mitre-ta0003
502 articles with this tag
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
USN-8618-1: Linux kernel vulnerabilities
USN-8616-1: Linux kernel (IBM) vulnerabilities
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
US warns of Iran-linked attacks on critical infrastructure
US warns of Iran-linked attacks on critical infrastructure
Beyond the Play Store: How Android threats really spread
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Iran-linked crews are probing more flavors of US industrial kit
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
What the recent SharePoint bugs told us about the patch race
Brazilian Banking Trojan Actively Spreading in Portugal
Ubuntu snap-confine vulnerability grants root access
Malware is targeting AI tools in software development environments
SharePoint vulnerability steals machine keys; fourth recent exploit
VU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability
TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
Ubuntu snap-confine Vulnerability Enables Local Root Access
Siemens IAM Client
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
SleeperGem attack targets Ruby ecosystem with malicious gems
HelloNet campaign abuses ViPNet update mechanism to target Russian organizations
New npm malware cluster targets Vite ecosystem
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
New macOS stealer uses social engineering and coercion
PhantomEnigma campaign hijacks Brazilian government websites for malware delivery
Fake TTF files deliver stealthy malware in global phishing campaign
Daxin malware resurfaces with new backdoor targeting Taiwan manufacturer
Russian hacker uses Google's AI tool to operate botnet
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
HelloNet campaign — new malicious modules launched through the ViPNet update system
Phishing Campaign Hides Lua Loader as TrueType Font File
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
CISA sounds alarm over trio of exploited SharePoint flaws
Investigating Persistence Mechanisms in AWS
LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised
OkoBot: new sophisticated malware framework targets cryptocurrency users
New Rust-based RAT named LabubaRAT impersonates NVIDIA software
CISA Urges SharePoint Hardening After New Exploitations
'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
The serpent’s tongue: Luring the Python out of its den
Threat Actors Achieve Persistence After SQL Injection
Six U-Boot vulnerabilities could allow stealthy firmware attacks
World Cup grudge attackers may have scored Argentine FA access via year-old infostealer infection
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
NCSC-2026-0225 [1.00] [M/H] Kwetsbaarheden verholpen in Siemens SICORE
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
China-Linked APT Expands Proxy Network With New Malware
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
Windows Service - Playbook & Detection Strategies
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
VU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat
ScreenConnect abused to deploy AsyncRAT in widespread campaign
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Rapid Response: Zimperium Delivers Immediate Coverage for Emerging Glitch SPY RAT Campaign
FreeBSD-SA-26:44.posixshm
FreeBSD-SA-26:43.tcp
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Phishers Gain Persistence at EU, Asia Hospitality Orgs
Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints
New Controller Flaws Expose Highway Signs and Billboards to Remote Hacking
Telegram-Based Millenium RAT Campaign Infects 60,000 Devices
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
‘DirtyClone’ Linux Kernel Vulnerability Leads to Root Access
2 Linux kernel flaw PoCs published, enabling local privilege escalation
Supply chain analysis: Kickbacks.ai VS Code extension. Empty pubkey, CSP relaxation, 90-second unsigned self-update, 60-second reassertion loop
China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
Crypto Clipper uses Tor and worm-like propagation for persistence and control
Akira, LimeWire, and the Sour Taste of Data Exfiltration
StealC infrastructure takedown assisted by AI analysis, C2 infiltration
macOS attack technique bypasses endpoint security tools
Be on the lookout for Mistic, a new backdoor used by ransomware broker
Microsoft uses AI to link two malware operations in racketeering suit
Lookalike npm Package Hides a Multi-Stage Windows RAT
What the Miasma campaign reveals about the new supply chain threat model and the underground market for developer credentials
Unpatched SharePoint servers opened the door to multiple attackers, Microsoft finds
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
One intrusion, two cyberattackers: Uncovering parallel threat activity
Microsoft links Mastra AI supply chain attack to North Korean hackers
Threat Brief: Mitigating Large-Scale Credential Attacks
CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
Operation Endgame Disrupts Malware Network Linked to Major Ransomware Gang
Microsoft discovers new lightweight backdoor that steals cryptocurrency
Attacker establishes persistent access to French business using OpenSSH and Tailscale
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2