Related Threat Clusters
-
MonikerLink RCE Vulnerability in Outlook Exploited with PoC Release
The MonikerLink vulnerability in Microsoft Outlook allows for remote code execution via malicious hyperlinks in emails. Discovered by Check Point Research, a proof-of-concept exploit has been released, potentially…
2 articles · Updated December 1, 2025 -
APT28 Exploits Vulnerable Routers for Global DNS Hijacking Campaign
Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000…
100 articles · Updated April 7, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
Iran-Linked Handala Group Launches Cyberattack on Stryker Medical Technology
On March 11, 2026, the Iranian-linked hacking group Handala executed a significant cyberattack on Stryker, a major U.S. medical technology company, causing a global disruption across its Microsoft environment. The…
276 articles · Updated March 11, 2026 -
Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897
Microsoft has patched a high-severity zero-day vulnerability in Exchange Server, tracked as CVE-2026-42897, which allows attackers to execute arbitrary JavaScript via crafted emails in Outlook Web Access. The flaw…
27 articles · Updated June 11, 2026 -
Project CAV3RN Enhances Espionage Tactics Using Google Apps Script and DNS
Project CAV3RN is a modular cyberespionage framework targeting organizations in Israel. Recent developments reveal its use of a sophisticated command-and-control (C2) design that dynamically combines direct HTTPS…
3 articles · Updated August 12, 2026 -
Payouts King Ransomware Uses Edgecution Malware via Malicious Edge Extension
A new ransomware campaign linked to the Payouts King group employs a malicious Microsoft Edge extension called 'Edgecution' to exploit the Chrome native messaging protocol. This attack allows the malware to escape the…
7 articles · Updated June 24, 2026 -
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
57 articles · Updated June 9, 2026 -
OAuth Client ID Spoofing Threatens Microsoft Entra Security
Cybercriminals are increasingly using OAuth client ID spoofing to conduct account enumeration against Microsoft Entra, the identity management service. This method allows attackers to infer username and password…
12 articles · Updated July 13, 2026 -
PCPJack Malware Targets TeamPCP Victims for Credential Theft
The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…
11 articles · Updated May 7, 2026
Recent Intelligence Reports
- Grandoreiro Banking Trojan Unleashed — www.ibm.com · August 20, 2026
- Project CAV3RN Uses Google Apps Script and DNS to Hide C2 Traffic in Israeli Cyberespionage Attacks — Gbhackers · August 12, 2026
- Microsoft Outlook Vulnerability Allows Attackers to Execute Malicious Code Remotely — Cybersecuritynews · August 12, 2026
- OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration — Proofpoint · July 13, 2026
- Malicious Edge extension abuses Native Messaging as bridge to malware — Bleepingcomputer · June 24, 2026
- Exploiting Cve 2023 23397 Microsoft Outlook Elevation Of Privilege Vulnerability — www.mdsec.co.uk · June 17, 2026
- Rapid7 Analysis: CVE-2023 — Rapid7 · June 17, 2026
- June 2026 Monthly Patch — Csa.Sg · June 10, 2026