Spam campaign targeting Brazil abuses Remote Monitoring and Management toolsCisco Talos·May 8, 10:00 UTC · May 8, 2025Threat actor57
Threat actor believed to be spreading new MedusaLocker variant since 2022Cisco Talos·Oct 3, 10:00 UTC · Oct 3, 2024Threat actor57
Threat actors using MacroPack to deploy Brute Ratel, Havoc and PhantomCore payloadsCisco Talos·Sep 3, 13:14 UTC · Sep 3, 2024Threat actor45
APT41 likely compromised Taiwanese government-affiliated research institute with ShadowPad and Cobalt StrikeCisco Talos·Aug 1, 12:00 UTC · Aug 1, 2024Threat actorCVE-2018-0824160
SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniquesCisco Talos·Jun 21, 12:00 UTC · Jun 21, 2024Threat actor45
New details on TinyTurla’s post-compromise activity reveal full kill chainCisco Talos·Mar 21, 13:08 UTC · Mar 21, 2024Threat actor57
TinyTurla-NG in-depth tooling and command and control analysisCisco Talos·Feb 22, 13:00 UTC · Feb 22, 2024Threat actor157
Operation Blacksmith: Lazarus targets organizations worldwide using novel TelegramCisco Talos·Dec 11, 13:50 UTC · Dec 11, 2023Threat actorCVE-2021-4422860
Malicious campaigns target government, military and civilian entities in Ukraine, PolandCisco Talos·Jul 13, 10:45 UTC · Jul 13, 2023Threat actor145
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agencyCisco Talos·Mar 14, 11:00 UTC · Mar 14, 2023Threat actor60
New campaign uses government, union-themed lures to deliver Cobalt Strike beaconsCisco Talos·Sep 28, 12:12 UTC · Sep 28, 2022Threat actorCVE-2017-019960
Gamaredon APT targets Ukrainian government agencies in new campaignCisco Talos·Sep 15, 13:00 UTC · Sep 15, 2022Threat actor157
Transparent Tribe begins targeting education sector in latest campaignCisco Talos·Jul 13, 23:58 UTC · Jul 13, 2022Threat actor57
What’s with the shared VBA code between Transparent Tribe and other threat actors?Cisco Talos·Feb 9, 13:05 UTC · Feb 9, 2022Threat actor57
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devicesCisco Talos·Apr 24, 15:54 UTC · Apr 24, 2024Threat actorCVE-2025-20333CVE-2025-20362CVE-2025-20363+3 CVEs60
Upgraded Aggah malspam campaign delivers multiple RATsCisco Talos·Apr 29, 15:48 UTC · Apr 29, 2020Threat actor57
Threat actors attempt to capitalize on coronavirus outbreakCisco Talos·Feb 13, 19:07 UTC · Feb 13, 2020Threat actor45
SWEED: Exposing years of Agent Tesla campaignsCisco Talos·Jul 15, 15:04 UTC · Jul 15, 2019Threat actorCVE-2017-8759CVE-2017-11882160
Managing SOC Alert Overload with Targeted Threat IntelligenceRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Threat actor45
State-sponsored campaigns target global network infrastructureCisco Talos·Apr 18, 15:02 UTC · Apr 18, 2023Threat actorCVE-2017-674260
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHelp Net Security·Jun 28, 00:00 UTC · Jun 28, 2026Threat actor in the wildCVE-2026-2023060