Related Threat Clusters
-
Gamaredon APT Escalates Cyber Operations Against Ukraine in 2025
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
7 articles · Updated June 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
17 articles · Updated June 11, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
Critical Authentication Flaw in Feast SDK and Operator Exposes Systems to RCE
A significant vulnerability, CVE-2026-18941, was identified in Feast and feast-operator due to the default 'no_auth' configuration, allowing unauthenticated access to critical endpoints. This flaw affects Red Hat…
2 articles · Updated August 11, 2026 -
ModHeader Extension Removed for Covert Data Collection
The ModHeader browser extension, used by approximately 1.6 million users across Chrome and Edge, was removed after researchers discovered a dormant data-collection capability embedded in its signed release. The…
8 articles · Updated July 14, 2026 -
LeakNet Ransomware Expands Tactics with ClickFix and Deno Loader
LeakNet, a ransomware group, has adopted new tactics involving ClickFix social engineering and a Deno-based fileless loader. This shift allows them to gain initial access through compromised websites, prompting users to…
7 articles · Updated March 18, 2026 -
Cloud Attacks Shift Focus to Exploiting Software Vulnerabilities
Hackers are increasingly targeting newly disclosed vulnerabilities in third-party software to access cloud environments, with the time frame for such attacks decreasing significantly. Google reports a notable decline in…
1 article · Updated March 9, 2026 -
Amazon SES Phishing Attacks Bypass Email Security Measures
In early 2026, a surge in phishing attacks utilizing Amazon Simple Email Service (SES) has been reported, exploiting exposed AWS Identity and Access Management (IAM) access keys. Attackers leverage this trusted email…
8 articles · Updated May 4, 2026
Recent Intelligence Reports
- Reverse-Lookup Service Exposed Millions of Photos of People's Faces — Rss.Slashdot · August 20, 2026
- 306 — cwe.mitre.org · August 11, 2026
- Standard MFA Won't Stop Hackers Who Route Microsoft 365 Phishing Through Google — Techtimes · August 7, 2026
- AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare — Aws.Amazon · July 27, 2026
- T1102 — attack.mitre.org · July 23, 2026
- Modheader Malware Chrome Spyware — hackindex.io · July 15, 2026
- AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration — Huntress · July 8, 2026
- Enforce least-privilege authorization in multi — Aws.Amazon · July 6, 2026