Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors
A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of…
12 articles · Updated September 9, 2026 -
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
40 articles · Updated September 2, 2026 -
GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain
The GhostShell malware cluster is actively targeting Ukraine’s UAV operations and defense supply chain. Utilizing advanced techniques such as mTLS-authenticated implants and Telegram-based loaders, the attackers gain…
2 articles · Updated June 25, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and…
7 articles · Updated August 11, 2026 -
UAT-7810 Expands Malware Arsenal to Enhance ORB Network
The China-linked threat actor UAT-7810 is evolving its malware toolkit, notably introducing LONGLEASH, an upgraded version of the SHORTLEASH backdoor. This group exploits known vulnerabilities in unpatched Ruckus…
12 articles · Updated July 7, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026 -
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026
Recent Intelligence Reports
- Four Nation-State Actors Used the Same Chrome Zero — Securityaffairs.Co · September 10, 2026
- Multiple Chinese hacking groups seen using identical Chrome zero — Therecord.Media · September 9, 2026
- Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero — Proofpoint · September 9, 2026
- CVE-2026-82533: DeepSeek Harness AI Agent Sandbox Escape — Ox.Security · September 9, 2026
- MacSync Stealer Uses ClickFix and Chunked Exfiltration — Socprime · September 9, 2026
- New Xcsset Malware Adds New Obfuscation Persistence Techniques To Infect Xcode Projects — www.microsoft.com · September 9, 2026
- HackerOne Bug Bounty Disclosure: -cve-fix-incomplete-for-aws-lc-cert-status-bypass-on-sectrust-path — Redpacketsecurity · September 8, 2026
- APTSimulator exploit — Sploitus · September 8, 2026