mitre-t1105
165 articles with this tag
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
MEDIUM
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
CRITICAL
MEDIUM
CRITICAL
CRITICAL
MEDIUM
HIGH
CRITICAL
HIGH
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Free streaming boxes may be routing criminal traffic through your home
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Hunting MacSync Stealer infrastructure through behavioral pivots
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
Australian cops cuff alleged TeamPCP masterminds
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns
Unspecified actors making AI-assisted attacks on critical infrastructure
Hunting MacSync Stealer infrastructure through behavioral pivots
‘GhostJacking’ attack turns error logs into indirect prompt injections
Attackers exploit AI skills registry for credential theft
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Anthropic’s Claude escaped test sandbox to attack three organizations
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
New macOS stealer uses social engineering and coercion
Accenture acknowledges security incident following 35GB data theft claim
New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
When a vendor's breach becomes yours: lessons from the Klue incident
Icarus threat actors exploit Klue OAuth breach to steal Salesforce data
USB worm spreads crypto-stealing malware via Windows shortcut files
China-linked group uses InfiniteRed malware to target medical research institutions
OptinMonster WordPress plugin hacked in CDN supply-chain attack
Attackers Hijack Popular WordPress Plugins to Deploy Backdoors
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
Miasma worms its way onto GitHub as attack kit goes open source
Infected Red Hat npm packages expose developer credentials
Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
New Linux malware 'Showboat' targets Middle East telecom provider
Expired domain leads to supply chain attack on node-ipc npm package
Malicious node-ipc versions published to npm in suspected maintainer account compromise
Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America
ConsentFix v3 attacks target Azure with automated OAuth abuse
Novel Minecraft-targeting stealer tapped by reemergent LofyGang
Checkmarx Confirms Data Stolen in Supply Chain Attack
Chinese National Extradited Over Silk Typhoon Cyber Campaign
GopherWhisper: China-linked hackers target governments with custom Go toolkit
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure
China-Backed Hackers Are Industrializing Botnets
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks
Iran‑linked PLC attacks cause real‑world disruption at critical US infra sites
Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets
Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
US warns of Iranian hackers targeting critical infrastructure
‘GrafanaGhost’ bypasses Grafana’s AI defenses without leaving a trace
Zero‑click Grafana AI attack can enable enterprise data exfiltration
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
Critical ShareFile Flaws Lead to Unauthenticated RCE
You Patched LiteLLM, But Do You Know Your AI Blast Radius?
ChatGPT Security Issue Enabled Data Theft via Single Prompt
New RoadK1ll WebSocket implant used to pivot on breached networks
European Commission admits attackers broke into public web systems, but says little else
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
From Vectors to Verdicts: Web App Testing with Vector Command
New Whitepaper: Exploiting Cellular-based IoT Devices
23rd March – Threat Intelligence Report
Authorities disrupt four IoT botnets behind record DDoS attacks
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
Security Flaw in AWS Bedrock Code Interpreter Raises Alarms
AI-generated Slopoly malware used in Interlock ransomware attack
PhantomRaven returns to npm with 88 bad packages
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
Threat Actor Exploits Flaws and Uses Elastic Cloud SIEM to Manage Stolen Data
Iran's MuddyWater Hackers Hit US Firms with New 'Dindoor' Backdoor
Malicious AI Assistant Extensions Harvest LLM Chat Histories
As War Continues, Pro-Iranian Actors Launch Barrage of Cyberattacks
Hackers Weaponize Claude Code in Mexican Government Cyberattack
Fake Next.js job interview tests backdoor developer's devices
Arkanix Stealer pops up as short-lived AI info-stealer experiment
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT RAT
CISA gives federal agencies three days to patch actively exploited Dell bug
Android Malware Hijacks Google Gemini to Stay Hidden
Crims create fake remote management vendor that actually sells a RAT
Remcos RAT Expands Real-Time Surveillance Capabilities
“ZeroDayRAT” Emergence Signals Advanced Mobile Spyware Threats
Nigerian man gets eight years in prison for hacking tax firms
Arkanix Stealer: a C++ & Python infostealer
CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware
Nigerian man sentenced to 8 years in prison for running phony tax refund scheme
Chinese hackers exploited zero-day Dell RecoverPoint flaw for 1.5 years
CRESCENTHARVEST: Iranian protestors and dissidents targeted in cyberespionage campaign
Dell's Hard-Coded Flaw: A Nation-State Goldmine
Dell RecoverPoint for Virtual Machines Zero Day Attack
New Keenadu Android Malware Found on Thousands of Devices
Cryptojacking Campaign Exploits Driver to Boost Monero Mining
China-linked snoops have been exploiting Dell 0-day since mid-2024, using 'ghost NICs' to avoid detection
Supply Chain Attack Embeds Malware in Android Devices