Related Threat Clusters
-
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
The Russian Foreign Intelligence Service (SVR) has been exploiting multiple vulnerabilities, including the SolarWinds breach, to compromise U.S. and allied networks. The SolarWinds attack, which began in September 2019,…
2 articles · Updated May 24, 2026 -
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks
A China-linked threat actor known as Red Menshen has been conducting a long-term espionage campaign targeting global telecommunications networks using a stealthy Linux kernel backdoor called BPFdoor. This malware…
16 articles · Updated March 26, 2026 -
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026
The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication…
8 articles · Updated August 30, 2026 -
Active Exploitation of VMware vCenter Path Traversal Vulnerability CVE-2026-59310
A critical vulnerability in VMware vCenter, tracked as CVE-2026-59310, is being actively exploited, allowing attackers to execute arbitrary code via a path traversal flaw in the Syslog Server. This vulnerability,…
4 articles · Updated August 18, 2026 -
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure
On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including…
37 articles · Updated August 19, 2026 -
Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
5 articles · Updated June 5, 2026 -
Fortinet FortiWeb Vulnerabilities Enable Potential Takeover
Fortinet has disclosed critical vulnerabilities in its FortiWeb web application firewall, allowing attackers to execute arbitrary code and potentially take over affected systems. The vulnerabilities, identified as…
3 articles · Updated August 14, 2026 -
GreyNoise Report Reveals Early Warning Signals for Edge Device Vulnerabilities
GreyNoise Intelligence has released a report indicating that spikes in malicious activity often precede the disclosure of new vulnerabilities in edge devices. The study tracked 147.8 million sessions over 103 days,…
13 articles · Updated April 20, 2026 -
Dell PowerFlex Security Updates Address Multiple Vulnerabilities
Dell has released two security updates (DSA-2025-434 and DSA-2025-435) addressing multiple vulnerabilities in PowerFlex Rack and Appliance systems. The updates cover numerous CVEs, including critical vulnerabilities in…
2 articles · Updated May 23, 2026 -
Pro-Iranian Group Ababil of Minab Claims Cyberattack on LACMTA
On April 9, 2026, the pro-Iranian hacking group Ababil of Minab claimed responsibility for a cyberattack on the Los Angeles County Metropolitan Transportation Authority (LACMTA). The group alleged access to critical…
5 articles · Updated April 15, 2026
Recent Intelligence Reports
- Chinese Fire Ant hackers turn Cisco routers into spying platforms — Bleepingcomputer · August 31, 2026
- Broadcom Delivers End-to-End Security, Identity, and Observability for Agentic AI — Stocktitan · August 31, 2026
- New 'Sleepwalker' backdoor uses custom command language | brief — Scworld · August 25, 2026
- PavinLoader Malware Spreads via ClickFix and Fake Download Campaigns — Technadu · August 25, 2026
- Sleepwalker A Passive Backdoor With Its Own Command Language — r136a1.dev · August 24, 2026
- You don't want this Sleepwalker backdoor on your Windows machine — Theregister · August 24, 2026
- 004 — attack.mitre.org · August 20, 2026
- Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign — Acronis · August 19, 2026