T1562.001 - Disable Or Modify Tools is a mitre_attack tracked across 50 threat clusters and 71 intelligence report mentions on ThreatCluster. First observed February 4, 2026; most recent activity July 25, 2026.
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
Researchers at SentinelOne have uncovered a malware framework named fast16, which dates back to 2005 and predates the infamous Stuxnet worm by five years. Fast16 is designed to subtly corrupt high-precision mathematical…
A North Korean cyber group, BlueNoroff, has developed a phishing kit that utilizes AI-generated faces to create convincing fake Zoom and Teams meetings targeting cryptocurrency executives. The kit employs pre-edited…
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
The PowMix botnet has been identified as targeting Czech organizations since at least December 2025. Attackers use malicious LNK files to initiate a PowerShell loader that extracts a ZIP archive, bypasses AMSI…
Microsoft has confirmed a critical zero-day vulnerability in Microsoft Defender, identified as CVE-2026-50656, which allows for local privilege escalation. The flaw, dubbed 'RoguePlanet,' was disclosed by security…
The Warlock ransomware group, also known as Water Manaul, has escalated its attack methods by exploiting unpatched Microsoft SharePoint servers and employing new tactics for persistence and lateral movement. Recent…