mitre-ta0005
371 articles with this tag
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Indonesia Hit by Android Banking App-Cloning Campaign
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
Gigabud banking trojan uses app cloning to evade fraud detection
From 88 lines to 1: Detecting DLL hijacking with Elastic Defend
NCSC-2026-0356 [1.00] [M/H] Kwetsbaarheden verholpen in diverse SAP-producten
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production
Inside Knight Office, a New M365 AiTM Phishing Kit
[NEU] [mittel] MISP: Mehrere Schwachstellen
Hacking AI customer service agents (Bug Bounty Village DEF CON 34)
LG TV flaws could let attackers listen in, even in standby mode
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Coder platform targeted by attackers delivering malicious Terraform modules
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
How China industrialized the infrastructure behind state hacking
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Attackers Steal METR API Key and Burn $600,000 in AI Credits
China-linked campaign targets high-value networks, critical infrastructure
McKesson confirms cyber incident after ShinyHunters claims patient-data theft
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
Authorities arrest 2 alleged members of prolific hacking group TeamPCP
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
CISA red team finds critical infrastructure vulnerabilities
Mobile Fraud in 2026: Malware is Actively Targeting Mobile Banking Apps in LATAM
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
[NEU] [hoch] JFrog Artifactory: Mehrere Schwachstellen
ToxicPanda 2.0 can take over your Android phone and banking apps
Windows Defender’s own driver can leave systems defenseless
🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia
New Agent Tesla malware version uses emoji obfuscation to evade detection
New Agent Tesla Malware Variant Boosts Evasion Capabilities
Backdoored Rust packages hit crates.io, exposing developers to malware at build time
Operation CameraSwarm compromises over 14,500 Dahua devices
New malware campaign combines social engineering with defense evasion
'Grandoreiro' Malware Resurfaces With Mexico Campaign
Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
NCSC-2026-0320 [1.00] [M/H] Kwetsbaarheden verholpen in Zabbix
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
Defending Against an Active Threat to Siemens S7 Series PLCs
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
ChainDrop worm crawls into npm supply chain, evades standard defenses
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
Akira ransomware reboots into Windows Safe Mode to knock EDR offline
Uber Freight keeps on trucking after extortion crew breaks in
Exposed: Woeful security at UK criminal records office that led to sensitive data leak
Fake CCleaner installs GhostDesk Chrome spyware
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
FirewallFalcon tool found hijacking network traffic
Attackers exploit AI skills registry for credential theft
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
Trojanized AI skills gain 1.7M installs in agent-targeted attack
Chinese-linked LightSpy spyware expands to over a dozen countries
Python package security in 2026: How supply chain attacks are targeting your AI development environment
Multiples vulnérabilités dans les produits Cisco (06 août 2026)
Anthropic’s Mythos AI used social engineering to target real people
Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
TP-Link Omada ZTP systems vulnerable to fleet-wide compromise
Rapid Response: Zimperium Secures Mobile Endpoints Against Octagon Android Malware
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
Travelers targeted when logging into hotel Wi-Fi networks
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Water system cyberattacks spread to Georgia, Michigan amid US-Iran conflict
HollowFrame Loader Uses Fake Python DLL to Evade Defender
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Cryptomining campaign avoids root access to evade detection
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers
Cryptominer Abuses Linux PAM to Hide From SOC Analysts
Silver Fox group uses new drivers in BYOVD attacks against Japanese manufacturer
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
After the Break-In: What Attackers Do Once They're Already Inside
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
OpenAI explains how its AI agent breached Hugging Face
USN-8621-1: Samba vulnerabilities
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
Golden Chickens malware-as-a-service resurfaces with four new families
Kubernetes Runtime Threats Explained
Lampion banking malware continues to target Portuguese organizations
Russian hackers exploit Zimbra zero-click flaw for email theft
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
Attackers Combo Up Evasion Tactics for BEC Phishing
Cruciferra Crypter Uses Process Ghosting to Evade Detection
OkoBot malware targets hardware wallet users with recovery phrase phishing
Windows bind links exploited for EDR evasion
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
New Windows Bind Link techniques let attackers evade EDR, security controls
Windows Bind Link Attacks Can Hide Malware From EDR Tools