent deserialization — Fieldeffect · August 28, 2026
- What Are Social Engineering Attacks — www.techtarget.com · August 27, 2026
- Warning: Two particularly dangerous malware strains. — Vietnam.Vn · August 27, 2026