Threat Actors Favor Rclone, WinSCP and cURL as Data Exfiltration ToolsInfosecurity Magazine·Aug 9, 10:00 UTC · Aug 9, 2024Threat actor60
When employees leave, is your data walking out the door?Help Net Security·Dec 29, 00:00 UTC · Dec 29, 2021Threat actor60
Cyera enhances its AI-powered data security platform to stop sensitive data exfiltrationHelp Net Security·Apr 27, 08:27 UTC · Apr 27, 2023Threat actor60
Talos uncovers espionage campaigns targeting CIS countries, embassies and EU health care agencyCisco Talos·Mar 14, 11:00 UTC · Mar 14, 2023Threat actor60
BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage ActivitiesRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2020-35730CVE-2023-23397CVE-2020-12641+1 CVEs60
New ‘Curly’ threat actor found targeting sensitive organizations in Georgia, MoldovaThe Record·Aug 13, 19:59 UTC · Aug 13, 2025Threat actor60
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devicesCisco Talos·Apr 24, 15:54 UTC · Apr 24, 2024Threat actorCVE-2025-20333CVE-2025-20362CVE-2025-20363+3 CVEs60
New APT Group Red Stinger Targets Military and Critical Infrastructure in Eastern EuropeThe Hacker News·May 11, 16:52 UTC · May 11, 2023Threat actor60
Menlo Security delivers unified governance and threat prevention for AI agents and humansHelp Net Security·Mar 25, 09:56 UTC · Mar 25, 2026Threat actor60
Chinese Hackers Murky, Genesis, and Glacial Panda Escalate Cloud and Telecom EspionageThe Hacker News·Feb 24, 14:01 UTC · Feb 24, 2026Threat actorCVE-2023-3519CVE-2025-3928CVE-2016-5195+1 CVEs60
Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of SecretsThe Hacker News·Nov 27, 03:43 UTC · Nov 27, 2025Threat actor160
CISA warns of ‘significant’ threat to federal networks after nation-state hackers stole F5 source code, undisclosed bug infoThe Record·Oct 15, 16:56 UTC · Oct 15, 2025Threat actor in the wildCVE-2023-4674760
SOC files: an APT41 attack on government IT services in AfricaKaspersky Securelist·Jul 21, 08:00 UTC · Jul 21, 2025Threat actor60
France links Russian APT28 to attacks on dozen French entitiesSecurity Affairs·Apr 30, 13:58 UTC · Apr 30, 2025Threat actorCVE-2023-2339760
Exposed: Russian military Unit 29155 does digital sabotage, espionageHelp Net Security·Dec 24, 13:27 UTC · Dec 24, 2024Threat actor60
Researchers Uncover Years-Long Cyber Espionage on Foreign Embassies in BelarusThe Hacker News·Aug 12, 05:47 UTC · Aug 12, 2023Threat actor60
Multi-modal data protection with AI’s helpHelp Net Security·Aug 4, 00:00 UTC · Aug 4, 2023Threat actor160
Southeast Asian hacking crew racks up victims, rapidly expands criminal campaignCyberScoop·May 31, 08:00 UTC · May 31, 2023Threat actor in the wild60
FBI disrupts sophisticated Russian cyberespionage operationCyberScoop·May 9, 16:00 UTC · May 9, 2023Threat actor in the wild60
Threat actors continue to exploit Log4Shell in VMware Horizon SystemsSecurity Affairs·Jun 24, 15:08 UTC · Jun 24, 2022Threat actorCVE-2021-44228CVE-2022-2295460
Microsoft Uncovers New Details of Russian Hacking Campaign Targeting UkraineThe Hacker News·Feb 5, 07:15 UTC · Feb 5, 2022Threat actor60
North Korea-linked Lazarus APT targets defense industrySecurity Affairs·Feb 25, 17:50 UTC · Feb 25, 2021Threat actor60
Two observations about the Italian EyePyramid espionage campaignSecurity Affairs·Jan 13, 07:26 UTC · Jan 13, 2017Threat actor60
Wild Neutron – Economic espionage threat actor returns with new tricksKaspersky Securelist·Jul 8, 13:04 UTC · Jul 8, 2015Threat actorCVE-2012-321360
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate SystemsRecorded Future·Jun 24, 00:00 UTC · Jun 24, 2026Threat actor60
MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 CountriesThe Hacker News·May 27, 09:52 UTC · May 27, 2026Threat actor60
State-sponsored actors, better known as the friends you don’t wantCisco Talos·May 12, 10:00 UTC · May 12, 2026Threat actor60
Thousands of Adobe Commerce stores hacked in competing CosmicSting campaignsSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Threat actorCVE-2024-3410260
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking CampaignThe Hacker News·Apr 8, 16:11 UTC · Apr 8, 2026Threat actorCVE-2023-50224160
APT37 combines cloud storage and USB implants to infiltrate airSecurity Affairs·Mar 2, 12:38 UTC · Mar 2, 2026Threat actor60
Chinese Hackers Use Anthropic's AI to Launch Automated Cyber Espionage CampaignThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Threat actor in the wild60
Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage CampaignRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actorCVE-2023-2339760
Detections in the Sky: Sigma Rules to Enhance Cloud Security for the Big ThreeRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actor160
Nation-state group CL-STA-0969 targeted Southeast Asian telecoms in 2024Security Affairs·Aug 4, 07:29 UTC · Aug 4, 2025Threat actorCVE-2016-5195CVE-2021-4034CVE-2021-315660
SAP cyberattack widens, drawing Salt Typhoon and Volt Typhoon comparisonsCyberScoop·May 15, 17:45 UTC · May 15, 2025Threat actor in the wild60
Fancy Bear campaign sought emails of high-level Ukrainians and their military suppliersCyberScoop·May 15, 09:00 UTC · May 15, 2025Threat actor in the wildCVE-2024-1118260
Russia-Linked APT28 Exploited MDaemon ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2025Threat actor in the wildCVE-2020-12641CVE-2020-35730CVE-2021-44026+3 CVEs60
Hacktivist Attacks on India Overstated Amid APT36 Espionage ThreatInfosecurity Magazine·May 12, 17:00 UTC · May 12, 2025Threat actor60
Volt Typhoon hackers were in Massachusetts utility’s systems for 10 monthsThe Record·Mar 12, 18:53 UTC · Mar 12, 2025Threat actor60