Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn…
17 articles · Updated May 25, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Chinese Threat Group Exploits Roundcube Vulnerabilities in University Networks
A suspected China-aligned threat group, tracked as UNK_MassTraction, has been exploiting vulnerabilities in Roundcube mail servers at U.S. and Canadian universities since May 2026. The campaign targets physics and…
14 articles · Updated July 7, 2026 -
Malicious NuGet Packages Target Chinese Developers, Steal Sensitive Data
Five malicious NuGet packages were discovered targeting developers in the Chinese .NET ecosystem. The packages, published under the account bmrxntfj, impersonate legitimate libraries and have accumulated around 65,000…
3 articles · Updated May 7, 2026 -
Supply Chain Attack Compromises Popular Rust Crates to Deliver Malware
On August 20, 2026, a supply chain attack targeted the Rust ecosystem, compromising the widely used crates arrayref, append-only-vec, and internment. The attackers injected a malicious dependency, proc-macro1, which…
22 articles · Updated August 20, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026
Recent Intelligence Reports
- Tr Dprk Apts Ted Backdoor Curlrat Target South Korean Media Automotive Sectors — www.rapid7.com · September 7, 2026
- Fake Minecraft Mod Deploys Myth Stealer RAT to Steal Browser Credentials and Cookies — Cybersecuritynews · September 7, 2026
- Revstealer Credential Harvesting Infostealer — www.elastic.co · September 6, 2026
- Fake Software Update Installs a Real Crypto Wallet — Itsecurityguru · September 2, 2026
- Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies — Gbhackers · September 2, 2026
- JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS — Gbhackers · September 1, 2026
- Hackers Target Claude Accounts With Malware That Steals Login Sessions — Pymnts · August 31, 2026
- WARNING: New Malware Campaign Targets Claude AI Users To Hijack Accounts — Linkedin · August 31, 2026