Netcat is a tool tracked across 12 threat clusters and 15 intelligence report mentions on ThreatCluster. First observed January 20, 2026; most recent activity July 24, 2026.
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
The China-linked threat actor UAT-7810 is evolving its malware toolkit, notably introducing LONGLEASH, an upgraded version of the SHORTLEASH backdoor. This group exploits known vulnerabilities in unpatched Ruckus…
A China-linked cyber espionage operation has compromised a Vietnamese public hospital's imaging systems, infiltrated Malaysia's Ministry of Foreign Affairs, and targeted Honduras's National Congress using a new malware…
A critical vulnerability in the marimo Python notebook platform, tracked as CVE-2026-39987, has been actively exploited to deploy a new variant of NKAbuse malware. The flaw allows for remote code execution without…
Two critical vulnerabilities, CVE-2026-20761 and CVE-2026-22885, were discovered in EnOcean's SmartServer IoT platform, affecting versions 4.60.009 and earlier. CVE-2026-20761 allows remote attackers to execute…
Anthropic's Claude Code AI platform has been found to have a critical network sandbox bypass vulnerability, allowing attackers to exfiltrate sensitive data, including user credentials and source code. Discovered by…
A Linux user attempted to use OpenAI's Codex AI agent for incident response during a cyberattack but faced significant challenges. The user was unaware that at least two threat actors had compromised their system,…
Security researchers have identified that SuperBox Android TV streaming devices, marketed as cost-effective media solutions, may secretly convert users' internet connections into proxy nodes for cybercriminal…
Recent research by Cisco Talos reveals that attackers are increasingly leveraging native macOS features to execute code and move laterally within enterprise environments. With over 45% of organizations now using macOS,…
The ShadowHS malware framework has been identified as a significant threat to Linux environments, utilizing a fileless architecture for stealthy operations. Discovered by Cyble Research & Intelligence Labs on January…