Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Head Mare Hackers Exploit TrueConf Vulnerabilities to Deploy Backdoors
The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed…
23 articles · Updated August 8, 2026 -
Iranian Hackers Target US Aviation with New Malware and SEO Poisoning
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
6 articles · Updated May 26, 2026 -
Ripple Shares North Korean Threat Intelligence to Combat Evolving Cyber Attacks
On May 5, 2026, Ripple announced it will share internal threat intelligence regarding North Korean hackers with Crypto ISAC, aimed at enhancing security across the cryptocurrency industry. This initiative follows a…
19 articles · Updated May 5, 2026 -
Bybit Sues North Korea Over $1.5 Billion Crypto Theft
Bybit has filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, accusing them of orchestrating a $1.5 billion hack in February 2025. The lawsuit, filed in the U.S. District…
23 articles · Updated August 8, 2026 -
North Korea's Lazarus Group Exploits Crypto Gaps, $6.75 Billion Stolen
In 2025 and the first half of 2026, North Korea's Lazarus Group has been a major threat in the cryptocurrency sector, responsible for approximately $6.75 billion in theft. The group has exploited vulnerabilities in the…
4 articles · Updated July 27, 2026 -
BlueNoroff Targets Cryptocurrency Executives with AI-Enhanced Fake Zoom Attacks
North Korea's BlueNoroff group is executing a sophisticated campaign against cryptocurrency executives, utilizing fake Zoom meetings enhanced with AI-generated avatars and stolen video footage. The attacks primarily…
6 articles · Updated April 29, 2026 -
Hack-for-Hire Campaign Targets Journalists in MENA Using Phishing and Spyware
A hack-for-hire operation has been uncovered targeting journalists and activists across the Middle East and North Africa, particularly focusing on Egyptian and Lebanese individuals. The campaign, attributed to a group…
18 articles · Updated April 8, 2026 -
Russian UAT-11795 Targets Users with Trojans in Legitimate Software
A Russian threat actor known as UAT-11795 has been deploying the Starland RAT and WLDR agent since June 2025, primarily targeting users in the U.S., Germany, Romania, and Venezuela. The group uses trojanized installers…
6 articles · Updated July 17, 2026 -
Critical Zoom Command Injection Vulnerability Allows Remote Code Execution
A critical command injection vulnerability in Zoom's Node Multimedia Routers (MMRs), tracked as CVE-2026-22844, has been disclosed. This flaw could permit meeting participants to execute arbitrary code on affected…
3 articles · Updated January 21, 2026
Recent Intelligence Reports
- AI-generated video of Singapore PM Lawrence Wong used in $3.8M fraud — Cryptobriefing · August 23, 2026
- How scammers built a fake Zoom call from real videos of PM Wong and other Singapore leaders — Channelnewsasia · August 22, 2026
- Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it — Theregister · August 21, 2026
- North Korean state-sponsored hackers — www.chainalysis.com · August 18, 2026
- Targeted Campaign Us Law Firms — cloud.google.com · August 16, 2026
- DETECT-World, a new detection model — www.resemble.ai · August 13, 2026
- [SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched — Buttondown · August 12, 2026
- CVE-2026-53415 — nvd.nist.gov · August 12, 2026