LegacyHive is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.
LegacyHive is a vulnerability tracked across 3 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed July 15, 2026; most recent activity July 18, 2026.
On July 15, 2026, security researcher Nightmare Eclipse released a proof-of-concept exploit named LegacyHive, targeting a zero-day vulnerability in the Windows User Profile Service (ProfSvc). This flaw allows arbitrary…
From late April to mid-June 2026, ACR Stealer, a malware-as-a-service operation, has ramped up its activity targeting enterprise users by stealing browser credentials, session tokens, and sensitive documents. The attack…
Ernst & Young LLP (EY) has confirmed a data breach involving unauthorized access to a third-party IT service management platform used for tax-related work. The breach, which occurred between March 28 and April 12, 2026,…
LegacyHive is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 5 intelligence report mentions.
The most recent intelligence report mentioning LegacyHive on ThreatCluster is dated July 18, 2026. Activity was first observed July 15, 2026, giving a tracked span from then to July 18, 2026.
Across ThreatCluster reporting, LegacyHive most frequently co-occurs with Data Breach, Malware, Phishing, Zero-day Exploit, CWE-200 - Exposure of Sensitive Information, among 12 tracked related entities.
The most significant recent cluster is “LegacyHive Exploit Targets Windows User Profile Service Zero-Day Vulnerability” (14 articles · Updated July 15, 2026). LegacyHive appears across 3 threat clusters in total, listed above with sources.
LegacyHive appears in 5 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.