RDP is a tool tracked across 10 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity June 30, 2026.
RDP (Remote Desktop Protocol) is a Microsoft protocol that enables remote sessions to Windows systems. In cybersecurity, attackers exploit exposed or poorly protected RDP endpoints, stolen credentials, or vulnerabilities to gain remote access, move laterally, and deploy ransomware or other malware. Its significance stems from wide deployment in enterprises and its frequent use as an initial access vector by ransomware groups, including activity tied to Akira per CISA advisories.
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
iOT365 has unveiled a new multi-vector detection model aimed at enhancing cybersecurity for critical infrastructure against emerging post-quantum threats. This innovative framework correlates various intelligence…
Advanced Persistent Threat (APT) groups are actively targeting networks within the construction industry to steal remote access credentials, specifically RDP, SSH, and Citrix logins. This campaign poses significant…
A significant increase in cybercrime involving physical violence has been reported across Europe, with at least 18 cases documented since the beginning of the year. This trend, termed 'violence as a service,' has been…
Advanced Persistent Threat (APT) groups are actively targeting construction industry networks to steal Remote Desktop Protocol (RDP), Secure Shell (SSH), and Citrix credentials. This campaign poses significant risks to…
The Vortex Werewolf cyber espionage group has been actively targeting Russian government and defense organizations since at least December 2025. This group utilizes social engineering and legitimate software utilities…
Research by Zero Networks published on February 4, 2026, indicates that the primary cybersecurity risks for businesses stem from legitimate internal access rather than zero-day exploits or specialized malware. The…
In 2025, there has been a significant rise in the abuse of ScreenConnect and other remote monitoring and management (RMM) tools by threat actors. Organizations using outdated or unpatched versions of these tools are…
On June 29, 2026, Offensive Security released Kali Linux 2026.2, introducing nine new tools and significant improvements to VM boot times. The update includes enhancements to the GNOME 50 and KDE Plasma 6.6 desktop…
In 2025, Europe has experienced a significant rise in cybercrime involving physical violence, with at least 18 reported cases. This trend, termed 'violence as a service,' began in 2024 and has been particularly…