T1204.002 - Malicious File is a mitre_attack tracked across 16 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed February 10, 2026; most recent activity July 22, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
A new malware named NarwhalRAT has been discovered targeting Korean users through phishing emails impersonating the Microsoft security team. The malware, linked to the North Korean hacking group APT37, can perform over…
On May 7, 2026, Ubuntu published USN-8251-1, addressing several critical vulnerabilities in libpng, affecting Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. The vulnerabilities include improper memory handling when processing…
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
A severe security vulnerability, CVE-2026-34714, has been identified in Vim, a popular text editor. This flaw allows attackers to execute arbitrary operating system commands by tricking users into opening specially…
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…
Threat actors are distributing malicious LNK files disguised as privacy consent forms and resumes to deceive users into executing them. Once opened, these files execute obfuscated PowerShell commands that download and…
Microsoft has identified a new cryptocurrency-stealing malware named Crypto Clipper, active since February 2026. This malware spreads primarily through malicious Windows shortcut files (.lnk) on USB drives, targeting…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…