Related Threat Clusters
-
WantToCry Ransomware Campaign Targets Exposed SMB Services for Remote Encryption
The WantToCry ransomware campaign exploits exposed Server Message Block (SMB) services to remotely encrypt files without deploying malware on victim systems. Attackers scan for open SMB ports and use brute-force methods…
6 articles · Updated May 20, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1484 articles · Updated February 9, 2026 -
Credential Stuffing Botnet Exposed with Full Access to Attack Infrastructure
A credential stuffing botnet targeting Twitter/X accounts has been discovered fully exposed online, allowing unrestricted access to its command-and-control infrastructure. The botnet, named 'Twitter Checker Master Panel…
2 articles · Updated April 14, 2026 -
Threat Actor Exploits Vulnerabilities to Abuse Elastic Cloud SIEM for Data Theft
Cybersecurity researchers from Huntress have uncovered a campaign where a threat actor exploited multiple software vulnerabilities, including the SolarWinds Web Help Desk, to exfiltrate data to a free trial instance of…
2 articles · Updated March 9, 2026 -
Microsoft Confirms Reboot Loops in Windows Servers After April 2026 Updates
Microsoft has acknowledged that certain Windows domain controllers are experiencing continuous reboot loops following the installation of the April 2026 security updates (KB5082063 and KB5082142). This issue primarily…
16 articles · Updated April 17, 2026 -
Microsoft Windows Updates Cause Access Issues for Cloud PC Users
Microsoft's January 2026 updates have led to significant access issues for users of Windows 365 and RemoteApp connections. Customers reported credential prompt failures and sign-in issues with their Cloud PC sessions…
9 articles · Updated January 15, 2026 -
Microsoft Defender Update Addresses Security Gaps in Windows Installations
Microsoft has released a new update for Windows Defender, specifically targeting outdated anti-malware definitions in Windows installation images. This update, identified as security intelligence update version…
4 articles · Updated April 5, 2026 -
Microsoft Resolves Windows Autopatch Driver Update Bug in EU
Microsoft has addressed a bug in its Windows Autopatch service that inadvertently deployed restricted driver updates on certain Windows devices in the European Union. The issue specifically impacted devices running…
2 articles · Updated May 14, 2026
Recent Intelligence Reports
- Picus Security: BlueHammer & RedSun — www.picussecurity.com · May 21, 2026
- WantToCry ransomware evades detection through SMB abuse, remote encryption — Scworld · May 20, 2026
- Microsoft fixes Windows Autopatch bug installing restricted drivers — Bleepingcomputer · May 13, 2026
- Microsoft: Some Windows servers enter reboot loops after April patches — Bleepingcomputer · April 17, 2026
- Botnet Exposed: Hackers Leave Worker Access and Root Passwords Wide Open — Gbhackers · April 14, 2026
- Microsoft releases new Defender update for Windows 11, 10, Server ISO installations — Neowin · April 5, 2026
- Threat Actor Exploits Flaws and Uses Elastic Cloud SIEM to Manage Stolen Data — Infosecurity-Magazine · March 9, 2026
- Windows Update side effects: Connection errors with Windows 365 — Heise.De · January 15, 2026