Skip to main content
← All Tags

Threat Intelligence

75 articles in this category (Page 1 of 4)

AI NewsCybersecurityThreat Intelligence

Chinese State-Backed Hackers Target Southeast Asian Militaries with Custom Malware

Chinese threat actor CL-STA-1087 has targeted Southeast Asian military systems since 2020 using custom backdoors like AppleChris and MemFun for espionage.

Read more
AI NewsCybersecurityThreat Intelligence

Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries

Google disrupted China-linked threat actor UNC2814, which breached 53 organizations in 42 countries using the GRIDTIDE backdoor and Google Sheets API for C2.

Read more
AI NewsCybersecurityThreat Intelligence

ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, and Ransomware Surges

2025 saw a 49% increase in ransomware groups targeting industrial organizations, while OpenSSL patched a critical RCE buffer overflow and RMM abuse surged 277%.

Read more
AI NewsCybersecurityThreat Intelligence

0-Click AI Prompt RCE and Other Emerging Cyber Threats

A zero-click remote code execution vulnerability in Claude Desktop Extensions has been discovered, posing a significant risk to over 10,000 active users.

Read more
AI NewsCybersecurityThreat Intelligence

Infy Hackers Revive Operations with New C2 Servers and Tornado Malware

Infy hackers resume operations post-Iran internet blackout, deploying Tornado malware and Telegram C2, with over 118 exfiltrated files since February 2025.

Read more
AI NewsCybersecurityThreat Intelligence

Cyber Threats Evolve with Increased Operational Efficiency

Threat actors are leveraging automation, prebuilt frameworks, and reusable infrastructure to cut time between access and impact, with over 10,000 infected IP addresses globally tied to the SystemBC malware operation.

Read more
AI NewsCybersecurityThreat Intelligence

China-Linked Amaranth-Dragon and Mustang Panda Exploit WinRAR Flaw in Espionage Campaigns

China-linked threat actors Amaranth-Dragon and Mustang Panda target Southeast Asian governments using WinRAR exploit and PlugX phishing lures, affecting at least 6 countries.

Read more
AI NewsCybersecurityThreat Intelligence

Agentic AI Becomes Top Cyber Threat in 2026

48% of respondents believe agentic AI will be the top attack vector for cybercriminals by the end of 2026, citing increased adoption and vulnerability to attacks.

Read more
AI NewsCybersecurityThreat Intelligence

Google Disrupts IPIDEA — One of the World’s Largest Residential Proxy Networks

Google dismantled IPIDEA, a residential proxy network used by 550+ threat groups to hijack millions of consumer devices for cybercrime and espionage.

Read more
AI NewsCybersecurityThreat Intelligence

Cyber Threats Evolve: 25+ Stories of Exploits, Scams, and Emerging Risks

A weekly ThreatsDay Bulletin reveals over 25 cyber attack stories, including major cybercrime forum takedowns, WhatsApp privacy claims challenged, and post-quantum cryptography shifts.

Read more
AI NewsCybersecurityThreat Intelligence

Continuous Threat Exposure Management in Practice

CTEM helps cybersecurity teams identify and prioritize exploitable risks using threat intelligence and testing, with over 40,000 vulnerabilities reported in 2024.

Read more
AI NewsCybersecurityThreat Intelligence

Pakistan-Linked Hackers Target Indian Government with Novel Golang Malware

Pakistan-linked threat actors launched two campaigns, 'Gopher Strike' and 'Sheet Attack', successfully targeting Indian government entities with advanced persistent threat (APT) techniques.

Read more
AI NewsCybersecurityThreat Intelligence

Konni Hackers Deploy AI-Generated PowerShell Backdoor Against Blockchain Developers

North Korean group Konni is leveraging AI-assisted PowerShell malware, resulting in a multi-stage attack chain targeting blockchain development environments.

Read more
AI NewsCybersecurityThreat Intelligence

Sandworm Blamed for Wiper Attack on Polish Power Grid

Researchers attributed the failed attempt to the infamous Russian APT Sandworm, which is notorious for wiper attacks on critical infrastructure.

Read more
AI NewsCybersecurityThreat Intelligence

Critical Security Flaws and Emerging Threats in Cybersecurity

Over 884 vulnerabilities were exploited for the first time in 2025, with network edge devices being the most frequently targeted, highlighting the urgency for organizations to act quickly on newly disclosed vulnerabilities.

Read more
AI NewsCybersecurityThreat Intelligence

New DynoWiper Malware Used in Attempted Sandworm Attack on Polish Power Sector

ESET links Russia-backed Sandworm to a failed December 2025 cyberattack using DynoWiper malware against Poland’s power and renewable energy systems.

Read more
AI NewsCybersecurityThreat Intelligence

DPRK Actors Leverage VS Code Tunnels for Stealthy Remote Access

A North Korean spear-phishing campaign utilizes legitimate Microsoft VS Code tunneling to establish remote access, bypassing traditional security measures.

Read more
AI NewsCybersecurityThreat Intelligence

North Korean PurpleBravo Campaign Targeted 3,136 IPs via Fake Job Interviews

North Korean PurpleBravo hackers targeted 3,136 IP addresses and 20 companies with malicious VS Code projects and BeaverTail malware.

Read more
AI NewsCybersecurityThreat Intelligence

Fortinet Exploits, AI-Powered Attacks & Emerging Malware Dominate Recent Cybersecurity Landscape

This week’s recap highlights a critical Fortinet vulnerability and the rise of sophisticated attacks leveraging AI and evolving malware frameworks.

Read more
AI NewsCybersecurityThreat Intelligence

China-Linked APT Exploits Sitecore Zero-Day in Critical Infrastructure Intrusions

Cisco Talos reports China-linked APT UAT-8837 leveraging a Sitecore zero-day (CVE-2025-53690, CVSS 9.0) against North American critical infrastructure.

Read more
AI NewsCybersecurityThreat Intelligence

LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing

China-linked attackers deployed the LOTUSLITE backdoor against U.S. government targets via Venezuela-themed phishing, highlighting continued reliance on DLL side-loading.

Read more
AI NewsCybersecurityThreat Intelligence

AI-Powered Voice Cloning Bypass and Telecom Security Concerns Dominate This Week’s Threats

This week’s security bulletin highlights a new AI voice cloning evasion technique, a $26M crypto hack, and increased scrutiny of telecom security practices.

Read more
AI NewsCybersecurityThreat Intelligence

Microsoft Disrupts RedVDS Cybercrime Service, Seizing Key Infrastructure

Microsoft collaborated with law enforcement to disrupt RedVDS, a cybercrime-as-a-service operation responsible for stealing millions, seizing two key domains.

Read more
AI NewsCybersecurityThreat Intelligence

Oceania Sees Rise in Cyberattacks Targeting Retail and Services

A new report reveals that retail and construction sectors in Australia and New Zealand experienced more cyberattacks in 2025 than critical infrastructure.

Read more