Operation “Armor Piercer:” Targeted attacks in the Indian subcontinent using commercial RATsCisco Talos·Sep 23, 12:01 UTC · Sep 23, 2021Vulnerability42
DoNot’s Firestarter abuses Google Firebase Cloud Messaging to spreadCisco Talos·Oct 29, 12:00 UTC · Oct 29, 2020Vulnerability42
‘DealersChoice’ is Sofacy’s Flash Player Exploit PlatformPalo Alto Unit 42·Nov 1, 10:25 UTC · Nov 1, 2018Vulnerability42
A new version of Triada spreads embedded in the firmware of Android devicesKaspersky Securelist·Apr 25, 10:00 UTC · Apr 25, 2025Vulnerability42
SideWinder APT’s postKaspersky Securelist·Oct 15, 10:00 UTC · Oct 15, 2024VulnerabilityCVE-2017-1188247
Tropic Trooper Targets Taiwanese Government and Fossil Fuel Provider With Poison IvyPalo Alto Unit 42·Nov 1, 10:39 UTC · Nov 1, 2018VulnerabilityCVE-2012-015835
Fresh Baked HOMEKit-made CooklesPalo Alto Unit 42·Nov 1, 10:21 UTC · Nov 1, 2018VulnerabilityCVE-2012-015835
The game is over: when “free” comes at too high a price. What we know about RenEngineKaspersky Securelist·Feb 11, 14:00 UTC · Feb 11, 2026Vulnerability30
UPS: Observations on CVE-2015-3113, Prior ZeroPalo Alto Unit 42·Nov 1, 09:48 UTC · Nov 1, 2018VulnerabilityCVE-2015-3113CVE-2014-1776CVE-2014-633260
ToddyCat: Unveiling an unknown APT actor attacking highKaspersky Securelist·Jun 21, 10:00 UTC · Jun 21, 2022Vulnerability42
Evilgrab Delivered by Watering Hole Attack on President of Myanmar’s WebsitePalo Alto Unit 42·Nov 1, 09:46 UTC · Nov 1, 2018VulnerabilityCVE-2014-633235
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Multiple vulnerabilities in TP-Link Omada system could lead to root accessCisco Talos·Jun 26, 16:00 UTC · Jun 26, 2024VulnerabilityCVE-2023-49906CVE-2023-49913CVE-2023-48724+11 CVEs47
Following the LNK metadata trailCisco Talos·Jan 19, 13:00 UTC · Jan 19, 2023VulnerabilityCVE-2015-009635
PSA: Conference Invite used as a Lure by Operation Lotus Blossom ActorsPalo Alto Unit 42·Nov 1, 10:25 UTC · Nov 1, 2018VulnerabilityCVE-2012-015860
Digital skimmer runs entirely on Google, defeats CSPSansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability30
Attackers Conducting Cryptojacking Operation Against U.S. Education OrganizationsPalo Alto Unit 42·Jun 6, 13:25 UTC · Jun 6, 2024Vulnerability42
“Cyber Conflict” Decoy Document Used In Real Cyber ConflictCisco Talos·Oct 22, 16:22 UTC · Oct 22, 2017Vulnerability30
Cisco Talos Honeypot Analysis Reveals Rise in Attacks on Elasticsearch ClustersCisco Talos·Feb 26, 18:56 UTC · Feb 26, 2019Vulnerability in the wildCVE-2014-3120CVE-2015-1427CVE-2018-7600+2 CVEs60
ProjectM: Link Found Between Pakistani Actor and Operation Transparent TribePalo Alto Unit 42·Nov 1, 10:11 UTC · Nov 1, 2018VulnerabilityCVE-2010-3333CVE-2012-015835
Korea In The CrosshairsCisco Talos·Jan 16, 05:57 UTC · Jan 16, 2018VulnerabilityCVE-2013-0808CVE-2017-019935
Playing Cat and Mouse: Three Techniques Abused to Avoid DetectionSecurity Affairs·May 23, 10:17 UTC · May 23, 2019VulnerabilityCVE-2017-019935
Cloud Atlas group acquires PowerCloud, ReverseSocks, SSHKaspersky Securelist·May 22, 09:12 UTC · May 22, 2026VulnerabilityCVE-2018-080247
“Keeper” Magecart Group Infects 570 SitesRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability30
Weaponization of Excel Add-Ins Part 2: Dridex Infection Chain Case StudiesPalo Alto Unit 42·Jun 5, 20:44 UTC · Jun 5, 2024Vulnerability30
Hackers can abuse Microsoft Teams updater to deliver malicious payloadsSecurity Affairs·Aug 6, 05:12 UTC · Aug 6, 2020Vulnerability30
Inception Attackers Target Europe with YearPalo Alto Unit 42·Mar 19, 16:47 UTC · Mar 19, 2019VulnerabilityCVE-2017-11882CVE-2012-185647
Korean MalDoc Drops Evil New Years PresentsCisco Talos·Feb 23, 15:00 UTC · Feb 23, 2017Vulnerability30
The Mystery of Duqu: Part FiveKaspersky Securelist·Nov 15, 18:15 UTC · Nov 15, 2011VulnerabilityCVE-2011-340235
APT group ToddyCat exploits a vulnerability in ESET for DLL proxyingKaspersky Securelist·Apr 7, 10:01 UTC · Apr 7, 2025VulnerabilityCVE-2024-11859CVE-2021-3627647
Kaspersky report on APT trends in Q3 2024Kaspersky Securelist·Nov 28, 10:00 UTC · Nov 28, 2024Vulnerability42
Google OAuth client library flaw allowed to deploy malicious payloadsSecurity Affairs·May 23, 19:04 UTC · May 23, 2022VulnerabilityCVE-2021-2257347
Mirai code reSecurity Affairs·Apr 16, 08:57 UTC · Apr 16, 2021VulnerabilityCVE-2017-17215CVE-2018-10561CVE-2014-836147
New Cyber Operation Targets Italy: Digging Into the Netwire Attack ChainSecurity Affairs·Jun 5, 18:26 UTC · Jun 5, 2020Vulnerability30
Analysis of CVE-2018-8174 VBScript 0day and APT actor related to Office targeted attackSecurity Affairs·May 10, 05:31 UTC · May 10, 2018VulnerabilityCVE-2018-8174CVE-2017-019947
Cloud Atlas: RedOctober APT is back in styleKaspersky Securelist·Dec 10, 10:03 UTC · Dec 10, 2014VulnerabilityCVE-2012-015847
eScan Antivirus Update Servers Compromised to Deliver MultiThe Hacker News·Feb 2, 05:47 UTC · Feb 2, 2026Vulnerability42