Related Threat Clusters
-
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
Cisco has disclosed a critical authentication bypass vulnerability, CVE-2026-20182, affecting its Catalyst SD-WAN Controller and Manager. This flaw allows unauthenticated remote attackers to bypass authentication and…
131 articles · Updated May 14, 2026 -
Critical cPanel Vulnerability Exploited in Southeast Asia Cyber Attacks
A sophisticated cyber campaign has exploited a critical cPanel vulnerability (CVE-2026-41940) to breach government and military servers in Southeast Asia, particularly targeting Indonesia. The attackers utilized a…
3 articles · Updated May 4, 2026 -
China-Nexus Hackers Target Hospitals and Governments with TriBack Loader Malware
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
2 articles · Updated July 23, 2026 -
New PoC Exploit for NTLM Reflection Bypass Vulnerability on Windows Server
A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability…
3 articles · Updated June 30, 2026 -
Cruciferra Crypter Service Powers Multiple Cybercrime Campaigns
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
8 articles · Updated July 20, 2026 -
Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
8 articles · Updated April 17, 2026 -
Hacktivist Groups Expand Attacks Beyond Russia to Middle East and Central Asia
Hacktivist groups 4BID, Hakerskii Kit, and C.A.S. have broadened their attack geography, targeting organizations in Kazakhstan, the UAE, Syria, and Egypt, moving beyond their previous focus on Russian and Belarusian…
2 articles · Updated June 9, 2026 -
AdaptixC2 Misused in Ransomware Operations Worldwide
Cybercriminals are increasingly exploiting AdaptixC2, a free emulation framework initially designed for penetration testing, for malicious payload delivery in ransomware attacks. This trend follows the release of new…
1 article · Updated October 31, 2025 -
AdaptixC2 Framework Misused in Ransomware Operations
Cybercriminals are exploiting AdaptixC2, an open-source Command and Control framework originally designed for penetration testing, for ransomware attacks. Recent research indicates a rise in its use for malicious…
1 article · Updated October 31, 2025 -
Kali Linux 2026.1 Released with New Tools and BackTrack Mode
On March 25, 2026, Kali Linux 2026.1 was officially released, introducing eight new tools and a refreshed visual theme. This update includes a new 'BackTrack mode' in Kali-Undercover, allowing users to recreate the look…
6 articles · Updated March 25, 2026
Recent Intelligence Reports
- Jadeprox China Nexus Triback Loader — www.group-ib.com · July 24, 2026
- China-Nexus Hackers Breached Hospital X-Rays, Embassy, and Congress With New ... — Techtimes · July 23, 2026
- Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service — Proofpoint · July 20, 2026
- PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on ... — Gbhackers · June 30, 2026
- Hacktivists are broadening their scope beyond political motivation — Securelist · June 8, 2026
- Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) — Tenable · May 14, 2026
- Ongoing exploitation of Cisco Catalyst SD — Blog.Talosintelligence · May 14, 2026
- SEA CPanel — ctrlaltintel.com · May 5, 2026