Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…
9 articles · Updated June 13, 2026 -
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
24 articles · Updated June 18, 2026 -
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
A critical vulnerability, CVE-2026-42945, has been discovered in the NGINX web server's ngx_http_rewrite_module, allowing unauthenticated attackers to execute remote code or crash servers. This heap-based buffer…
51 articles · Updated May 13, 2026 -
Critical NGINX UI Vulnerability CVE-2026-33032 Under Active Exploitation
A critical vulnerability in the nginx-ui web server management tool, tracked as CVE-2026-33032, has been actively exploited since March 2026. This flaw allows attackers to bypass authentication on the /mcp_message…
22 articles · Updated April 15, 2026 -
Critical Vulnerabilities in Sangoma Switchvox Exploited for Remote Code Execution
Sangoma Switchvox SMB Edition 8.3 (104997) has multiple vulnerabilities, including CVE-2026-9586, a critical unauthenticated SQL injection flaw allowing remote code execution. This vulnerability enables attackers to…
2 articles · Updated September 2, 2026 -
Critical RCE Vulnerability in Divi Form Builder Plugin for WordPress
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload, allowing Remote Code Execution in all versions up to 5.1.8. This vulnerability arises from insufficient file extension validation in the…
9 articles · Updated July 3, 2026 -
Belarusian Hackers Target Yury Hubarevich with Sophisticated Phishing Attack
On May 29, 2026, Yury Hubarevich, a prominent Belarusian politician, was targeted in a phishing attack linked to the Belarusian espionage group UNC1151. The attack involved an email disguised as a Google notification,…
11 articles · Updated June 5, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
APT28 (Fancy Bear) has been linked to Operation Roundish, utilizing a comprehensive Roundcube exploitation toolkit against Ukrainian government targets. The toolkit, discovered in January 2026, includes XSS payloads, a…
3 articles · Updated July 23, 2026
Recent Intelligence Reports
- Switchvox Post — labs.sra.io · September 2, 2026
- Oracle Linux 9 Nginx Key Denial of Service Vulnerability ELSA-2026 — Linuxsecurity · August 27, 2026
- Oracle Linux 8 Nginx Vulnerability Could Lead to Memory Disclosure Risk — Linuxsecurity · August 27, 2026
- Oracle Linux 10 ELSA-2026 — Linuxsecurity · August 26, 2026
- The Outsider Part 1 Pulling One Thread On A 1 9 Billion Phishing Machine — tapetumlabs.com · August 14, 2026
- Breakglass Intelligence's March 2026 analysis — intel.breakglass.tech · August 12, 2026
- Fedora 43 GoAccess 1.11 Important Buffer Overflow Fix 2026 — Linuxsecurity · August 3, 2026
- Flying Eagle — hunt.io · July 30, 2026