IIS is a technology platform tracked across 26 threat clusters and 30 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 16, 2026.
IIS (Internet Information Services) is Microsoft's web server and application hosting platform for Windows, used to serve websites and web applications. Its security posture matters because misconfigurations, exposure of credentials in code, and supply-chain risks in the .NET ecosystem can compromise hosted apps, and OS-level updates can affect availability and resilience of IIS deployments.
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
In 2024, Iranian APT group BladedFeline launched a cyber campaign against Kurdish and Iraqi government officials, utilizing advanced malware tools including the Shahmaran backdoor and the Whisper backdoor. The attacks…
PTC Inc. has disclosed a critical vulnerability, CVE-2026-4681, in its Windchill and FlexPLM software that allows for remote code execution through the deserialization of trusted data. The vulnerability has been…
A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a…
ConnectWise ScreenConnect has been compromised by two critical vulnerabilities, CVE-2024-1708 and CVE-2024-1709, which allow attackers to bypass authentication and execute remote code. The vulnerabilities were disclosed…
Microsoft patched CVE-2026-47291, a critical remote code execution vulnerability in the Windows HTTP.sys protocol stack. This flaw allows unauthenticated remote attackers to exploit an integer overflow during HTTP/1.x…
On April 9, 2026, the pro-Iranian hacking group Ababil of Minab claimed responsibility for a cyberattack on the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group alleged access to critical…
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
In June 2026, a new ransomware family named Spirals executed a double extortion attack against an IT services company in South Asia, completing the operation in under 24 hours. The attackers gained initial access by…
A critical vulnerability (CVE-2025-63261) affecting AWStats, a web server log analyzer, was published on March 20, 2026. This vulnerability allows for arbitrary code execution via command injection, impacting users of…