Google Cloud is a tool tracked across 50 threat clusters and 137 intelligence report mentions on ThreatCluster. First observed October 28, 2025; most recent activity July 24, 2026.
APT41, a China-backed threat group, has been identified using a new zero-detection ELF backdoor targeting Linux cloud workloads across major platforms including AWS, Google Cloud Platform, Microsoft Azure, and Alibaba…
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
On July 20, 2026, German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its developer in Indonesia. The operation neutralized over 200 servers and disrupted approximately…
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
A critical vulnerability in Linux KVM, named Januscape (CVE-2026-53359), has been discovered after lying dormant for 16 years. This flaw allows attackers with root access in a guest virtual machine to escape to the host…
Hackers have compromised Docker images and VSCode extensions for the Checkmarx KICS analysis tool, which is used to identify security vulnerabilities in source code. The attack involved a trojanized KICS Docker image…
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
A newly identified supply chain vulnerability named 'Cordyceps' affects CI/CD workflows across major platforms, allowing unauthenticated attackers to exploit Git-based repositories. Novee's research flagged 654…
Google has filed a lawsuit against the 'Outsider Enterprise', a China-based cybercrime network, for allegedly using AI tools, including its Gemini platform, to conduct large-scale phishing operations. The operation has…
In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS)…