Related Threat Clusters
-
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
Bulgaria's Circles Exports Surveillance Tech to Rights Violators
Between 2018 and 2023, Bulgaria licensed the export of surveillance technology from Circles, a company linked to NSO Group, to various countries with histories of human rights abuses. Human Rights Watch revealed that…
9 articles · Updated June 19, 2026 -
Exposed DICOM Servers Risk Patient Data Across Healthcare Systems
A cybersecurity investigation revealed that over 3,800 DICOM servers are exposed to the internet, compromising the personal health information of approximately 16 million patients across more than 110 countries. The…
4 articles · Updated May 5, 2026 -
WantToCry Ransomware Campaign Targets Exposed SMB Services for Remote Encryption
The WantToCry ransomware campaign exploits exposed Server Message Block (SMB) services to remotely encrypt files without deploying malware on victim systems. Attackers scan for open SMB ports and use brute-force methods…
6 articles · Updated May 20, 2026 -
Gentlemen RaaS Leak Exposes 10% of 2026's Ransomware Victims
On May 4, 2026, a leak of internal communications from The Gentlemen Ransomware-as-a-Service (RaaS) operation surfaced on underground forums. The leak, which included chats and backend data from November 2025 to April…
2 articles · Updated May 14, 2026 -
CISA Warns of Active Exploitation of Oracle Identity Manager Vulnerability CVE-2025-61757
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, is being actively exploited in the wild. This flaw…
31 articles · Updated November 26, 2025 -
Oracle Identity Manager RCE Vulnerability Exploited in Active Attacks
A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively…
19 articles · Updated November 21, 2025 -
Five Plead Guilty in North Korean IT Worker Fraud Scheme
Five individuals have pleaded guilty to facilitating North Korean operatives in obtaining remote IT jobs at U.S. companies by using false and stolen identities. The U.S. Department of Justice has also seized $15 million…
39 articles · Updated November 17, 2025 -
Emergence of Agentic AI Raises Governance and Security Challenges
In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of…
4432 articles · Updated February 10, 2026
Recent Intelligence Reports
- Unspecified actors making AI — Feeds.Feedburner · August 20, 2026
- 005 — attack.mitre.org · August 20, 2026
- Feds Confirm AI Is Writing Exploits for Siemens PLCs Used in Water and Energy — Techtimes · August 20, 2026
- ICS Operators Warned of AI — Infosecurity-Magazine · August 20, 2026
- 'Not a theoretical risk,' feds warn as attackers use AI — Theregister · August 19, 2026
- Cisco Talos, which tracks the same group under the alias Static Tundra — blog.talosintelligence.com · July 14, 2026
- Running In Circles Uncovering The Clients Of Cyberespionage Firm Circles — citizenlab.ca · June 19, 2026
- Best Dox Software – 2026 Buyer's Guide — Wifitalents · June 16, 2026