The life and times of Cozy Bear, the Russian hackers who just hit Microsoft and HPEArs Technica · Security·Jan 26, 13:15 UTC · Jan 26, 2024Threat actor160
The Dutch intelligence service AIVD 'hacked' Russian Cozy Bear systems for yearsSecurity Affairs·Jan 26, 10:40 UTC · Jan 26, 2018Threat actor57
How the Russian hacking group Cozy Bear, suspected in the SolarWinds breach, plays the long gameCyberScoop·Dec 18, 21:04 UTC · Dec 18, 2020Threat actor57
Exclusive - Hunting Cozy Bear, new campaign, old habitsSecurity Affairs·Nov 23, 10:38 UTC · Nov 23, 2018Threat actor57
Cozy Bear revisits one of its greatest hits, researchers say: election skulduggeryCyberScoop·May 27, 20:21 UTC · May 27, 2021Threat actor in the wild60
Cozy Bear Hackers Target JetBrains TeamCity Servers in Global CampaignInfosecurity Magazine·Dec 14, 15:30 UTC · Dec 14, 2023Threat actorCVE-2023-4279360
Cozy Bear targets NGOs and Think Tanks in postSecurity Affairs·Nov 12, 09:26 UTC · Nov 12, 2016Threat actor57
Someone is using the 'Cozy Bear' moniker to scare DDoS victims into bitcoin paymentsCyberScoop·Nov 18, 14:47 UTC · Nov 18, 2019Threat actor in the wild60
Cozy Bear kept moving after 2016 election, ESET saysCyberScoop·Oct 17, 13:33 UTC · Oct 17, 2019Threat actor in the wild60
Cozy Bear targets EU diplomats with wine-tasting invites (again)Help Net Security·Apr 16, 00:00 UTC · Apr 16, 2025Threat actor57
Russia-linked Cozy Bear uses evasive TTPs to target Microsoft 365Security Affairs·Aug 19, 23:20 UTC · Aug 19, 2022Threat actor160
Cyber-espionage operation on embassies linked to Russia’s Cozy Bear hackersThe Record·Nov 14, 16:45 UTC · Nov 14, 2023Threat actorCVE-2023-3883160
Hewlett Packard Enterprise tells SEC it was breached by Russia’s 'Cozy Bear' hackersThe Record·Jan 24, 22:25 UTC · Jan 24, 2024Data breach145
TeamViewer says Russia’s ‘Cozy Bear’ hackers attacked corporate IT systemThe Record·Jun 28, 18:54 UTC · Jun 28, 2024Threat actor57
Russian hacking unit Cozy Bear adds Google Drive to its arsenal, researchers sayCyberScoop·Jul 19, 10:00 UTC · Jul 19, 2022Threat actor in the wild60
Enriching User Behavior Analytics With Threat IntelligenceRecorded Future·Jun 24, 00:00 UTC · Jun 24, 2026Exploit / PoC60
Microsoft critics accuse the firm of ‘negligence’ in latest breachCyberScoop·Jan 24, 15:58 UTC · Jan 24, 2024Data breach45
Russian Hackers get Cozy with American PoliticsSecurity Affairs·Nov 3, 18:00 UTC · Nov 3, 2017Malware42
APT29 hit German political parties with bogus invites and malwareHelp Net Security·Mar 25, 00:00 UTC · Mar 25, 2024Malware42
APTs use of lesser-known TTPs are no less of a headacheHelp Net Security·Apr 23, 13:37 UTC · Apr 23, 2026Exploit / PoC60
German political party targeted by SVR-linked group in spearphishing campaign, Mandiant saysCyberScoop·Mar 22, 17:52 UTC · Mar 22, 2024Threat actor in the wild60
The Snake APT Group is preparing its offensive against highSecurity Affairs·May 5, 13:12 UTC · May 5, 2017Threat actor57
Kaspersky discovers overlap between SolarWinds hack, TurlaCyberScoop·Jan 11, 16:22 UTC · Jan 11, 2021Threat actor in the wild60
Week in review: LLM package hallucinations harm supply chains, Nagios Log Server flaws fixedHelp Net Security·Apr 20, 00:00 UTC · Apr 20, 2025RansomwareCVE-2025-31200CVE-2025-31201CVE-2025-24054+1 CVEs60
Three Dutch banks and Tax Agency under DDoS Attacks ... is it a Russian job?Security Affairs·Jan 30, 18:24 UTC · Jan 30, 2018Malware55
Russia-linked APT29 group changes TTPs following April advisoriesSecurity Affairs·May 7, 21:03 UTC · May 7, 2021Threat actorCVE-2021-26855CVE-2018-13379CVE-2019-1653+9 CVEs50
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS MalwareThe Hacker News·Feb 24, 14:21 UTC · Feb 24, 2026Malware30
UK NCSC blames APT29 for attacks on COVIDSecurity Affairs·Jul 16, 14:46 UTC · Jul 16, 2020Threat actor60
Russia-linked APT29 targets diplomatic and government organizationsSecurity Affairs·May 2, 05:34 UTC · May 2, 2022Threat actor57
New report unearths the expertise in Russian hackers' codeCyberScoop·Sep 9, 17:00 UTC · Sep 9, 2016Exploit / PoC in the wild60
The many ways electric cars are vulnerable to hacks, and whether that matters in a realCisco Talos·Feb 1, 19:00 UTC · Feb 1, 2024Exploit / PoC60
Evidence suggests Russia's SVR is still using 'WellMess' malware, despite US warningsCyberScoop·Jul 30, 14:19 UTC · Jul 30, 2021Malware in the wild60
Russian Adversaries Target DropBox and Google Drive in New CampaignInfosecurity Magazine·Jul 20, 14:45 UTC · Jul 20, 2022Threat actor57
HPE is notifying individuals affected by a December 2023 attackSecurity Affairs·Feb 10, 21:03 UTC · Feb 10, 2025Data breach57
Russia-linked APT group Midnight Blizzard hacked HPESecurity Affairs·Jan 25, 08:20 UTC · Jan 25, 2024Threat actor57
DNC officials say Russians unsuccessfully tried to hack them after 2018 midtermsCyberScoop·Jan 18, 18:31 UTC · Jan 18, 2019Data breach in the wild60
Russian hackers breached Microsoft customer support to try phishing targets in 36 countriesCyberScoop·Jun 28, 13:46 UTC · Jun 28, 2021Data breach in the wild60
Russian hackers accessed Microsoft source codeCyberScoop·Mar 8, 20:41 UTC · Mar 8, 2024Data breach160