Before SolarWinds, US officials say SVR began stealthily targeting cloud services in 2018CyberScoop·Apr 26, 17:24 UTC · Apr 26, 2021Data breach in the wild60
Russia’s SVR spy agency scanned for Microsoft Exchange Server bug, UK and US sayCyberScoop·May 7, 17:05 UTC · May 7, 2021Exploit / PoC in the wild160
White House slaps sanctions on Russian cyber activities while blaming SVR for SolarWinds campaignCyberScoop·Apr 15, 18:31 UTC · Apr 15, 2021Threat actor in the wild60
German political party targeted by SVR-linked group in spearphishing campaign, Mandiant saysCyberScoop·Mar 22, 17:52 UTC · Mar 22, 2024Threat actor in the wild60
Agencies warn about Russian government hackers going after unpatched vulnerabilitiesCyberScoop·Oct 11, 15:58 UTC · Oct 11, 2024Vulnerability in the wild60
Russian SVR-Linked APT29 Targets JetBrains TeamCity Servers in Ongoing AttacksThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Threat actor in the wildCVE-2023-4279360
Evidence suggests Russia's SVR is still using 'WellMess' malware, despite US warningsCyberScoop·Jul 30, 14:19 UTC · Jul 30, 2021Malware in the wild60
U.S. government accuses Russian companies of recruiting spies, hacking for MoscowCyberScoop·Apr 16, 13:48 UTC · Apr 16, 2021Exploit / PoC in the wild60
Cozy Bear Hackers Target JetBrains TeamCity Servers in Global CampaignInfosecurity Magazine·Dec 14, 15:30 UTC · Dec 14, 2023Threat actorCVE-2023-4279360
Russia-linked APT29 spotted targeting JetBrains TeamCity serversSecurity Affairs·Dec 14, 15:12 UTC · Dec 14, 2023Threat actorCVE-2023-4279360
Five Eyes nations warn of evolving Russian cyberespionage practices targeting cloud environmentsCyberScoop·Feb 26, 17:18 UTC · Feb 26, 2024Threat actor in the wild60
Russian cyberspies targeted the Slovak government for monthsThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Exploit / PoC60
Top 12 Security Flaws Russian Spy Hackers Are Exploiting in the WildThe Hacker News·May 11, 06:23 UTC · May 11, 2021Exploit / PoCCVE-2018-13379CVE-2019-9670CVE-2019-11510+9 CVEs60
UK and US share more vulnerabilities exploited by Russia's APT29 hackersThe Record·Dec 9, 00:00 UTC · Dec 9, 2022Vulnerability in the wildCVE-2018-13379CVE-2019-1653CVE-2019-2725+9 CVEs60
FBI, CISA Uncover Tactics Employed by Russian Intelligence HackersThe Hacker News·Apr 28, 06:42 UTC · Apr 28, 2021Data breachCVE-2019-19781CVE-2018-13379CVE-2019-9670+2 CVEs60
NSA, FBI, DHS expose Russian intelligence hacking tradecraftCyberScoop·Apr 15, 13:56 UTC · Apr 15, 2021Exploit / PoC in the wild60
Did Someone at the Commerce Dept. Find a SolarWinds Backdoor in Aug. 2020?Krebs on Security·Apr 15, 00:00 UTC · Apr 15, 2021MalwareCVE-2020-400660
Threat AdvisoryCisco Talos·Dec 19, 16:50 UTC · Dec 19, 2025Advisory in the wildCVE-2026-20182CVE-2025-20333CVE-2025-20362+6 CVEs160
CISA Warns of Threat Actors Exploiting F5 BIGThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2024Threat actorCVE-2022-27924CVE-2023-4279360
Russian foreign intelligence hackers gain access to top Microsoft officials, company saysCyberScoop·Jan 19, 23:30 UTC · Jan 19, 2024Exploit / PoC in the wild60
SolarWinds says fewer than 100 customers were impacted by supply chain attackThe Record·Dec 9, 00:00 UTC · Dec 9, 2022Exploit / PoC60
Russian hacking unit Cozy Bear adds Google Drive to its arsenal, researchers sayCyberScoop·Jul 19, 10:00 UTC · Jul 19, 2022Threat actor in the wild60
US spy agencies review software suppliers' ties to Russia following SolarWinds hackCyberScoop·May 6, 21:22 UTC · May 6, 2021Exploit / PoC in the wild60
SEC hits four companies with fines for misleading disclosures around SolarWinds hackCyberScoop·Oct 22, 16:01 UTC · Oct 22, 2024Policy & legal55
Exclusive: Russian spies hacked UK government systems earlier this year, stole data and emailsThe Record·Aug 8, 00:00 UTC · Aug 8, 2024Data breach60
Hackers are increasingly hiding within services such as Slack and Trello to deploy malwareCyberScoop·Aug 16, 13:00 UTC · Aug 16, 2023Malware in the wild60
Denmark warns of Russian spies posing as ‘journalists or business people’The Record·May 5, 13:26 UTC · May 5, 2023Threat actor60
Ex-NSA employee charged with violating Espionage Act, selling U.S. cyber secretsCyberScoop·Sep 29, 22:37 UTC · Sep 29, 2022Threat actor in the wild60
CMC Networks chooses Juniper Networks to offer managed AI-driven SD-WAN solution in AfricaHelp Net Security·Jul 15, 00:00 UTC · Jul 15, 2021Industry55
SolarWinds hackers are behind a widespread phishing campaign impersonating USAID, Microsoft saysCyberScoop·May 28, 14:19 UTC · May 28, 2021Threat actor in the wild60
Threat Source Newsletter (April 22, 2021)Cisco Talos·Apr 22, 18:00 UTC · Apr 22, 2021Ransomware in the wild60
Russia's SolarWinds Attack and Software SecuritySchneier on Security·Jan 8, 12:27 UTC · Jan 8, 2021Data breach60
FireEye's Mandia on SolarWinds hack: 'This was a sniper round'CyberScoop·Dec 21, 14:51 UTC · Dec 21, 2020Data breach in the wild60
Pavlov’s Digital House: Russia Focuses Inward for Vulnerability AnalysisRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025VulnerabilityCVE-2018-814860
SolarWinds Releases Hotfix for Critical CVE-2025The Hacker News·Sep 23, 12:46 UTC · Sep 23, 2025Exploit / PoC in the wildCVE-2025-26399CVE-2024-28988CVE-2024-2898660
Amazon Stops Russian APT29 Watering Hole AttackInfosecurity Magazine·Sep 1, 11:00 UTC · Sep 1, 2025Threat actor60
Threats to the 2025 NATO Summit: Cyber, Influence, and Hybrid RisksRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actor60
Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove OtherwiseThe Hacker News·Jun 9, 11:00 UTC · Jun 9, 2025Data breach60