Frequency
6
occurrences
First Seen
May 11, 2026
Last Seen
June 24, 2026
Related Threat Clusters
-
Akira Ransomware Attack Exploits Disabled VPN Account
A recent Akira ransomware attack targeted a mid-sized organization by exploiting a disabled local SSL VPN account through brute-force methods. The attackers gained initial access, performed credential discovery, and…
2 articles · Updated May 29, 2026 -
New Mistic Backdoor Linked to Ransomware Access Broker Activity
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
21 articles · Updated June 24, 2026 -
Password Resets Fail to Mitigate Active Directory Breaches
Changing passwords is a common response to suspected breaches in Active Directory (AD) environments, but it does not always eliminate the threat. Attackers can exploit cached password hashes, which may remain valid even…
2 articles · Updated May 11, 2026
Recent Intelligence Reports
- Symantec’s Threat Hunter Team observed ModeloRAT — www.security.com · June 24, 2026
- Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
- Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker — Security · June 24, 2026
- Akira Ransomware Kill Chain Reconstructed from Logs — Socprime · May 29, 2026
- Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th) — Isc.Sans.Edu · May 27, 2026
- Why Changing Passwords Doesn't End an Active Directory Breach — Bleepingcomputer · May 11, 2026