Related Threat Clusters
-
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this…
2 articles · Updated August 22, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
CISA Urges Endpoint Security Enhancements After Stryker Cyberattack
On March 11, 2026, medical technology firm Stryker experienced a significant cyberattack attributed to the Iran-linked hacking group Handala. The attack exploited vulnerabilities in Stryker's Microsoft Intune endpoint…
45 articles · Updated March 19, 2026 -
TA416 Resumes Cyber Espionage Against European Governments Amid Geopolitical Tensions
Chinese state-backed group TA416 has reemerged with intensified cyber espionage campaigns targeting European governments, following a quiet period since 2023. Proofpoint reported that the group's renewed activity began…
9 articles · Updated April 1, 2026 -
HOLLOWGRAPH Malware Exploits Microsoft 365 Calendars for Espionage
Group-IB has identified HOLLOWGRAPH, a sophisticated Windows malware that abuses the Microsoft Graph API to covertly exfiltrate files and receive commands through compromised Microsoft 365 calendar events. The malware…
10 articles · Updated July 20, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
US Charges Russian Hacker for Facilitating Void Blizzard Cyber Espionage Campaign
Denis Obrezko, a 36-year-old Russian national, was arrested in Thailand and extradited to the US, where he faces charges for facilitating a cyber espionage campaign linked to the group Void Blizzard. This group has…
8 articles · Updated June 10, 2026 -
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These…
74 articles · Updated September 8, 2026 -
Critical RabbitMQ Vulnerabilities Enable Broker Takeover via OAuth Secrets
Miggo Security discovered two critical vulnerabilities in RabbitMQ, a widely used open-source message broker. The flaws, CVE-2026-57219 and CVE-2026-57221, were present since early 2024 and allow unauthenticated…
6 articles · Updated July 13, 2026 -
Critical miniOrange SAML SSO Vulnerabilities Allow WordPress Admin Takeover
Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) have been identified in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing unauthenticated attackers to forge…
8 articles · Updated August 24, 2026
Recent Intelligence Reports
- T1078.004 Valid Accounts: Cloud Accounts — attack.mitre.org · September 9, 2026
- Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero — Securityweek · September 8, 2026
- 2026 Cloud Security Index — www.intruder.io · September 7, 2026
- What Okta and Microsoft's Approaches Tell Us About the Future of Ident — Infosecurity-Magazine · September 4, 2026
- New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password — Itsecurityguru · September 2, 2026
- Inside Knight Office, a New M365 AiTM Phishing Kit — Huntress · September 2, 2026
- Hackers target WordPress sites in miniOrange auth bypass attacks — Bleepingcomputer · August 24, 2026
- [SecurityIntel] 22 Aug | GitLab CVE-2026-19478 Under Active Exploitation — Buttondown · August 22, 2026