Heroku is a technology platform tracked across 4 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed April 17, 2026; most recent activity May 26, 2026.
The PowMix botnet has been identified as targeting Czech organizations since at least December 2025. Attackers use malicious LNK files to initiate a PowerShell loader that extracts a ZIP archive, bypasses AMSI…
On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…
In late February 2024, a large-scale phishing campaign known as 'SubdoMailing' was uncovered, exploiting gaps in DMARC safeguards. This tactic allowed attackers to send emails from compromised subdomains, bypassing SPF…
Cyber attackers are increasingly using Microsoft Teams to impersonate IT helpdesk staff, employing social engineering tactics to gain remote access to enterprise systems. This method, known as 'cross-tenant helpdesk…