mitre-t1021
188 articles with this tag
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
INFO
MEDIUM
HIGH
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches
US warns of Iran-linked attacks on critical infrastructure
In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Iran-linked crews are probing more flavors of US industrial kit
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
OpenAI model escape puts enterprise AI defenses on notice
Open AI Claims Its AI Models Went Rogue and Hacked Another Company
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI admits it was the source of the agent swarm that attacked Hugging Face
A new extortion cocktail: office printers, small ransoms, and BitLocker
ACR Stealer: Two observed intrusion chains amid increased threat activity
Attackers Combo Up Evasion Tactics for BEC Phishing
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
Cruciferra Crypter Uses Process Ghosting to Evade Detection
Google Mandiant warns of exposed serverless functions as attack vector
New TuxBot v3 Evolution IoT botnet framework shows signs of AI development
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
SonicWall customers under threat as attackers exploit 2 zero-days
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
OkoBot: new sophisticated malware framework targets cryptocurrency users
The US government warns that Russia state hackers are coming after your router
EU and UK officially blame Russian spies for cyberattack on Poland's power grid
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Lateral Movement Attack: Techniques, Detection & Prevention
Vibe-Coded Malware Caught in Active Directory Attack
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
Cybercriminals exploit India’s tax filing season with a dual-malware campaign
Hydro-Québec Le Circuit Electrique charging station backend
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
UAT-7810 continues building ORB networks using new malware
JadePuffer: The First Complete LLM-Driven Ransomware Attack
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Sysdig clocks first documented case of agentic ransomware
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Agentic AI Used to Conduct Ransomware Attack via Langflow
1st ‘agentic ransomware’ JADEPUFFER invades database at machine speed
Argo CD flaw shows why GitOps infrastructure should be treated as tier zero
Fileless Malware Abuses Google Blogspot to Deploy Infostealer in Memory
The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
China-Linked Group Targets Southeast Asia Critical Systems
More Klue Breach Victims Identified as Hackers Get Hacked
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
The hits keep on coming for Cisco vulnerabilities
Oracle PeopleSoft Zero-Day
Unpatched SharePoint servers opened the door to multiple attackers, Microsoft finds
Klue breach exposed Salesforce CRM data through stolen OAuth tokens
AryStinger botnet infected thousands of D-Link routers worldwide
NCSC-2026-0208 [1.00] [M/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine
Microsoft discovers new lightweight backdoor that steals cryptocurrency
FortiBleed: You Can't Patch Your Way Out of This
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
NCSC-2026-0207 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Fusion Middleware producten
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
Oracle PeopleSoft zero‑day fuels ShinyHunters extortion spree
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
The ‘Miasma’ worm source code briefly leaked on GitHub
AI-driven computer worm demonstrates autonomous network exploitation
Miasma worms its way onto GitHub as attack kit goes open source
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks
Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
Silent Ransom Group Uses DNS Fast Flux in Attacks
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
Another Cisco Catalyst SD-WAN Manager bug actively exploited
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine
Threat Actor Uses AI to Build EDR Evasion Tools
Dutch cops wrest 17M devices from mystery botnet's clutches
The Gentlemen are coming for your files, and then your network
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
[NEU] [hoch] AMD Chipsätze: Mehrere Schwachstellen
PureLogs Variant Steals Data via Purchase Order Lures
Drupal bug added to CISA list of known exploited vulnerabilities
Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
WantToCry ransomware evades detection through SMB abuse, remote encryption
Hackers bypass SonicWall VPN MFA due to incomplete patching
Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation
A 6-step guide for responding to the Foxconn ransomware/supply chain incident
GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials
The Canvas breach proved that prevention is no longer enough
Kazuar: Anatomy of a nation-state botnet
TeamPCP releases ‘vibe coded’ Shai-Hulud source code, issues challenge
Kazuar: Anatomy of a nation-state botnet
North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems
Kazuar: Anatomy of a nation-state botnet
Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns
House committee chair calls on Instructure to testify in Canvas hack
When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain Compromise
New GhostLock tool abuses Windows API to block file access
South Staffordshire Water Fined £1m After Data Breach
New GhostLock tool abuses Windows API to block file access
PCPJack Campaign Boots TeamPCP Off Compromised Machines