OilRig campaign, Iran-Linked Hackers Target US Gov. & Energy GridSecurity Affairs·Jan 27, 20:43 UTC · Jan 27, 2018Threat actor60
China-linked APT group Salt Typhoon compromised some US ISPsSecurity Affairs·Sep 26, 14:04 UTC · Sep 26, 2024Threat actor in the wildCVE-2024-20399CVE-2021-3086960
DOD, DHS expose hacking campaign in Russia, Ukraine, India, MalaysiaCyberScoop·Oct 1, 19:32 UTC · Oct 1, 2020Threat actor in the wild60
Threat actors exploit recently disclosed Atlassian Confluence flaw in cryptomining campaignSecurity Affairs·Jun 10, 20:51 UTC · Jun 10, 2022Threat actor in the wildCVE-2022-2613460
Joint Advisory Warns of PRC-Backed Cyber Espionage Targeting Telecom NetworksThe Hacker News·Dec 6, 03:36 UTC · Dec 6, 2024Threat actor60
RedAlpha Conducts Multi-Year Credential Theft Campaign Targeting Global Humanitarian, Think Tank, and Government OrganizationsRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actor60
Threat actors continue to exploit Log4Shell in VMware Horizon SystemsSecurity Affairs·Jun 24, 15:08 UTC · Jun 24, 2022Threat actorCVE-2021-44228CVE-2022-2295460
Threat actors found a way to bypass mitigation F5 BIGSecurity Affairs·Jul 8, 13:37 UTC · Jul 8, 2020Threat actor in the wildCVE-2020-590260
Threat actors are attempting to exploit recently fixed F5 BIGSecurity Affairs·Jul 8, 12:43 UTC · Jul 8, 2020Threat actor in the wildCVE-2020-590260
Lazarus APT updates its toolset in watering hole attacksKaspersky Securelist·Apr 24, 05:00 UTC · Apr 24, 2025Threat actor60
Iranian Cyber Espionage Group Targets Financial and Government Sectors in Middle EastThe Hacker News·Nov 3, 04:45 UTC · Nov 3, 2023Threat actor60
Salt Typhoon Uses Citrix Flaw in Global CyberInfosecurity Magazine·Oct 20, 13:15 UTC · Oct 20, 2025Threat actor60
Threat actors exploited Palo Alto PanSecurity Affairs·Apr 15, 11:34 UTC · Apr 15, 2024Threat actorCVE-2024-3400160
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devicesCisco Talos·Apr 24, 15:54 UTC · Apr 24, 2024Threat actorCVE-2025-20333CVE-2025-20362CVE-2025-20363+3 CVEs60
The Epic Turla OperationKaspersky Securelist·Aug 7, 13:55 UTC · Aug 7, 2014Threat actorCVE-2013-5065CVE-2013-3346CVE-2012-172360
A large-scale phishing campaign targets WordPress WooCommerce usersSecurity Affairs·Apr 28, 11:43 UTC · Apr 28, 2025Threat actorCVE-2023-4512460
APT28 hacked Roundcube email servers of Ukrainian entitiesSecurity Affairs·Jun 21, 19:20 UTC · Jun 21, 2023Threat actorCVE-2020-35730CVE-2020-12641CVE-2021-44026+1 CVEs60
Large-scale Citrix NetScaler Gateway credential harvesting campaign exploits CVE-2023Security Affairs·Oct 9, 22:02 UTC · Oct 9, 2023Threat actor in the wildCVE-2023-351960
Threat actors exploit discontinues Boa web servers to target critical infrastructureSecurity Affairs·Nov 24, 08:47 UTC · Nov 24, 2022Threat actorCVE-2017-9833CVE-2021-3355860
A cascade of compromise: unveiling Lazarus' new campaignKaspersky Securelist·Oct 27, 05:41 UTC · Oct 27, 2023Threat actor160
Threat Actors Probe Gitea Docker Flaw CVE-2026The Hacker News·Jul 9, 06:04 UTC · Jul 9, 2026Threat actor in the wildCVE-2026-20896160
Threat actors use CVE-2021Security Affairs·Sep 30, 09:17 UTC · Sep 30, 2021Threat actorCVE-2021-2608460
Spying on satellite internet comms with a $300 listening stationSecurity Affairs·Aug 10, 07:00 UTC · Aug 10, 2020Threat actor60
⚡ Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & MoreThe Hacker News·Jan 12, 16:26 UTC · Jan 12, 2026Threat actorCVE-2026-21858CVE-2025-22224CVE-2025-22225+1 CVEs60
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate SystemsRecorded Future·Jun 24, 00:00 UTC · Jun 24, 2026Threat actor60
Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaignsHelp Net Security·Jun 19, 12:07 UTC · Jun 19, 2026Threat actor60
What’s the point of press releases from threat actors?Cisco Talos·Sep 21, 18:00 UTC · Sep 21, 2023Threat actor60
Gauss: Nation-state cyberKaspersky Securelist·Aug 9, 17:00 UTC · Aug 9, 2012Threat actorCVE-2010-256860