Related Threat Clusters
-
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this…
2 articles · Updated August 22, 2026 -
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
Destructive Lotus Wiper Targets Venezuelan Energy Sector Amid Geopolitical Tensions
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
8 articles · Updated April 21, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
22 articles · Updated August 30, 2026 -
China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
2 articles · Updated July 23, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
Localized Phishing Campaign Targets Cambodian Organizations with Multi-Stage Malware
A recent cyber campaign has been identified targeting organizations in Cambodia, utilizing localized phishing lures. The attack employs a complex multi-stage infection chain, starting with an Inno Setup installer that…
2 articles · Updated August 28, 2026 -
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Acronis Threat Research Unit has identified a new malware campaign named PATCHCORD, targeting Afghan telecom providers and critical infrastructure in South Asia. The malware, a custom backdoor written in C/C++, is…
10 articles · Updated August 13, 2026
Recent Intelligence Reports
- Kimsuky exploits AI coding agents to spearhead premium-themed hacks in Korea - CHOSUNBIZ — Biz.Chosun · September 7, 2026
- Four REVSTEALER — Thehackernews · September 6, 2026
- Microsoft Security Intelligence — www.microsoft.com · September 2, 2026
- Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools — Cybersecuritynews · September 2, 2026
- Pwning The Ai Stack — www.vulncheck.com · September 2, 2026
- Counterfeit installers to system compromise: Tracking a deceptive software download campaign — Blogs.Microsoft · September 1, 2026
- Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks — Helpnetsecurity · September 1, 2026
- Fake Claude Opus 5 app delivers malware and wipes its own tracks — Helpnetsecurity · September 1, 2026