Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
281 articles · Updated April 2, 2026 -
New Cyber Extortion Groups Target Critical Infrastructure with Phishing Tactics
Two threat groups, Cordial Spider and Snarky Spider, affiliated with The Com, are targeting U.S. organizations across various critical infrastructure sectors for rapid data theft and extortion. Their operations,…
5 articles · Updated May 1, 2026 -
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…
44 articles · Updated July 1, 2026 -
N-able Passportal Vulnerability Exposes User Credentials
A vulnerability in N-able's Passportal password manager allows any malicious website to gain complete access to user credentials for up to 100 days. The issue, identified by Bay Area Labs, stems from the browser…
2 articles · Updated August 20, 2026 -
RovoBlast Vulnerability Exposes Enterprise Data via One-Click Attack
Atlassian's Rovo AI assistant was found vulnerable to a one-click prompt injection attack, dubbed RovoBlast, which allows attackers to inject malicious instructions into authenticated user sessions. This vulnerability…
4 articles · Updated August 10, 2026 -
Zscaler and Vectra AI Combat AI-Driven Cyber Threats
Zscaler has integrated its Zero Trust platform with Vectra AI to enhance threat detection and response capabilities against sophisticated cyber attacks. The integration focuses on identifying malicious…
3 articles · Updated May 29, 2026 -
Phishing and BEC Incidents Surge: Email Security Practices Essential
In 2025, phishing and business email compromise (BEC) incidents surged, with the FBI reporting over 191,561 complaints and $3.04 billion in BEC losses. Email remains the primary vector for social engineering attacks,…
2 articles · Updated August 8, 2026 -
iAuthFlow V2 Phishing Kit Enables Rogue Passkey Enrollment for Persistent Account Access
The iAuthFlow V2 phishing toolkit, available for $10,000, allows attackers to enroll rogue passkeys on compromised accounts, ensuring persistent access even after victims change their passwords. This attack employs a…
2 articles · Updated August 21, 2026
Recent Intelligence Reports
- Iauthflow V2 Phishing Google Passkeys — abnormal.ai · August 21, 2026
- N — Darkreading · August 20, 2026
- From Fake Interview To Signed Clickonce Three Payload Windows Chain — haveibeensquatted.com · August 20, 2026
- Best email security solutions for MSPs in 2026: a buyer's guide — Acronis · August 18, 2026
- Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant — Infosecurity-Magazine · August 10, 2026
- One — Csoonline · August 10, 2026
- Email Incident Response Team Roles: A Complete Breakdown of Every Position ... — Adaptivesecurity · August 8, 2026
- Russian hackers can steal government emails without victims clicking a link, cyber agencies warn — www.nextgov.com · July 24, 2026