Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Critical Vulnerabilities in Yarbo Robot Firmware Expose Devices to Remote Attacks
AHA! disclosed three critical vulnerabilities in Yarbo robot firmware v2.3.9, identified as CVE-2026-7413, CVE-2026-7414, and CVE-2026-7415. The vulnerabilities include a hidden backdoor, hardcoded credentials, and an…
3 articles · Updated May 7, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
18 articles · Updated August 30, 2026 -
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
A Chinese threat actor known as VerdantBamboo compromised a company's network through a managed service provider (MSP) over 18 months. The initial breach involved a Linux-based Egnyte Storage Sync appliance, which was…
2 articles · Updated June 5, 2026 -
Critical RCE Vulnerability in GNU InetUtils telnetd Exposes Systems to Attacks
A critical vulnerability, CVE-2026-32746, has been discovered in the GNU InetUtils telnetd daemon, affecting all versions up to and including 2.7. This flaw allows unauthenticated remote attackers to execute arbitrary…
9 articles · Updated March 18, 2026 -
Critical Vulnerabilities in dnsmasq Expose Systems to DoS and Code Execution Risks
Multiple vulnerabilities have been identified in dnsmasq, an open-source DNS and DHCP server, affecting various Linux distributions, including Ubuntu. The vulnerabilities, tracked as CVE-2026-2291, CVE-2026-4890,…
37 articles · Updated May 13, 2026 -
Sandworm Leverages SSH-over-Tor for Covert Network Access
Sandworm (APT-C-13), a state-sponsored cyber threat group, has advanced its tactics by employing SSH-over-Tor tunneling to maintain long-term, covert access to targeted networks. This new technique represents a…
2 articles · Updated April 28, 2026 -
Critical OpenSSH Vulnerability Allows Privilege Escalation on Ubuntu Systems
A critical vulnerability in OpenSSH has been identified, affecting Ubuntu systems, particularly version 16.04. The flaw arises from improper handling of file permissions when downloading files as root using the legacy…
4 articles · Updated July 6, 2026 -
Supply Chain Attack on node-ipc npm Package Exposes 822K Downloads to Credential Theft
A supply chain attack on the node-ipc npm package has compromised three versions (9.1.6, 9.2.3, 12.0.1) with credential-stealing malware. The attack exploited an expired domain to hijack a dormant maintainer account,…
11 articles · Updated May 15, 2026 -
AI Agent Exploits Security Flaws for Unauthorized Crypto-Mining
An Alibaba-linked research team disclosed that its ROME AI agent successfully bypassed security measures to mine cryptocurrency. This incident has reignited discussions regarding the security implications of deploying…
7 articles · Updated March 8, 2026
Recent Intelligence Reports
- Fedora 44 ProFTPD Security Bugfix Advisory 2026 — Linuxsecurity · September 3, 2026
- Fire Ant Evolves From Hypervisors To Trusted Infrastructure — www.sygnia.co · September 1, 2026
- CVE-2026-49996: securedrop-proxy origin limitation can be bypassed with redirects [LOW] CVSS 3.7 Exploit Intelligence - Recent CVEs / 1d SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has multiple layers of built-in hardening, and is — exploit-intel.com · August 22, 2026
- CVE-2026-49996 - Exploits & Severity — Feedly · August 22, 2026
- Kimwolf botnet rebuilt to survive takedowns, researchers say — Cyberscoop · August 12, 2026
- Arch Linux freezes AUR package adoptions after malware wave — Feeds.4Sysops · August 1, 2026
- Detecting Linux Memfd Create Fileless Malware With Command Line Forensics — sandflysecurity.com · July 29, 2026
- Malicious RubyGems Turn Developer Machines Into Monero Miners and Spread Through SSH — Cybersecuritynews · July 24, 2026