Related Threat Clusters
-
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that…
6 articles · Updated May 22, 2026 -
Critical Check Point VPN Vulnerability Exploited by Ransomware Gang
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The…
46 articles · Updated June 8, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
Critical Vulnerabilities Found in nginx Affecting openSUSE Leap 15.6
A significant update for nginx has been released to address multiple vulnerabilities affecting openSUSE Leap 15.6. The vulnerabilities include CVE-2026-1642, a plaintext data injection flaw, CVE-2026-27654, a buffer…
5 articles · Updated May 8, 2026 -
Critical Vulnerabilities in TP-Link Archer Routers Expose Users to Attacks
TP-Link has patched multiple critical vulnerabilities in its Archer NX router series, specifically affecting models NX200, NX210, NX500, and NX600. The most severe flaw, CVE-2025-15517, allows unauthenticated attackers…
11 articles · Updated March 25, 2026 -
Multiple Ruby Vulnerabilities in Oracle Linux Require Immediate Attention
Recent updates for Oracle Linux address critical vulnerabilities in Ruby affecting versions 2.5, 3.3, and 4.0. Key issues include a code execution flaw (CVE-2026-41316) and denial of service vulnerabilities…
10 articles · Updated July 6, 2026 -
Russian Military Hackers Compromise UK Internet Traffic
On April 7, 2026, reports emerged that Russian military hackers have successfully rerouted internet traffic of British users. This operation is believed to be a state-sponsored cyber attack aimed at compromising…
2 articles · Updated April 7, 2026 -
Global Takedown of Tycoon2FA Phishing Service Disrupts Major Cybercrime Operation
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
59 articles · Updated March 5, 2026 -
Critical Vulnerability in MCP Protocol Exposes 200,000 AI Servers to Remote Code Execution
A report by OX Security has identified a critical vulnerability in the Model Context Protocol (MCP) developed by Anthropic, potentially exposing over 200,000 AI servers to remote code execution. The flaw lies in the…
12 articles · Updated April 16, 2026 -
Exposed DICOM Servers Risk Patient Data Across Healthcare Systems
A cybersecurity investigation revealed that over 3,800 DICOM servers are exposed to the internet, compromising the personal health information of approximately 16 million patients across more than 110 countries. The…
4 articles · Updated May 5, 2026
Recent Intelligence Reports
- BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers — Gbhackers · September 1, 2026
- 4 Outdated Cybersecurity Tips That No Longer Keep You Safe — Aol · August 15, 2026
- Initial NAS Message Security: Applying 5G Cybersecurity and Privacy Capabilities — Csrc.Nist · August 6, 2026
- 130626 — support.omadanetworks.com · August 5, 2026
- Police Disrupt a €140M Cyber Fraud Ring in Spain — Darkreading · July 16, 2026
- Oracle Linux 8 Ruby Important DoS Fixes Advisory ELSA-2026 — Linuxsecurity · July 7, 2026
- Kuala Lumpur Joins Singapore, Bangkok, and Ho Chi Minh City in Battling Severe Surges in ... — Travelandtourworld · June 22, 2026
- AMD changes rules, denies researcher $10000 bounty after taking 124 days to patch security flaw — Techspot · June 12, 2026