threat-intel Iran-linked hackers expand infrastructure across Europe and Middle East, report says Iranian-linked hackers, known as Tortoiseshell, are expanding their operations across Europe and the Middle East, including establishing infrastructure in Britain. The group, associated with Iran's Islamic Revolutionary Guard Corps, utilizes tools like a TwoStroke backdoor and reverse SSH tunnels to conduct espionage o… The Record · 4d ago High UKBESAiranaptssh tunnel
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel Exploits and vulnerabilities in Q2 2026 Q2 2026 saw a significant surge in the number of registered vulnerabilities, largely driven by the increasing adoption of AI tools for vulnerability discovery. Researchers are now publishing exploits for vulnerabilities… Securelist · 4d ago High CVE-2018-0802CVE-2017-11882CVE-2017-0199vulnerabilitythreat-intelapt
threat-intel China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware China's 'SilkParasite' operation, utilizing AI-assisted malware, has been targeting government institutions across Central Asia for nearly a year. Threat researchers at Bitdefender identified seven previously unseen malw… The Record · Aug 20, 2026 High CHKAKYaiespionagemalware
threat-intel Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks Pakistan's Transparent Tribe, a known advanced persistent threat (APT) group, has been aggressively targeting organizations in Afghanistan and India, utilizing a refined toolset including the Patchcord backdoor and other… Dark Reading · Aug 20, 2026 High AFINPAaptsocial engineeringbrowser hijacking
threat-intel Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation Four critical vulnerabilities – affecting macOS, SharePoint, vCenter, and IKE – are currently being actively exploited in the wild. These flaws have led to widespread attacks, including the deployment of ransomware and b… The Hacker News · Aug 19, 2026 Critical CVE-2026-65400CVE-2026-55040CVE-2026-59310DEUSTRvulnerabilitycyberattackransomware
threat-intel Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution.… The Hacker News · Aug 17, 2026 High IRc2dnsgoogle
threat-intel ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-65400CVE-2026-68820CHNOFRexploitvulnerabilityransomware
threat-intel Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware A Chinese-nexus advanced persistent threat (APT) group, suspected to be operating from China, exploited a newly patched VMware vCenter vulnerability (CVE-2026-59310) to deploy Babuk-derived ransomware. The attack involve… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-59309CHGEIRaptvulnerabilityransomware
vulnerability VMware vCenter : des serveurs français compromis A critical vulnerability, CVE-2026-59310, affecting VMware vCenter has been actively exploited since August 3rd, with over 360 compromised IP addresses across 47 countries, including a significant number in France. The v… ZATAZ · Aug 13, 2026 High CVE-2026-59310CVE-2026-47876CVE-2026-59309DEUSTRvulnerabilityexploitreverse shell
threat-intel New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure A Pakistan-aligned threat actor, APT36 (Transparent Tribe), is targeting Afghan telecom providers and critical infrastructure in South Asia with a new backdoor campaign called PATCHCORD. The campaign utilizes sector-spec… The Hacker News · Aug 13, 2026 High CVE-2024-6387AFINbackdoorc2afghanistan
threat-intel Critical VMware vCenter Vulnerability in Attackers’ Crosshairs A critical vulnerability (CVE-2026-59310) in VMware vCenter is being actively exploited by an advanced persistent threat (APT) group, leading to remote code execution and persistent access for attackers. The vulnerabilit… SecurityWeek · Aug 13, 2026 Critical CVE-2026-59310DEUSTRvulnerabilityremote code executionssh
vulnerability Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors are actively exploiting a recently patched critical vulnerability (CVE-2026-59310) in Broadcom VMware vCenter to gain persistent remote access. QUIRSO discovered a campaign involving 361 unique victim IP ad… The Hacker News · Aug 12, 2026 High CVE-2026-59310CVE-2026-59309GEUNTUvulnerabilityexploitreverse_ssh
threat-intel Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Russian state-sponsored threat actors, linked to the Sandworm group, are using fake recruitment campaigns to trick IT professionals in Ukraine into installing malware. They impersonate IT companies like Sopra Steria Bulg… The Hacker News · Aug 11, 2026 High RUUKsocial engineeringvpnrecruitment
vulnerability Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird downloads for Linux after an unencrypted copy was accidentally committed to a private repository. This affects older downloads and requires man… The Hacker News · Aug 11, 2026 High gpgkey revocationgithub breach
threat-intel Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants The Head Mare APT group is exploiting multiple vulnerabilities in TrueConf servers to deliver the PhantomCore and PhantomGraph backdoors. Attackers connect to TrueConf servers without authorization, call a server functio… Securelist · Aug 11, 2026 Critical aptmalwarebackdoor
threat-intel Russian military hackers pose as recruiters to target Ukrainian IT workers Russian military hackers, linked to the Sandworm group (APT44/Seashell Blizzard), are impersonating IT recruiters to target Ukrainian IT workers and install malicious software. The operation involves using legitimate job… The Record · Aug 10, 2026 High UKRUrecruitmentvpnwireguard
threat-intel TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore Russian cybersecurity vendor TrueConf has been repeatedly targeted by the threat actor known as Head Mare, who leverages zero-day vulnerabilities in their server software to deploy a backdoor (PhantomCore) and a related… The Hacker News · Aug 10, 2026 High CVE-2026-3502CHRUzero-dayaptbackdoor
threat-intel Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking A Russian state-sponsored APT group, Storm-2945 (linked to Midnight Blizzard/APT29), is leveraging compromised public Wi-Fi gateway networks to steal Microsoft 365 credentials of traveling employees. The campaign involve… SecurityWeek · Aug 3, 2026 High aptcredential theftdns manipulation
threat-intel Laundry Bear’s webmail hackers had more in store after February, report says Laundry Bear, a Russian state-linked APT group, has been aggressively exploiting vulnerabilities in both Zimbra Collaboration Suite’s webmail platform and Microsoft Outlook Web Access (OWA) to steal emails and credential… The Record · Jul 29, 2026 High CVE-2026-42897NLUSRUaptvulnerabilityzero-day