T1562 - Impair Defenses is a mitre_attack tracked by ThreatCluster, appearing in 25 threat clusters built from 30 intelligence report mentions.
T1562 - Impair Defenses is a mitre_attack tracked across 25 threat clusters and 30 intelligence report mentions on ThreatCluster. First observed December 23, 2025; most recent activity July 26, 2026.
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
A wave of attacks exploiting CVE-2024-12802, an authentication bypass vulnerability in SonicWall SSL VPN appliances, began in February 2026. Despite a firmware patch issued in 2025, attackers were able to bypass…
The Gentlemen ransomware, a Go-based RaaS, has been active since mid-2025 and employs aggressive propagation methods. It utilizes 21 remote execution techniques, including PsExec, WMIC, and PowerShell Remoting, to…
Sophos X-Ops analysts uncovered a threat actor utilizing AI technologies to develop a malware-testing framework aimed at evading endpoint detection and response (EDR) systems. The activity was detected on June 2, 2026,…
Qilin and Warlock ransomware variants have been identified exploiting vulnerable drivers to disable over 300 endpoint detection and response (EDR) tools. This exploitation allows the ransomware to evade detection and…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
Recent research from ESET reveals that ransomware attackers are increasingly using EDR killers to disable endpoint detection and response (EDR) systems before launching their encryptors. These tools have become standard…
The anonymous security researcher known as Nightmare-Eclipse has been banned from both GitHub and GitLab due to the release of multiple unpatched Windows vulnerabilities. GitHub terminated the account on May 25, 2026,…
T1562 - Impair Defenses is a mitre_attack tracked by ThreatCluster, appearing in 25 threat clusters built from 30 intelligence report mentions.
The most recent intelligence report mentioning T1562 - Impair Defenses on ThreatCluster is dated July 26, 2026. Activity was first observed December 23, 2025, giving a tracked span from then to July 26, 2026.
Across ThreatCluster reporting, T1562 - Impair Defenses most frequently co-occurs with Agrius, Apt38, APT41, APT5, Aquatic Panda, among 12 tracked related entities.
The most significant recent cluster is “Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor” (2 articles · Updated June 17, 2026). T1562 - Impair Defenses appears across 25 threat clusters in total, listed above with sources.
T1562 - Impair Defenses appears in 30 intelligence report mentions across 25 deduplicated threat clusters, aggregated from 17,000+ monitored sources.