T1566.003 - Spearphishing Via Service is a mitre_attack tracked across 42 threat clusters and 49 intelligence report mentions on ThreatCluster. First observed February 8, 2026; most recent activity July 24, 2026.
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
On April 22, 2026, the BSI and BfV reported an active phishing campaign targeting high-profile individuals in Germany via the Signal messaging app. The campaign, attributed to a likely state-sponsored actor, focuses on…
On June 25, 2026, Ukraine's Security Service (SBU) and the FBI announced a coordinated cyber campaign by Russian intelligence targeting messaging accounts of officials, military personnel, politicians, and activists in…
The US Department of State has announced a reward of up to $10 million for information on two Russian-linked hacking groups, UNC5792 and UNC4221, accused of phishing attacks on Signal and WhatsApp users. These groups…
On July 20, 2026, German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its developer in Indonesia. The operation neutralized over 200 servers and disrupted approximately…
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
Recent reports reveal two coordinated phishing campaigns, GLITTER CARP and SEQUIN CARP, targeting journalists and activists linked to the International Consortium of Investigative Journalists (ICIJ) and other critical…
The Lazarus Group, a North Korean hacking organization, executed a targeted attack on the CEO of AllSecure using a fake LinkedIn job interview and deepfake technology. This sophisticated approach highlights the…
Google has filed a lawsuit against the 'Outsider Enterprise', a China-based cybercrime network, for allegedly using AI tools, including its Gemini platform, to conduct large-scale phishing operations. The operation has…