mitre-t1133
466 articles with this tag
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
AI agents exploited PaperCut flaws to breach 395 organizations
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Indonesia Hit by Android Banking App-Cloning Campaign
VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Passkey-themed social engineering leads to identity and cloud compromise
ClickFix Moves into the Browser to Steal Cryptocurrency
New Android RAT uses worm to target exposed ADB services
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
THost9 Android RAT Pairs Packed Loader With ADB Worm
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
North Korean Hackers Deploy New Linux Espionage Toolkit
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
Anatomy of a Silent Domain Takeover
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
How China industrialized the infrastructure behind state hacking
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Prompting the Payload: How an npm Supply Chain Attack Delivers the RedC2 AI-Powered Linux Implant
PaperCut Exploitation Escalates to Active Intrusions
⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
CRPx0 hacking service for dummies claims victim count more than quintupled
Siemens S7 Series PLCs and other Internet-exposed PLC Attack
CISA red team finds critical infrastructure vulnerabilities
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Nimbus Manticore expands infrastructure and malware arsenal
FBI seizes China-linked QScan and QTRouter platforms used to target US critical infrastructure
More than 100 water systems were hit in July cyberattacks
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
Tracking PavinLoader across ClickFix and fake download campaigns
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
TrueConf flaws enabling attacks on meeting participants added to KEV catalog
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
Operation CameraSwarm compromises over 14,500 Dahua devices
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
Frequently asked questions about the active threat to Siemens S7 Series PLCs
ICS Operators Warned of AI-Driven Attacks on Siemens PLCs
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
Defending Against an Active Threat to Siemens S7 Series PLCs
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
‘TWINLOOT’ Python implant abuses Microsoft services for stealthy C2
CRLF-Powered Desync Attacks: Beheading HTTP Streams
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
China-Linked Hacker Shows AI Capabilities in APAC Attack
New Unisoc modem flaw allows Android kernel access
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
Fortune 500 Companies Hit in Azure Data Theft Campaign
ChainDrop worm crawls into npm supply chain, evades standard defenses
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Taiwan confirms AI-assisted cyberattack on government systems
vCenter Flaw Exploited Just Five Days After Disclosure
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
New 'Plug and Pwn' attacks exploit Windows Plug and Play for SYSTEM privileges
Critical VMware vCenter flaw actively exploited in 47 countries
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
Uber Freight keeps on trucking after extortion crew breaks in
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Fake CCleaner installs GhostDesk Chrome spyware
Kimwolf v7: An Evolution of the Kimwolf Botnet
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack
FirewallFalcon tool found hijacking network traffic
Hacktivist group Head Mare exploits TrueConf vulnerabilities to deliver backdoors
WordPress Plugins Compromised Without a Single File Change
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
Chinese-linked LightSpy spyware expands to over a dozen countries
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
ChainDrop: Inside a Self-Propagating npm Worm
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Researcher Claims Control of ChatGPT Secure Sandbox
Enterprise passkey security under threat from malware
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
Report: Passkey security issues could allow account takeover
Paperclip AI Flaws Let Unauthenticated Attackers Run Commands