Related Threat Clusters
-
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as…
2 articles · Updated August 12, 2026 -
Warlock Ransomware Group Enhances Attack Techniques with BYOVD and Remote Access Tools
The Warlock ransomware group, also known as Water Manaul, has escalated its attack methods by exploiting unpatched Microsoft SharePoint servers and employing new tactics for persistence and lateral movement. Recent…
5 articles · Updated March 16, 2026 -
Qilin and Warlock Ransomware Exploit Vulnerable Drivers to Compromise EDR Tools
Qilin and Warlock ransomware variants have been identified exploiting vulnerable drivers to disable over 300 endpoint detection and response (EDR) tools. This exploitation allows the ransomware to evade detection and…
2 articles · Updated April 6, 2026 -
Ransomware Tactics Evolve: EDR Killers Expand Beyond Vulnerable Drivers
Recent research from ESET reveals that ransomware attackers are increasingly using EDR killers to disable endpoint detection and response (EDR) systems before launching their encryptors. These tools have become standard…
18 articles · Updated March 19, 2026 -
Payroll Pirate Campaign Targets Payroll Systems Using AiTM Session Hijacking
The 'Payroll Pirate' campaign has emerged, utilizing advanced phishing and AiTM session hijacking to bypass MFA and reroute payroll disbursements. Targeting mid-market and enterprise organizations, attackers exploit…
2 articles · Updated June 15, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Phishing and Authentication Abuse Surge in Cybersecurity Incidents
In Q2 2026, phishing attacks accounted for over 50% of cybersecurity incident response engagements, according to Cisco Talos. This marks an increase from approximately 35% in the previous quarter. Authentication abuse…
2 articles · Updated September 2, 2026 -
Eurofiber France Data Breach Exposes Sensitive Corporate Data
Eurofiber France has confirmed a significant data breach linked to a ransomware group, which has reportedly exposed sensitive corporate data now circulating on the darknet. The company is collaborating with…
7 articles · Updated November 18, 2025 -
Eurofiber France Reports Data Theft Following Cyberattack
Eurofiber France confirmed that cybercriminals accessed and stole data from its systems during a cyberattack on November 13, 2025. The breach targeted a vulnerability in the company's ticket management platform,…
2 articles · Updated November 17, 2025 -
Warlock Ransomware Exploits ToolShell SharePoint Vulnerabilities
Warlock ransomware has been deployed through vulnerabilities in ToolShell SharePoint. Organizations using affected SharePoint versions are at risk, as the ransomware exploits chained vulnerabilities to gain access.…
2 articles · Updated October 30, 2025
Recent Intelligence Reports
- ID-based attacks rife as phishing, authentication abuse on the rise - IT — It-Online.Co.Za · September 2, 2026
- CyberScoop: Microsoft SharePoint attacks ensnare 400 victims, including US agencies — cyberscoop.com · August 13, 2026
- Payroll Pirate Campaign Uses AiTM Session Hijacking to Bypass MFA and Redirect Salaries — Gbhackers · June 15, 2026
- Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools — Thehackernews · April 6, 2026
- EDR killers explained: Beyond the drivers — Welivesecurity · March 19, 2026
- Warlock Ransomware Group Augments Post — Darkreading · March 17, 2026
- ESET Threat Report H2 2025 — Feeds.Feedburner · December 16, 2025
- Eurofiber admits crooks swiped data from French unit after cyberattack — Theregister · November 17, 2025