7-Zip is a tool tracked across 29 threat clusters and 45 intelligence report mentions on ThreatCluster. First observed November 1, 2025; most recent activity July 23, 2026.
Ukrainian CERT has identified a cyber campaign attributed to the UAC-0099 threat cluster, which targets organizations in Ukraine using the legitimate Notepad++ application to distribute malware. The attackers deliver a…
A remote code execution vulnerability in 7-Zip, tracked as CVE-2025-11001, is being actively exploited by attackers. This flaw allows remote attackers to execute arbitrary code on affected installations, with a CVSS…
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
A remote code execution vulnerability in 7-Zip, tracked as CVE-2025-11001, is currently being exploited by attackers. This flaw allows remote attackers to execute arbitrary code on affected installations, impacting…
An anonymous researcher known as Bikini has released exploit code for over a dozen zero-day vulnerabilities affecting 15 popular open-source projects, including the Linux kernel and Libssh2. The exploits were disclosed…
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
A critical heap buffer overflow vulnerability has been identified in 7-Zip version 26.00, allowing attackers to execute arbitrary code through a vtable hijack. This flaw, tracked as CVE-2026-48095 and assigned advisory…
A cyber espionage campaign utilizing the GoSerpent backdoor has infiltrated government networks in Southeast Asia for over five years, harvesting sensitive police and biometric data. The operation, revealed by…
China-linked cyber-espionage group Bronze Butler, also known as Tick, exploited a zero-day vulnerability in Motex Lanscope Endpoint Manager, identified as CVE-2025-61932. This critical request origin verification flaw…
In July 2026, a ClickFix campaign was discovered on the Artlist subdomain new-blog.artlist[.]io, where attackers injected malicious code that masqueraded as a CAPTCHA to install a Remote Access Trojan (RAT). The attack…