mitre-t1133
337 articles with this tag
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
US warns of Iran-linked attacks on critical infrastructure
Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Brazilian Banking Trojan Actively Spreading in Portugal
TrickBot variant uses DNS tunneling for command and control
How an OpenAI benchmark test turned into a real-world cyberattack
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
OpenAI Models Escaped Containment and Hacked HuggingFace
Sophisticated crypter service Cruciferra evades detection with advanced techniques
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Hugging Face Hacked in Autonomous AI Attack
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
ACR Stealer: Two observed intrusion chains amid increased threat activity
Phishing Campaign Hides Lua Loader as TrueType Font File
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
NPM ecosystem hit with two new supply chain compromises
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
ShinyHunters group exploits OAuth trust, prompting Microsoft security upgrades
New Rust-based RAT named LabubaRAT impersonates NVIDIA software
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
The serpent’s tongue: Luring the Python out of its den
AI-powered breaches provide wake-up call for incident response
Governments to enterprises: Improve your router security hygiene
The US government warns that Russia state hackers are coming after your router
Russia’s FSB attacks critical infrastructure, says 12 Western nations
Australian businesses targeted in global content management system exploitation campaign
Six U-Boot vulnerabilities could allow stealthy firmware attacks
Officials once again warn defenders that Russian hackers are targeting network devices
RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker
Ciblage et compromission d’entités françaises au moyen du mode opératoire d’attaque Turla (13 juillet 2026)
Targeting and Compromise of French Entities Using the Turla Intrusion Set (13 juillet 2026)
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Threat actor uses AI-generated malware in network intrusion
Lateral Movement Attack: Techniques, Detection & Prevention
Vibe-Coded Malware Caught in Active Directory Attack
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
China-Linked APT Expands Proxy Network With New Malware
New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Why The Gentlemen ransomware is a test of identity and recovery controls
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
Researchers Claim First Fully Agentic Ransomware: JadePuffer
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
Brazilian Banking Trojan Ousaban Targets Spain and Portugal
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks
Defence Impairment Olympics
Gamaredon group expands malware arsenal in ongoing Ukraine cyberattacks
'Djinn' Stealer Targets Cloud, AI Credentials
Chinese Framework Powers 200,000 Scam Sites
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs
FishMonger’s arsenal upgraded: SprySOCKS for Windows
Nation-state actors cracked critical Australian infrastructure to ‘cripple it at a time of their choosing’
Microsoft uses AI to link two malware operations in racketeering suit
New ‘Mistic’ RAT Opens Door to Several Ransomware Families
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
Exploiting Auth0 Defaults in XSS Attacks - elttam
Microsoft links Mastra AI supply chain attack to North Korean hackers
CISA warns Fortinet users to secure devices after FortiBleed leak
Fake Boots emails target millions in large phishing campaign
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
From package to postinstall payload: Inside the Mastra npm supply chain compromise
Massive breach spills credentials for thousands of sensitive networks
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
AUR suspends new registrations as 1,500-plus malicious packages flood repository
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic
Chinese hackers breached North American research institutions via REDCap servers
Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security Risks
China-linked spies backdoored authentication stack to stay hidden for years
China-nexus group hid in Linux login system for nearly a decade
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
FBI shuts down 13 ‘consulting’ websites used for suspected Chinese espionage
OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor
OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
FBI seizes 13 websites linked to alleged Chinese intelligence-gathering effort
JDY botnet expands, enabling rapid exploitation of disclosed vulnerabilities