threat-intel N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete N-able has revealed that attackers exploited a vulnerability in its N-central remote monitoring and management platform to gain remote administrative access to customer systems. Despite a patch release, attackers continued to exploit an alternate path, leading to a wider range of affected versions and requiring custome… The Hacker News · Aug 3, 2026 High CVE-2026-18577CVE-2026-18556FIauthenticationremote accessvulnerability
threat-intel Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays The Iranian state-backed hacking group Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is deploying a new campaign targeting entities across the Middle East, Africa, and South… The Hacker News · Jul 28, 2026 High IREGJOwindowsbackdoortunneling
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
threat-intel Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin… WeLiveSecurity · Jun 25, 2026 HighCVSS 8.8 CVE-2025-8088RUcyberespionagerussiaspearphishing