Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
20 articles · Updated August 30, 2026 -
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
2 articles · Updated June 5, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Critical Januscape Vulnerability in Linux KVM Exposes Cloud Servers to Attacks
A critical vulnerability in Linux KVM, named Januscape (CVE-2026-53359), has been discovered after lying dormant for 16 years. This flaw allows attackers with root access in a guest virtual machine to escape to the host…
31 articles · Updated July 7, 2026 -
Toy Ghouls Launch GenieLocker Ransomware Targeting Russian Manufacturing
The Toy Ghouls group, also known as Bearlyfy, has introduced a new ransomware called GenieLocker, active since March 2026. This ransomware targets Windows, Linux, and VMware ESXi systems, primarily affecting the…
5 articles · Updated July 30, 2026 -
Foxconn Cyberattack: Nitrogen Ransomware Claims 8TB of Data Theft
Foxconn confirmed a cyberattack on its North American facilities, attributed to the Nitrogen ransomware group, which claims to have stolen 8 terabytes of data, including over 11 million files. The attack reportedly…
54 articles · Updated May 12, 2026 -
Teen Hacker Extradited for Role in Scattered Spider Cybercrime Group
Peter Stokes, a 19-year-old dual citizen of the U.S. and Estonia, was extradited from Finland to the U.S. to face charges related to his involvement in the Scattered Spider hacking group. The group has been linked to…
37 articles · Updated July 1, 2026 -
Kyber Ransomware Targets Windows and VMware ESXi Systems
The Kyber ransomware group has launched a coordinated attack targeting both Windows file servers and VMware ESXi systems. In March 2026, cybersecurity firm Rapid7 analyzed two variants of the ransomware deployed in the…
3 articles · Updated April 22, 2026 -
Chinese Hackers Exploit Dell Zero-Day Flaw CVE-2026-22769 Since Mid-2024
A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw, tracked as CVE-2026-22769, features a…
40 articles · Updated February 17, 2026
Recent Intelligence Reports
- Sygnia Reveals New Activity by China — Morningstar · August 30, 2026
- Sygnia Reveals New Activity by China — Sg.Finance.Yahoo · August 30, 2026
- Aurora ransomware actors leverage AI tool for exploitation campaigns | brief — Scworld · August 28, 2026
- Hackers from the Russian — Mezha.Ua · August 28, 2026
- Hackers used Cursor AI to hack into at least 10 companies - Межа — Mezha.Ua · August 28, 2026
- Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations — Infosecurity-Magazine · August 28, 2026
- LockBit 5.0 targets U.S. Bank, one of the largest banks in the United States — Escudodigital · August 20, 2026
- AvosLocker — www.sophos.com · August 12, 2026