threat-intel CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six previously exploited vulnerabilities to its KEV catalog, including flaws in Citrix NetScaler, Linux, and Microsoft SQL Server. These vulnerabilities are actively being exploited, with telemetry showing attacks originating from various countr… The Hacker News · 3d ago High CVE-2019-1068CVE-2026-8452CVE-2022-0995SWGEHOkevexploitationvulnerability
threat-intel UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit The Chinese-speaking cybercrime group UAT-10147 is aggressively targeting web servers globally, leveraging AI-powered tools to automate intrusion operations and establish persistent access. They utilize a new cross-platf… The Hacker News · 6d ago High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOairansomwaremalware
threat-intel Is Cyber missing the Marque? The White House is considering a program allowing private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside the United States, a move that significantly ex… Cisco Talos · Aug 20, 2026 High CHoffensive-cybercybercrimeai
threat-intel UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities Chinese-speaking intrusion actor UAT-10147 is employing a sophisticated, cross-platform intrusion toolset, SPECTRE, leveraging AI-assisted development to evade detection. SPECTRE is a cross-platform backdoor with Linux r… Cisco Talos · Aug 20, 2026 High CVE-2019-16098CVE-2021-21551CHaiedrlinux
threat-intel UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publ… Cisco Talos · Aug 20, 2026 High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOaiautomationpost-exploitation