NordVPN — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
December 6, 2025
Last Seen
August 4, 2026

Related Threat Clusters

  • Iranian APT Group Conducts Password Spray Attacks on Microsoft 365 Accounts

    In March 2026, a suspected Iranian APT group, identified as Gray Sandstorm, initiated a password spraying campaign targeting Microsoft 365 accounts of over 300 organizations in Israel and more than 25 in the UAE. The…

    9 articles · Updated April 1, 2026
  • Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks

    In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…

    10 articles · Updated July 6, 2026
  • Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching

    BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…

    1125 articles · Updated February 9, 2026
  • NordVPN Denies Breach Claims of Salesforce Server Leak

    NordVPN has denied claims of a breach involving its internal Salesforce development servers. A threat actor known as '1011' alleged that they accessed sensitive data, but NordVPN stated that only 'dummy data' from a…

    11 articles · Updated January 5, 2026
  • Israel's Cyber Operation Targets Iranian Supreme Leader Khamenei

    Israel conducted a cyber operation to hack Tehran's traffic cameras, allowing them to monitor the movements of Iran's supreme leader, Ali Khamenei, and his bodyguards. This intelligence gathering was part of a broader…

    69 articles · Updated March 2, 2026
  • Malware Injected into Banking Apps Compromises User Security

    Cybercriminals are injecting malicious code into legitimate mobile banking applications, leading to user data theft and financial fraud. Attackers are decompiling these apps, embedding trojans and backdoors, and…

    4 articles · Updated December 6, 2025
  • Global Spam Wave Targets Users via Unsecured Zendesk Systems

    A massive spam wave has emerged, affecting users worldwide through unsecured Zendesk support systems. Starting on January 18, 2026, victims reported receiving hundreds of emails with unusual subject lines, although the…

    2 articles · Updated January 21, 2026
  • NordVPN Hack Claims Refuted by Company

    NordVPN has refuted claims made by a hacker named 1011, who alleged that the company was hacked. This follows a previous refutation of claims by another group, ScatteredLapsus$Hunters, regarding a different firm,…

    2 articles · Updated January 7, 2026

Recent Intelligence Reports

  • Active Exploitation of N-able N-central Vulnerabilities (CVE-2026-18556, CVE-2026-18577) — Rescana · August 4, 2026
  • MITRE ATT&CK - MuddyWater — attack.mitre.org · July 8, 2026
  • Suspected Iran-Nexus Password Spray Targets Microsoft 365 — Technadu · April 1, 2026
  • Iran targets M365 accounts with password — Theregister · March 31, 2026
  • Iranian IP Camera Targeting Escalates Cyber Warfare — Technadu · March 4, 2026
  • Zendesk ticket systems hijacked in massive global spam wave — Bleepingcomputer · January 21, 2026
  • NordVPN Hack Claim Firmly Refuted by NordVPN — Databreaches · January 7, 2026
  • NordVPN Hack Claim Firmly Refuted by NordVPN — Databreaches · January 7, 2026

CVSS v3.1 Breakdown