Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical RCE Vulnerability in Windows IKE Actively Exploited
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported…
4 articles · Updated August 19, 2026 -
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as…
2 articles · Updated August 12, 2026 -
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
8 articles · Updated March 19, 2026 -
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
Global Takedown of Kratos Phishing-as-a-Service Infrastructure
On July 20, 2026, German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its developer in Indonesia. The operation neutralized over 200 servers and disrupted approximately…
17 articles · Updated July 21, 2026
Recent Intelligence Reports
- How Aitm Phishing Bypassed Mfa To Hijack A Microsoft 365 Mailbox In Bec Scheme — www.trendaisecurity.com · August 20, 2026
- [SecurityIntel] 20 Aug | AI — Buttondown · August 20, 2026
- Critical RCE flaw in Windows IKE Extension now actively exploited — Bleepingcomputer · August 19, 2026
- Warning about attacks on Microsoft IKE, SharePoint, VMware vCenter and macOS — Heise.De · August 19, 2026
- Researchers Link 'Jewelbug' Chinese APT to Hack-for — Infosecurity-Magazine · August 14, 2026
- Cybercriminals' Latest Medtech Target: Cook Medical — Mddionline · August 14, 2026
- ZDI August 2026 analysis — www.zerodayinitiative.com · August 13, 2026
- CNBC: Microsoft: Chinese hacking groups were part of SharePoint attacks — www.cnbc.com · August 13, 2026