mitre-ta0010
351 articles with this tag
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
MEDIUM
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
MEDIUM
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
MEDIUM
HIGH
LOW
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
INFO
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Extortion crews have their eyes on high-value AI data, Google warns
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Extortion crews have their eyes on high-value AI data, Google warns
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
BGP hijacking incident diverts traffic, targeting Softaculous and Virtualizor users
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
Healthcare Giant McKesson Investigates Data Breach Incident
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
Australian cops cuff alleged TeamPCP masterminds
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Chinese Hacker Group QTFY Uses Custom-Built Platforms to Target US Infrastructure, FBI Warns
OpenAI explains how its AI agents did crime and attacked Hugging Face
Over 100 US water utilities had cyberattacks in July, says CISA
Insight into agentic hacking tools: Hermes, OpenClaw and the Bayesian brain
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
New malware targets Android car head units for ad fraud and botnet creation
Unspecified actors making AI-assisted attacks on critical infrastructure
The long tail of Clop’s PTC hack is just beginning to emerge
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
Microsoft finally patches critical one-click Copilot vulnerability, more than eight months after learning of it
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Delta Air Lines investigates rogue Wi-Fi network on flight from DEF CON
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Storm-1175 actor deploys new StormEncryptor ransomware after N-central vulnerability exploitation
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
One-click flaw in Atlassian Rovo exposed enterprise data via prompt injection attack
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Google Links Redact Extortion Group to BlackFile Rebrand
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Almost Half of Malware Samples Communicate Direct to IP
The Minnesota attackers may hold a better backup of your plant than you do
UK’s Police National Legal Database Reveals Data Breach
Russian spies turn public Wi-Fi into malware delivery systems
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Health-ISAC warns of ShinyHunters' increasing attacks on healthcare SSO accounts
Italian organizations targeted by 148 ransomware attacks in first half of 2026
We now have a better understanding how OpenAI hacked into Hugging Face
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
PTC Windchill Vulnerability Exploited in Ransomware Campaign
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Year-long Russian attacks infect users as soon as they look at an email
Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Russian Global Webmail Espionage
Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
Qilin exploits Palo Alto Networks GlobalProtect VPN firewalls
What happens if you visit a WordPress site hacked through wp2shell?
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
HollowGraph malware uses Microsoft 365 calendar for command and control
Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Chinese actors leverage AI tools for automated cyberattacks on government and financial systems
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
20+ Hijacked Government Websites Became
an Attack Channel
Malicious ModHeader extension pulled from Chrome and Edge stores
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
Defending SaaS-based applications against ShinyHunters OAuth abuse
Australian Cyber Agency Warns of Global CMS Exploitation Campaign
New Helix data extortion group uses identity-focused tactics to target SharePoint
Armored Likho APT leverages AI-generated malware and BusySnake Stealer
Suspected Chinese spies target universities with Roundcube exploit
Accenture Confirms Data Breach After Hacker Claims Source Code Theft
VU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls
Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target
Accenture acknowledges security incident following 35GB data theft claim
Windows is watching: Anti-piracy tool fingers Scattered Spider suspect
Hydro-Québec Le Circuit Electrique charging station backend
JadePuffer: The First Complete LLM-Driven Ransomware Attack
6th July – Threat Intelligence Report
Alleged Scattered Spider Hacker Extradited to US
Scattered Spider suspect extradited over $8 million ransom scheme
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
More Klue Breach Victims Identified as Hackers Get Hacked
Why patch directives only go so far
Amadey, StealC malware operations disrupted in Operation Endgame action
When a vendor's breach becomes yours: lessons from the Klue incident
The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration
Klue breach exposed Salesforce CRM data through stolen OAuth tokens
Prevent data exfiltration: AWS egress controls for cloud workloads
New Prinz Eugen ransomware prioritizes recent files for encryption
Authorities disrupt Evil Corp’s SocGholish botnet
Cloudflare blocked 38.5 billion cyberattacks against civil society organizations
Icarus threat actors exploit Klue OAuth breach to steal Salesforce data
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
Attackers drop DragonForce ransomware leveraging MS Teams relay systems