Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…
9 articles · Updated June 13, 2026 -
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as…
2 articles · Updated July 21, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
Cloud Atlas APT Group Exploits CVE-2018-0802 and Modifies termsrv.dll for RDP Access
The Cloud Atlas APT group has been observed employing a sophisticated cyber espionage campaign targeting government and commercial entities in Russia and Belarus. This campaign, active since 2025 and continuing into…
4 articles · Updated May 25, 2026 -
Cloud Atlas APT Targets Russia and Belarus with New Tools and Techniques
Cloud Atlas, an advanced persistent threat group, has intensified its cyberespionage activities against government and commercial entities in Russia and Belarus since late 2025. The group employs phishing emails…
2 articles · Updated May 23, 2026 -
Critical Vulnerabilities in Fedora's OpenSSH and libssh Libraries
Recent updates for Fedora's OpenSSH and libssh libraries address critical vulnerabilities. CVE-2026-59996 and CVE-2026-60002, published on July 8, 2026, involve file misplacement and use-after-free issues in OpenSSH.…
5 articles · Updated July 23, 2026 -
Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766
In June 2026, a surge in attacks targeting SonicWall Gen 7 firewalls has been reported, exploiting CVE-2024-40766, an improper access control flaw. This vulnerability allows threat actors to gain unauthorized access,…
2 articles · Updated June 23, 2026 -
Critical OpenSSH Vulnerabilities Affecting Multiple Ubuntu Versions
Multiple vulnerabilities in OpenSSH have been discovered, affecting Ubuntu 22.04 LTS and its derivatives. Key issues include improper handling of the legacy scp protocol, which could lead to unintended setuid or setgid…
2 articles · Updated April 29, 2026
Recent Intelligence Reports
- Why Chasing CVSS Scores Is Failing the Security Team — Cybersift · August 31, 2026
- Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel — Infosecurity-Magazine · August 26, 2026
- CVE-2024-6387 — nvd.nist.gov · August 13, 2026
- Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure — Infosecurity-Magazine · August 12, 2026
- Gunra Ransomware Hit Hospitals and Governments; Linux Victims Should Not Pay Ransom — Techtimes · August 11, 2026
- OpenSSH 10.5 fixes ssh-agent lock bypass that exposed local — Feeds.4Sysops · August 11, 2026
- Locking your ssh-agent exposed local — Feeds2.Feedburner · August 11, 2026
- 115909 — securelist.ru · July 30, 2026