Putty is a tool tracked across 17 threat clusters and 19 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity July 22, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
A study by Semperis reveals that 52% of ransomware attacks target organizations during holidays and weekends, exploiting reduced cybersecurity staffing. The report surveyed 1,500 IT and security professionals across ten…
On May 25, 2026, Fedora released updates for Putty addressing multiple security vulnerabilities, including CVE-2026-48850, a double free vulnerability in RSA KEX code, CVE-2026-48851, which affects TELNET session data,…
The Adaptavist Group, a UK enterprise software consultancy, is investigating a security breach that occurred in late March 2026, when an attacker gained unauthorized access using stolen credentials. CEO Simon…
Cybercriminals are distributing the Oyster backdoor malware disguised as popular office tools, including Microsoft Teams and Google Meet. This campaign, targeting individuals in the financial sector, has been active…
The pkr_mtsi malware loader has been upgraded to incorporate advanced stealth techniques, including hashed API resolution and improved obfuscation. Initially observed in April 2025, it is utilized for deploying various…
The Windows packer pkr_mtsi has been identified as a tool for executing extensive malvertising campaigns that deliver various malware families. First detected on April 24, 2025, it distributes trojanized installers…
Hackers are exploiting a critical unauthenticated access vulnerability (CVE-2025-12480) in Gladinet's Triofox file-sharing platform. This flaw allows attackers to bypass authentication and gain administrative access,…