Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1865 articles · Updated February 12, 2026 -
Cisco DoS Vulnerability CVE-2026-20188 Requires Manual Reboot for Recovery
Cisco has disclosed a high-severity denial-of-service (DoS) vulnerability tracked as CVE-2026-20188 affecting the Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO). The flaw arises from…
4 articles · Updated May 7, 2026 -
Cisco ASA Zero-Day Exploited in State-Espionage Campaign
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
27 articles · Updated December 18, 2025 -
Cisco Alerts on Active Exploitation of ASA and FTD Vulnerabilities
Cisco has confirmed that hackers are actively exploiting a remote code execution vulnerability in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) products. Organizations using these devices are…
2 articles · Updated November 6, 2025 -
Cisco Faces Multiple Critical Vulnerabilities in Unified CCX and Firewalls
Cisco has disclosed critical vulnerabilities in its Unified Contact Center Express (CCX) platform and Adaptive Security Appliances (ASA) that allow unauthenticated remote attackers to execute arbitrary code and…
10 articles · Updated November 10, 2025 -
SonicWall Investigates State-Backed Breach of Cloud Backup Service
SonicWall reported a security incident involving unauthorized access to backup firewall configuration files stored in a cloud environment. The company attributed the breach to a state-backed threat actor and engaged…
8 articles · Updated November 21, 2025
Recent Intelligence Reports
- LevelBlue found that phishing started 65% of intrusions — www.levelblue.com · July 25, 2026
- New Cisco DoS flaw requires manual reboot to revive devices — Bleepingcomputer · May 6, 2026
- T1685: Disable or Modify Tools — attack.mitre.org · April 28, 2026
- Firestarter malware survives Cisco firewall updates, security patches — Bleepingcomputer · April 24, 2026
- CISA, NCSC issue Firestarter backdoor warning — Theregister · April 24, 2026
- Governments on high alert after CISA snuffs out Firestarter backdoor on fed network — Theregister · April 24, 2026
- ACSC issues High Status alert for Cisco Firepower and Secure Firewall products — Technologydecisions.Au · April 24, 2026
- ArcaneDoor Attack (Cisco ASA Zero-Day) — Filestore.Fortinet · December 18, 2025