RClone is a tool tracked across 17 threat clusters and 27 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity July 22, 2026.
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
The Gamaredon group, a Russian-aligned APT, has significantly upgraded its cyber capabilities in 2025, focusing on spear-phishing campaigns against Ukrainian targets. ESET Research reports that Gamaredon conducted 35…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
Operation CamelClone is a sophisticated cyber espionage campaign targeting government agencies and defense institutions in Algeria, Mongolia, Ukraine, and Kuwait. The attackers use spear-phishing emails containing…
The Warlock ransomware group, also known as Water Manaul, has escalated its attack methods by exploiting unpatched Microsoft SharePoint servers and employing new tactics for persistence and lateral movement. Recent…
In March 2026, the Trigona ransomware group, which operates as a Ransomware-as-a-Service (RaaS), utilized a newly developed custom tool named 'uploader_client.exe' to enhance their data exfiltration capabilities. This…
The Gentlemen ransomware group has emerged as a significant threat in 2026, exploiting vulnerabilities in Fortinet systems, particularly CVE-2024-55591, an authentication bypass flaw. They have been observed using…
In July 2026, the ransomware group World Leaks leaked approximately 19,000 files related to India's Kudankulam Nuclear Power Plant on the dark web. The data, allegedly sourced from Reliance Group, includes blueprints,…
Cyber attackers are increasingly using Microsoft Teams to impersonate IT helpdesk staff, employing social engineering tactics to gain remote access to enterprise systems. This method, known as 'cross-tenant helpdesk…