threat-intel Threat landscape for industrial automation systems. Q2 2026 In Q2 2026, the percentage of ICS computers blocked by malicious objects continued to decline, hitting a low of 19.15%, the lowest since 2022. East Asia and Africa saw significant increases in threat percentages across various categories, including malicious scripts, phishing pages, and email threats. Biometrics consi… Securelist · 3d ago High RUCHAFicsindustrial automationcybersecurity
threat-intel Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks Pakistan's Transparent Tribe, a known advanced persistent threat (APT) group, has been aggressively targeting organizations in Afghanistan and India, utilizing a refined toolset including the Patchcord backdoor and other… Dark Reading · Aug 20, 2026 High AFINPAaptsocial engineeringbrowser hijacking
threat-intel New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure A Pakistan-aligned threat actor, APT36 (Transparent Tribe), is targeting Afghan telecom providers and critical infrastructure in South Asia with a new backdoor campaign called PATCHCORD. The campaign utilizes sector-spec… The Hacker News · Aug 13, 2026 High CVE-2024-6387AFINbackdoorc2afghanistan
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
threat-intel Device Code Phishing Up 1,500% in 2026; Vishing Doubles Device code phishing and vishing are experiencing a dramatic surge, driven by state-sponsored and cybercriminal groups, and are proving highly effective at bypassing traditional security measures. CrowdStrike reports a 1… Dark Reading · Aug 4, 2026 High USRUEUphishingvishingdevice-code-phishing
threat-intel Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk Chinese-speaking hackers are targeting government organizations in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria, using two new backdoors, OctLurk and SilkLurk, along with… The Hacker News · Jul 31, 2026 High AFKYTAbackdoorproxycyberattack
threat-intel Russian Global Webmail Espionage A persistent cyberespionage campaign, tracked as CL-STA-1114, originating from Russian threat actors (Void Blizzard and LAUNDRY BEAR) is targeting Zimbra webmail instances across various sectors, including governments, d… Palo Alto Unit 42 · Jul 23, 2026 High CVE-2025-66376NAUKCIcyberespionagephishingvulnerability
threat-intel Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor A long-dormant Chinese-linked malware, Daxin, resurfaced in Taiwan after over a decade, alongside a new backdoor called Stupig. Daxin, a kernel-mode rootkit, has been used in targeted attacks since 2013, and its ability… The Hacker News · Jul 16, 2026 High CHAFTHcyber espionagekernel-modecommand and control
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware
threat-intel Websites with an undefined trust level: avoiding the trap This Securelist article discusses the growing threat of websites with an "undefined trust level," which are not traditional phishing sites but still pose significant risks to users. These sites, often mimicking legitimat… Securelist · May 6, 2026 Medium AFLARUscamfraudonline scams