threat-actor
160 articles with this tag
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
INFO
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
CRITICAL
MEDIUM
CRITICAL
HIGH
INFO
HIGH
MEDIUM
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
CRITICAL
CRITICAL
CRITICAL
MEDIUM
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
Phishing campaign targets widely used RMM platforms in 46 countries
Breeze Comet threat actor targets Brazilian financial sector with sophisticated attacks
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Carry-On Compromise: TA4922 Packs PackClient
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
How Clop accessed the enterprise blueprint with no credentials
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
I'm Worried About a Prompt Injection Worm
Crook hawks millions of records allegedly plundered from corporate Azure tenants
Fortune 500 Companies Hit in Azure Data Theft Campaign
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
DPRK’s Lazarus Group exploits Windows zero-day in backdoor campaign
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
Storm-1175 actor deploys new StormEncryptor ransomware after N-central vulnerability exploitation
FirewallFalcon tool found hijacking network traffic
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
After the Break-In: What Attackers Do Once They're Already Inside
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Toy Ghouls’ new toy: the GenieLocker ransomware
Inside Astaroth's New Spambot Component
Tanaka emerges as top data leak broker in first half of 2026
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Attackers Are Learning to Live Off the AI Toolchain
JadePuffer returns with ransomware built to target AI models and infrastructure
ACR Stealer: Two observed intrusion chains amid increased threat activity
JadePuffer agentic attacks now target AI model data with ransomware
Hugging Face uses GLM 5.2 to investigate AI agent-driven cyberattack
Ecopetrol confirms ransomware attempt, data stolen from 3,300 accounts
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Threat actor impersonated hundreds of brands on GitHub to push infostealer malware
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
Defending SaaS-based applications against ShinyHunters OAuth abuse
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
Vibe-Coded Malware Caught in Active Directory Attack
UAT-7810 continues building ORB networks using new malware
Sysdig clocks first documented case of agentic ransomware
PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords
"Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
The Gentlemen are knocking: сustom backdoors and evolving tactics
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus
Akira, LimeWire, and the Sour Taste of Data Exfiltration
Securing the service desk: Why social engineering attacks keep succeeding
MalwareBazaar | SolarisLoader
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
Russian Initial Access Broker Behind FortiBleed Campaign
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
One intrusion, two cyberattackers: Uncovering parallel threat activity
A Glimpse into the “Search Your Target” Market for Stolen Credentials
Killing me gently: Inside Gentlemen’s EDR killer framework
TA4922: The Suspected Chinese Crime Group is Going Global
Malware à la Mode: Tracking Dropping Elephant Tradecraft Through a China-Themed Loader Chain
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms
Chinese-Speaking Actor TA4922 Widens Its Global Reach
Threat Actor Uses AI to Build EDR Evasion Tools
Inside Red Lamassu’s JFMBackdoor
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
AI helps Russian-speaking GreyVibe run five parallel attack chains on Ukrainian targets
Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks
New Threat Actor Jinx-0164 Targets Crypto Developers on macOS
Weekly Update 505
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
GitHub Confirms Hack Impacting 3,800 Internal Repositories
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
Exposing Fox Tempest: A malware-signing service operation
Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
How Storm-2949 turned a compromised identity into a cloud-wide breach
Shai-Hulud Worm Clones Spread After Code Release
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
Thus Spoke…The Gentlemen
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
UAT-8302 and its box full of malware
New PCPJack worm steals credentials, cleans TeamPCP infections
UAT-8302 and its box full of malware
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Edu tech firm Instructure discloses cyber incident, probes impact
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
Checkmarx Confirms Data Stolen in Supply Chain Attack
TeamPCP-linked VECT 2.0 ransomware unintentionally destroys files larger than 128 KB
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
Inside an OPSEC Playbook: How Threat Actors Evade Detection
BlackFile Group Targets Retail and Hospitality with Vishing Attacks