Related Threat Clusters
-
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
The Russian state-backed hacking group Sandworm has intensified its operations against Ukrainian organizations by deploying data-wiping malware. This campaign targets critical sectors, including the grain industry, and…
6 articles · Updated November 7, 2025 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Critical FreeIPA Vulnerabilities Allow Unauthenticated Admin Access
A critical flaw in FreeIPA, tracked as CVE-2026-76578, allows unauthenticated clients to create Kerberos identities and gain administrative privileges. This vulnerability arises from a misconfigured access control rule…
3 articles · Updated September 8, 2026 -
Destructive Lotus Wiper Targets Venezuelan Energy Sector Amid Geopolitical Tensions
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
8 articles · Updated April 21, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
FortiBleed Campaign Compromises 75,000+ Fortinet Devices Globally
A credential-harvesting campaign known as 'FortiBleed' has compromised over 75,000 Fortinet firewalls and VPNs across 194 countries. The attackers, suspected to be Russian-speaking cybercriminals, exploited previously…
105 articles · Updated June 17, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897
Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw…
27 articles · Updated June 11, 2026
Recent Intelligence Reports
- The September 2026 Security Update Review — www.zerodayinitiative.com · September 9, 2026
- September 2026 Patch Tuesday: Updates and Analysis — Crowdstrike · September 9, 2026
- NTLMv1 DC Rainbow Tables: Domain Compromise — adscanpro.com · September 8, 2026
- The September 2026 Security Update Review — Thezdi · September 8, 2026
- FreeIPA 4.13.3 — www.freeipa.org · September 8, 2026
- Hackers claim access to DMW network as DICT probes gov’t cyberattacks — Newsbytes.Ph · September 7, 2026
- DragonForce Ransomware | Group Profile, Cartel Alliance & Attack Analysis (2026) — Dexpose · September 7, 2026
- IT Support Impersonation Turns a Teams Chat Into Domain — Cybersecurity-Insiders · September 4, 2026