Related Threat Clusters
-
Microsoft Office 0-day Vulnerability CVE-2026-21509 Exploited; Emergency Fix Released
Microsoft Office 2016 to 2024 and Office 365 apps are affected by a zero-day vulnerability (CVE-2026-21509) that is currently being exploited in attacks. Microsoft has released emergency security updates to address this…
7 articles · Updated January 27, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Exploitation of WinRAR CVE-2025-8088 Threatens Ukrainian Organizations
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
19 articles · Updated June 8, 2026 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Cloud Atlas APT Targets Russia and Belarus with New Tools and Techniques
Cloud Atlas, an advanced persistent threat group, has intensified its cyberespionage activities against government and commercial entities in Russia and Belarus since late 2025. The group employs phishing emails…
2 articles · Updated May 23, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products
On September 8, 2026, multiple CVEs were disclosed affecting various Microsoft products, including SharePoint and Office. Key vulnerabilities include improper access controls, buffer overflows, and command injections,…
927 articles · Updated September 8, 2026 -
Microsoft March 2026 Patch Tuesday Addresses 79 Vulnerabilities, Including Zero-Days
On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively…
51 articles · Updated March 10, 2026 -
Critical Microsoft Office Vulnerability Enables Remote Code Execution
On March 10, 2026, Microsoft published security updates for a critical vulnerability in its Office suite, identified as CVE-2026-26110. This flaw allows unauthorized attackers to execute malicious code remotely on…
4 articles · Updated March 11, 2026
Recent Intelligence Reports
- Microsoft Patch Tuesday Hits Record 974 CVEs, Two Exploited — Thecyberexpress · September 9, 2026
- Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero — Cybersecuritynews · September 8, 2026
- Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880) — Tenable · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026