Cloudflare Workers is a technology platform tracked by ThreatCluster, appearing in 10 threat clusters built from 13 intelligence report mentions.
Cloudflare Workers is a technology platform tracked across 10 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed November 24, 2025; most recent activity August 2, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
The advanced persistent threat group SideWinder has initiated a targeted phishing campaign aimed at South Asian government organizations, specifically targeting institutions like the Bangladesh Navy and Pakistan’s…
A coordinated international effort led by Microsoft and Europol has dismantled Tycoon2FA, a significant phishing-as-a-service platform responsible for bypassing multi-factor authentication and enabling large-scale…
On May 10, 2026, threat actors exploited CVE-2026-39987, a remote code execution vulnerability in the marimo notebook environment, to gain unauthorized access to internal databases. The attackers utilized a large…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
In May 2026, TrendAI™ Research reported on a cyber intrusion involving the ClearFake campaign, where threat actors utilized the EtherHiding technique to deliver payloads via smart contracts on the BNB Smart Chain…
At Black Hat USA 2026, 29% of sessions focused on AI security, highlighting a shift in attack methodologies targeting agent infrastructure. Significant briefings from Check Point Research revealed vulnerabilities in…
A Russian-linked campaign is distributing the StealC V2 infostealer malware through malicious Blender 3D model files uploaded to marketplaces like CGTrader. This malware exploits Blender's ability to execute Python…
The SloppyLemming threat group has conducted a series of cyberattacks from January 2025 to January 2026, focusing on government entities and critical infrastructure in Pakistan and Bangladesh. This campaign,…
Cloudflare Workers is a technology platform tracked by ThreatCluster, appearing in 10 threat clusters built from 13 intelligence report mentions.
The most recent intelligence report mentioning Cloudflare Workers on ThreatCluster is dated August 2, 2026. Activity was first observed November 24, 2025, giving a tracked span from then to August 2, 2026.
Across ThreatCluster reporting, Cloudflare Workers most frequently co-occurs with Apt32, Apt34, APT41, APT42, Badhatch, among 12 tracked related entities.
The most significant recent cluster is “MuddyWater Targets U.S. Entities Amid Geopolitical Tensions” (16 articles · Updated July 22, 2026). Cloudflare Workers appears across 10 threat clusters in total, listed above with sources.
Cloudflare Workers appears in 13 intelligence report mentions across 10 deduplicated threat clusters, aggregated from 17,000+ monitored sources.