Related Threat Clusters
-
Active Exploitation of N-able N-central Authentication Bypass Vulnerability
N-able has issued an emergency hotfix for CVE-2026-18577, an authentication bypass vulnerability in its N-central RMM platform, which allows remote, unauthenticated attackers to gain administrative access. This flaw…
12 articles · Updated August 5, 2026 -
Warlock Ransomware Group Enhances Attack Techniques with BYOVD and Remote Access Tools
The Warlock ransomware group, also known as Water Manaul, has escalated its attack methods by exploiting unpatched Microsoft SharePoint servers and employing new tactics for persistence and lateral movement. Recent…
5 articles · Updated March 16, 2026 -
AI-Driven Botnet Migration by Russian Actor in Just Six Minutes
A Russian-speaking threat actor known as 'bandcampro' utilized AI to migrate a command-and-control (C&C) botnet in just six minutes, performing only 11% of the work manually. The operation targeted eight computers in a…
21 articles · Updated July 14, 2026 -
Multiple Attackers Exploit Unpatched SharePoint Servers, Microsoft Reports
Microsoft's DART team discovered two distinct threat actors operating simultaneously within the same victim network, complicating incident response efforts. The investigation began with ransomware activity linked to…
5 articles · Updated June 23, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1887 articles · Updated February 12, 2026 -
Chinese Hackers Exploit Windows Zero-Day to Target European Diplomats
A China-linked hacking group, UNC6384, has exploited a Windows zero-day vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks, which occurred in…
18 articles · Updated November 3, 2025 -
Chinese Hackers Exploit Windows Vulnerability to Target European Diplomats
A Chinese-linked hacking group, UNC6384, has been exploiting a Windows shortcut vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks involve spear…
4 articles · Updated October 31, 2025
Recent Intelligence Reports
- Active exploitation of N-able N-central authentication bypass flaw — Fieldeffect · August 5, 2026
- New Spirals ransomware can lock down an entire network in under 24 hours — Pcquest · July 16, 2026
- 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes — Theregister · July 14, 2026
- Unpatched SharePoint servers opened the door to multiple attackers, Microsoft finds — Csoonline · June 23, 2026
- Warlock Ransomware Group Augments Post — Darkreading · March 17, 2026
- Chinese hackers target Western diplomats using hard-to — Csoonline · October 31, 2025