Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Tropic Trooper Expands Tactics with Multi-Stage Attacks on Japanese and Taiwanese Targets
On March 12, 2026, Zscaler ThreatLabz reported a campaign by the Tropic Trooper APT targeting Chinese-speaking individuals in Taiwan, Japan, and South Korea. The attack involved a malicious ZIP archive containing…
5 articles · Updated April 24, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
Kimsuky Group Leverages AI for Malware Targeting South Korean Government
The North Korean hacking group Kimsuky is utilizing generative AI to create malware aimed at South Korean government systems, as reported by Kaspersky on May 14, 2026. The malware, named HelloDoor, is a Rust-based…
5 articles · Updated May 14, 2026 -
Kimsuky Targets South Korea with Advanced Malware and Social Engineering Tactics
North Korean hackers known as Kimsuky have launched a series of cyberattacks against South Korean military and corporate sectors during March and April 2026. The group utilized sophisticated social engineering tactics,…
2 articles · Updated May 29, 2026 -
Amazon Q Developer Vulnerability Enables Cloud Credential Theft
A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server…
11 articles · Updated June 26, 2026 -
High-Severity RCE Vulnerabilities Found in Angular Language Service Extension
Multiple high-severity vulnerabilities have been identified in the Angular Language Service extension for Visual Studio Code, potentially allowing remote code execution (RCE) attacks. These vulnerabilities stem from…
2 articles · Updated May 26, 2026 -
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products
On September 8, 2026, multiple CVEs were disclosed affecting various Microsoft products, including SharePoint and Office. Key vulnerabilities include improper access controls, buffer overflows, and command injections,…
927 articles · Updated September 8, 2026 -
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
229 articles · Updated July 1, 2026 -
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These…
67 articles · Updated September 8, 2026
Recent Intelligence Reports
- Microsoft Patch Tuesday September 2026 Security Update Review — blog.qualys.com · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026
- CVE-2026 — Api.Msrc.Microsoft · September 8, 2026