Lazarus APT steals cryptocurrency and user data via a decoy MOBA gameKaspersky Securelist·Oct 23, 11:00 UTC · Oct 23, 2024Threat actorCVE-2024-494760
Russia-Aligned TAG-70 Targets European Government and Military Mail Servers in New Espionage CampaignRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actorCVE-2023-2339760
Large-scale Citrix NetScaler Gateway credential harvesting campaign exploits CVE-2023Security Affairs·Oct 9, 22:02 UTC · Oct 9, 2023Threat actor in the wildCVE-2023-351960
Russian Espionage Operation Targets Organizations Tied to Ukraine WarInfosecurity Magazine·May 16, 11:15 UTC · May 16, 2025Threat actorCVE-2024-11182CVE-2023-4377060
Cybercriminal adoption of browser fingerprintingHelp Net Security·Apr 5, 00:00 UTC · Apr 5, 2024Threat actor60
Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT TechniquesRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Threat actor60
BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage ActivitiesRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2020-35730CVE-2023-23397CVE-2020-12641+1 CVEs60
Russia-Linked APT28 Exploited MDaemon ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2025Threat actor in the wildCVE-2020-12641CVE-2020-35730CVE-2021-44026+3 CVEs60
Sophisticated Phishing Campaign Targets Ukraine’s Largest BankInfosecurity Magazine·Feb 5, 16:30 UTC · Feb 5, 2025Threat actor60
Phishing campaign targets U.S. Department of Education's G5 portalHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2025Threat actor60
SOC files: an APT41 attack on government IT services in AfricaKaspersky Securelist·Jul 21, 08:00 UTC · Jul 21, 2025Threat actor60
Fancy Bear campaign sought emails of high-level Ukrainians and their military suppliersCyberScoop·May 15, 09:00 UTC · May 15, 2025Threat actor in the wildCVE-2024-1118260
APT28 hacked Roundcube email servers of Ukrainian entitiesSecurity Affairs·Jun 21, 19:20 UTC · Jun 21, 2023Threat actorCVE-2020-35730CVE-2020-12641CVE-2021-44026+1 CVEs60
APT review: what the world’s threat actors got up to in 2019Kaspersky Securelist·Dec 4, 10:00 UTC · Dec 4, 2019Threat actor60
ESET: Vietnamese hacking group hijacks Southeast Asian sites in watering hole campaignCyberScoop·Nov 20, 22:14 UTC · Nov 20, 2018Threat actor in the wild60
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countriesCyberScoop·Jul 23, 20:31 UTC · Jul 23, 2026Threat actor in the wildCVE-2025-6637660
A Browser Extension Risk Guide After the ShadyPanda CampaignThe Hacker News·Jul 9, 15:37 UTC · Jul 9, 2026Threat actor60
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universitiesCyberScoop·Jul 7, 09:00 UTC · Jul 7, 2026Threat actorCVE-2024-42009CVE-2025-4911360
Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploitedHelp Net Security·Jun 28, 00:00 UTC · Jun 28, 2026Threat actor in the wildCVE-2026-2023060
Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaignsHelp Net Security·Jun 19, 12:07 UTC · Jun 19, 2026Threat actor60
Thousands of Adobe Commerce stores hacked in competing CosmicSting campaignsSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Threat actorCVE-2024-3410260
⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & MoreThe Hacker News·Nov 3, 17:59 UTC · Nov 3, 2025Threat actorCVE-2025-61932CVE-2025-55315CVE-2025-10680+18 CVEs160
Amazon Stops Russian APT29 Watering Hole AttackInfosecurity Magazine·Sep 1, 11:00 UTC · Sep 1, 2025Threat actor60
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan TargetsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2022-1040CVE-2022-3019060
I Went to See ‘God’s Influencer,’ the Millennial Saint Carlo Acutis404 Media·Apr 16, 12:40 UTC · Apr 16, 2025Threat actor60
Lazarus Group deceives developers with 6 new malicious npm packagesCyberScoop·Mar 12, 22:31 UTC · Mar 12, 2025Threat actor in the wild160
Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ CountriesThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2025Threat actorCVE-2024-1709CVE-2023-48788CVE-2021-34473+4 CVEs160
Lazarus Group Exploits Google Chrome Flaw in New CampaignInfosecurity Magazine·Oct 24, 17:00 UTC · Oct 24, 2024Threat actorCVE-2024-494760
North Korea-linked APT37 exploited IE zeroSecurity Affairs·Oct 19, 14:07 UTC · Oct 19, 2024Threat actor in the wildCVE-2024-38178CVE-2022-4112860
Nation-State Actors Weaponize Ivanti VPN ZeroThe Hacker News·Jan 17, 01:56 UTC · Jan 17, 2024Threat actor in the wildCVE-2023-46805CVE-2024-21887160
A cascade of compromise: unveiling Lazarus' new campaignKaspersky Securelist·Oct 27, 05:41 UTC · Oct 27, 2023Threat actor160
Ukrainian Military Targeted in Phishing Campaign Leveraging Drone ManualsThe Hacker News·Sep 25, 13:05 UTC · Sep 25, 2023Threat actor60
APT37 used Internet Explorer ZeroSecurity Affairs·Dec 8, 15:08 UTC · Dec 8, 2022Threat actor in the wildCVE-2022-41128CVE-2017-019960
Russia’s Turla group goes trolling with code labeled “TrumpTower”CyberScoop·Jul 15, 20:28 UTC · Jul 15, 2019Threat actor in the wild60
'Cobalt Group' launches new campaign against banks in Romania, RussiaCyberScoop·Aug 30, 22:43 UTC · Aug 30, 2018Threat actor in the wild60
North Korea-linked Lazarus APT behind recent ActiveX attacksSecurity Affairs·Jun 12, 21:09 UTC · Jun 12, 2018Threat actor60
The Epic Turla OperationKaspersky Securelist·Aug 7, 13:55 UTC · Aug 7, 2014Threat actorCVE-2013-5065CVE-2013-3346CVE-2012-172360