Related Threat Clusters
-
UAT-7290 Cyber Espionage Targets South Asian Telecoms
UAT-7290, a China-linked advanced persistent threat group, has been active since at least 2022, focusing on espionage against telecommunications providers in South Asia. The group employs a range of Linux and Windows…
2 articles · Updated January 12, 2026 -
Critical Joomla JCE Vulnerability Under Active Exploitation
A critical vulnerability in the Joomla Content Editor (JCE), tracked as CVE-2026-48907, allows unauthenticated attackers to execute remote code on affected Joomla sites. This flaw affects JCE versions below 2.9.99.6 and…
33 articles · Updated June 17, 2026 -
Advanced Threat Actor Exploits Cisco and Citrix Zero-Day Vulnerabilities
An advanced persistent threat actor exploited zero-day vulnerabilities in Cisco Identity Service Engine and Citrix NetScaler products. The attacks utilized custom malware and were detected by Amazon's MadPot honeypot…
8 articles · Updated November 12, 2025 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Cl0p Ransomware Group Claims Data Theft from Nearly 50 Companies
The Cl0p hacking group has claimed to have stolen significant data from nearly 50 companies, including Shell, Philips, General Electric (GE), and Fiserv. The group reported stealing approximately 89GB from Shell and…
30 articles · Updated August 14, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
APT Exploits Zero-Day Vulnerabilities in Cisco and Citrix Systems
An advanced persistent threat (APT) group exploited zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix systems, specifically CVE-2025-5777 and CVE-2025-20337. The attacks were detected by…
16 articles · Updated November 18, 2025 -
China's Brickstorm Malware Compromises US Critical Networks
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…
10 articles · Updated December 4, 2025 -
Microsoft's .NET RCE Bug Remains Unfixed, Affecting Enterprise Applications
Security researchers have identified a remote code execution (RCE) vulnerability in the .NET framework that impacts various enterprise applications. Piotr Bazydło from watchTowr presented these findings at Black Hat…
3 articles · Updated December 10, 2025 -
CISA Flags OpenPLC ScadaBR Vulnerability as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the OpenPLC ScadaBR vulnerability, tracked as CVE-2021-26829, to its Known Exploited Vulnerabilities catalog after confirming active…
2 articles · Updated December 2, 2025
Recent Intelligence Reports
- Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it — Theregister · August 21, 2026
- Shell and Philips Confirm Investigation as Cl0p Claimed Data Theft — Technadu · August 14, 2026
- Earth Simnavaz Cyberattacks — www.trendmicro.com · July 23, 2026
- Critical Joomla JCE RCE Added to CISA KEV as Attacks Target Linux Web Servers — Linuxsecurity · June 17, 2026
- UAT-8099 Targets IIS in Asia with BadIIS and GotoHTTP — Socprime · February 2, 2026
- UAT-8099 Exploits IIS Servers Using Web Shell Attacks — Cyberpress · January 30, 2026
- UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region — Cybersecuritynews · January 30, 2026
- Cisco Talos uncovers UAT — Industrialcyber.Co · January 9, 2026