mitre-ta0008
228 articles with this tag
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
MEDIUM
CRITICAL
MEDIUM
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Mirage Kitten targets Middle East and Africa region with new malware
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Iranian Hackers Target Siemens and Schneider Industrial Systems, CISA Warns
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
TrickBot variant uses DNS tunneling for command and control
North Korean hackers target South Korean software vendors
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
OpenAI model escape puts enterprise AI defenses on notice
Open AI Claims Its AI Models Went Rogue and Hacked Another Company
OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
Hugging Face Hacked in Autonomous AI Attack
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Google Mandiant warns of exposed serverless functions as attack vector
New TuxBot v3 Evolution IoT botnet framework shows signs of AI development
TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development
CISA warns that three SharePoint Server bugs are actively exploited
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
AI-powered breaches provide wake-up call for incident response
The US government warns that Russia state hackers are coming after your router
Australian businesses targeted in global content management system exploitation campaign
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
Lateral Movement Attack: Techniques, Detection & Prevention
Vibe-Coded Malware Caught in Active Directory Attack
Iran-Linked Hackers Using Modular C&C Framework in Cyberattacks
Why The Gentlemen ransomware is a test of identity and recovery controls
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
Sysdig clocks first documented case of agentic ransomware
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework
Researchers Claim First Fully Agentic Ransomware: JadePuffer
New Avalon Malware Framework Packs CrownX Ransomware Capabilities
Agentic AI Used to Conduct Ransomware Attack via Langflow
1st ‘agentic ransomware’ JADEPUFFER invades database at machine speed
Argo CD flaw shows why GitOps infrastructure should be treated as tier zero
The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
China-Linked Group Targets Southeast Asia Critical Systems
Gamaredon group expands malware arsenal in ongoing Ukraine cyberattacks
'Djinn' Stealer Targets Cloud, AI Credentials
Chinese APT CL-STA-1062 targets Southeast Asia with new TinyRCT backdoor
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Self-destructing Mistic backdoor linked to access broker selling corporate footholds to ransomware gangs
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
Oracle PeopleSoft Zero-Day
FortiBleed campaign steals 110M credentials from FortiGate targets
Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs
New ‘Mistic’ RAT Opens Door to Several Ransomware Families
Russian Initial Access Broker Behind FortiBleed Campaign
Exploiting Auth0 Defaults in XSS Attacks - elttam
AryStinger botnet infected thousands of D-Link routers worldwide
CISA warns Fortinet users to secure devices after FortiBleed leak
FortiBleed: You Can't Patch Your Way Out of This
USB worm spreads crypto-stealing malware via Windows shortcut files
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack
Securing CI/CD in an agentic world: Claude Code Github action case
DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company
Adriatic Port Cyber-Attack by Anubis Sparks Warning Over Maritime Security Risks
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
Iranian Cyber Group Handala Claims Cal Water Hack
Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters
OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
The ‘Miasma’ worm source code briefly leaked on GitHub
AI-driven computer worm demonstrates autonomous network exploitation
Miasma worms its way onto GitHub as attack kit goes open source
Meet Hades: The malware that lies to AI security agents
Gogs patches critical zero-day enabling remote code execution
Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO
Silent Ransom Group Uses DNS Fast Flux in Attacks
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
Another Cisco Catalyst SD-WAN Manager bug actively exploited
Securing CI/CD in an agentic world: Claude Code Github action case
Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine
Russian hackers exploit WinRAR vulnerability for data theft
New threat actor JINX-0164 targets crypto firms with macOS malware
Dutch cops wrest 17M devices from mystery botnet's clutches
With Complex Cloud Integrations, Small Errors Lead to Major Compromises
The Gentlemen are coming for your files, and then your network
Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor
JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware
AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites
The Hackers Behind Shai-Hulud: Lucky or Skilled?
From Cookies to Keys: The Threat of Session Hijacking
New Linux malware 'Showboat' targets Middle East telecom provider
Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
GitHub Actions Cache Poisoning is eating open source
Chinese hackers target telcos with new Linux, Windows malware
Hackers bypass SonicWall VPN MFA due to incomplete patching
Microsoft Self-Service Password Reset abused in Azure data theft attacks