threat-actor
85 articles with this tag
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
CRITICAL
CRITICAL
CRITICAL
MEDIUM
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
MEDIUM
INFO
HIGH
INFO
CRITICAL
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
INFO
CRITICAL
LOW
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
LOW
MEDIUM
MEDIUM
INFO
Weekly Update 505
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
GitHub Confirms Hack Impacting 3,800 Internal Repositories
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
Exposing Fox Tempest: A malware-signing service operation
Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
How Storm-2949 turned a compromised identity into a cloud-wide breach
Shai-Hulud Worm Clones Spread After Code Release
Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182)
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
Thus Spoke…The Gentlemen
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
UAT-8302 and its box full of malware
New PCPJack worm steals credentials, cleans TeamPCP infections
UAT-8302 and its box full of malware
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Edu tech firm Instructure discloses cyber incident, probes impact
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
TeamPCP-linked VECT 2.0 ransomware unintentionally destroys files larger than 128 KB
Checkmarx Confirms Data Stolen in Supply Chain Attack
Inside an OPSEC Playbook: How Threat Actors Evade Detection
BlackFile Group Targets Retail and Hospitality with Vishing Attacks
TGR-STA-1030: New Activity in Central and South America
FIRESTARTER Backdoor
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
French govt agency confirms breach as hacker offers to sell data
Detection strategies across cloud and identities against infiltrating IT workers
Untangling a Linux Incident With an OpenAI Twist
Nightmare-Eclipse Tooling Seen in Real-World Intrusion
Rockstar Games gets a taste of grand theft data amid ShinyHunters threat of 'Pay or leak'
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
Medusa Ransomware Attack
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
Decoding NightSpire: Ransomware IOCs Aren't Set in Stone
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
Detecting CI/CD Supply Chain Attacks with Canary Credentials
Hackers exploit React2Shell in automated credential theft campaign
A threat actor who goes by the name "Mr. Raccoon" has claimed to hack Adobe support via 3rd party Indian BPO firm
React2Shell Exploited in Large-Scale Credential Harvesting Campaign
A threat actor who goes by the name "Mr. Raccoon" has claimed to hack Adobe support via 3rd party Indian BPO firm
An overview of ransomware threats in Japan in 2025 and early detection insights from Qilin cases
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack
Venom Stealer MaaS Platform Commoditizes ClickFix Attacks
FBI confirms hack of Director Patel's personal email inbox
A cunning predator: How Silver Fox preys on Japanese firms this tax season
European Commission investigating breach after Amazon cloud hack
New “Darksword” iOS exploit used in infostealer attack on iPhones
The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico
Boggy Serpens Threat Assessment
“Handala Hack” – Unveiling Group’s Modus Operandi
Silence of the hops: The KadNap botnet
BlackSanta EDR-Killer Targets HR Teams in CV-Themed Campaign
Salesforce issues new security alert tied to third customer attack spree in six months
Overly permissive ‘guest’ settings put Salesforce customers at risk
New ‘BlackSanta’ EDR killer spotted targeting HR departments
Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit
Threat Actor Exploits Flaws and Uses Elastic Cloud SIEM to Manage Stolen Data
Web Server Exploits and Mimikatz Used in Attacks Targeting Asian Critical Infrastructure
Recent Cisco Catalyst SD-WAN Vulnerability Now Widely Exploited
Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale
Risky Business #827 -- Iranian cyber threat actors are down but not out
AI-powered attack kits go open source, and CyberStrikeAI may be just the beginning
Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries
Operation Epic Fury: Potential Iranian Cyber Counteroffensive Operations
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day
Unmasking Agent Tesla: A Deep Dive into a Multi-Stage Campaign
Risky Business #826 -- A week of AI mishaps and skulduggery
3 Threat Groups Started Targeting ICS/OT in 2025: Dragos
tripwire.com
The Lazarus group: North Korean scourge for +10 years | NCC Group
Cato CTRL™ Threat Research: Investigation of RMM Tools Leveraged by Ransomware Gangs in Real-World Incidents
Threat Advisory: VoidLink
New threat actor UAT-9921 deploys VoidLink against enterprise sectors
The Dragonforce Cartel: LockBit–Qilin–DragonForce Alliance
The Godfather of Ransomware? Inside DragonForce’s Cartel Ambitions
UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors
0APT ransomware group rises swiftly with bluster, along with genuine threat of attack
New threat actor, UAT-9921, leverages VoidLink framework in campaigns
Can’t stop, won’t stop: TA584 innovates initial access
Labyrinth Chollima Evolves into Three North Korean Hacking Groups