threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities *before* they are officially assigned CVEs, leading to a faster exploitation cycle. This resulted i… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
vulnerability Multiples vulnérabilités dans ClamAV (10 août 2026) Multiple vulnerabilities have been discovered in ClamAV, potentially allowing attackers to compromise data confidentiality, cause denial of service, and introduce an unspecified security issue. These vulnerabilities affe… CERT-FR · Aug 10, 2026 Medium CVE-2025-8088CVE-2026-20337CVE-2026-20338vulnerabilityantivirusclamav
threat-intel Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse The Gamaredon APT group continued its aggressive cyberattacks against Ukraine throughout 2025, utilizing a range of new malware and exploiting vulnerabilities to steal sensitive information. The group expanded its tactic… The Hacker News · Jun 29, 2026 High CVE-2025-8088RUUAspear-phishingpersistencecloud-services
threat-intel Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets Russia-linked APT Turla has been deploying a new .NET backdoor, dubbed StockStay, to conduct ongoing cyber espionage against Ukrainian government and military organizations, as well as entities with interests in Italian… SecurityWeek · Jun 26, 2026 High CVE-2025-8088UKRUITespionagebackdoorphishing
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin… WeLiveSecurity · Jun 25, 2026 HighCVSS 8.8 CVE-2025-8088RUcyberespionagerussiaspearphishing
threat-intel Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs Russian threat actors, including Shadow-Earth-066 (UAC-0226) and Earth Dahu (Primitive Bear, Shuckworm), are continuing to exploit a long-standing vulnerability (CVE-2025-8088) in WinRAR to conduct data theft and cyber e… Dark Reading · Jun 9, 2026 High CVE-2025-8088CVE-2023-38831RUUAwinrarvulnerabilitycyberespionage
threat-intel WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine A vulnerability in WinRAR, first identified in July 2025, is being exploited by Russia-aligned cyber groups to deploy malware targeting Ukrainian organizations. The attackers, including Earth Dahu and SHADOW-EARTH-066, a… The Hacker News · Jun 9, 2026 High CVE-2025-8088RUUAwinrarexploitukraine
threat-intel Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Gamaredon group is exploiting a WinRAR vulnerability (CVE-2025-8088) to deploy a multi-stage malware campaign targeting Ukraine. This campaign utilizes GammaWorm and GammaSteel, designed for data theft and persistenc… The Hacker News · Jun 2, 2026 High CVE-2025-8088CVE-2026-21509RUUAwinrarmalwarevulnerability
threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce