threat-actor
130 articles with this tag
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
CRITICAL
CRITICAL
CRITICAL
MEDIUM
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
INFO
INFO
CRITICAL
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Attackers Are Learning to Live Off the AI Toolchain
JadePuffer returns with ransomware built to target AI models and infrastructure
ACR Stealer: Two observed intrusion chains amid increased threat activity
JadePuffer agentic attacks now target AI model data with ransomware
Hugging Face uses GLM 5.2 to investigate AI agent-driven cyberattack
Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Threat actor impersonated hundreds of brands on GitHub to push infostealer malware
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
Defending SaaS-based applications against ShinyHunters OAuth abuse
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
Vibe-Coded Malware Caught in Active Directory Attack
UAT-7810 continues building ORB networks using new malware
Sysdig clocks first documented case of agentic ransomware
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
"Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
The Gentlemen are knocking: сustom backdoors and evolving tactics
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Akira, LimeWire, and the Sour Taste of Data Exfiltration
Securing the service desk: Why social engineering attacks keep succeeding
MalwareBazaar | SolarisLoader
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
Russian Initial Access Broker Behind FortiBleed Campaign
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
One intrusion, two cyberattackers: Uncovering parallel threat activity
A Glimpse into the “Search Your Target” Market for Stolen Credentials
Killing me gently: Inside Gentlemen’s EDR killer framework
TA4922: The Suspected Chinese Crime Group is Going Global
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
Chinese-Speaking Actor TA4922 Widens Its Global Reach
Threat Actor Uses AI to Build EDR Evasion Tools
Inside Red Lamassu’s JFMBackdoor
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
AI helps Russian-speaking GreyVibe run five parallel attack chains on Ukrainian targets
Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
Disrupting Glassworm: Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet
Weekly Update 505
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
GitHub Confirms Hack Impacting 3,800 Internal Repositories
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
Exposing Fox Tempest: A malware-signing service operation
Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
How Storm-2949 turned a compromised identity into a cloud-wide breach
Shai-Hulud Worm Clones Spread After Code Release
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
Thus Spoke…The Gentlemen
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
UAT-8302 and its box full of malware
New PCPJack worm steals credentials, cleans TeamPCP infections
UAT-8302 and its box full of malware
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Edu tech firm Instructure discloses cyber incident, probes impact
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
Checkmarx Confirms Data Stolen in Supply Chain Attack
TeamPCP-linked VECT 2.0 ransomware unintentionally destroys files larger than 128 KB
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
Inside an OPSEC Playbook: How Threat Actors Evade Detection
BlackFile Group Targets Retail and Hospitality with Vishing Attacks
TGR-STA-1030: New Activity in Central and South America
FIRESTARTER Backdoor
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
French govt agency confirms breach as hacker offers to sell data
Detection strategies across cloud and identities against infiltrating IT workers
Nightmare-Eclipse Tooling Seen in Real-World Intrusion
Untangling a Linux Incident With an OpenAI Twist
Rockstar Games gets a taste of grand theft data amid ShinyHunters threat of 'Pay or leak'
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
Medusa Ransomware Attack
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
Decoding NightSpire: Ransomware IOCs Aren't Set in Stone
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
Detecting CI/CD Supply Chain Attacks with Canary Credentials
Hackers exploit React2Shell in automated credential theft campaign
A threat actor who goes by the name "Mr. Raccoon" has claimed to hack Adobe support via 3rd party Indian BPO firm
React2Shell Exploited in Large-Scale Credential Harvesting Campaign
A threat actor who goes by the name "Mr. Raccoon" has claimed to hack Adobe support via 3rd party Indian BPO firm
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
An overview of ransomware threats in Japan in 2025 and early detection insights from Qilin cases
Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069
Venom Stealer MaaS Platform Commoditizes ClickFix Attacks
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
FBI confirms hack of Director Patel's personal email inbox
A cunning predator: How Silver Fox preys on Japanese firms this tax season
European Commission investigating breach after Amazon cloud hack
New “Darksword” iOS exploit used in infostealer attack on iPhones
The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico
Boggy Serpens Threat Assessment
“Handala Hack” – Unveiling Group’s Modus Operandi