Additional Entities Targeted by DarkSide Affiliate, TAG-21; Links to WellMess and Sliver InfrastructureRecorded Future·Jul 15, 00:00 UTC · Jul 15, 2025Ransomware57
White House formally blames Russian intelligence service SVR for SolarWinds hackThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Ransomware57
Before SolarWinds, US officials say SVR began stealthily targeting cloud services in 2018CyberScoop·Apr 26, 17:24 UTC · Apr 26, 2021Data breach in the wild60
Russian foreign intelligence service spotted exploiting JetBrains vulnerabilityThe Record·Dec 13, 18:46 UTC · Dec 13, 2023VulnerabilityCVE-2023-4279347
Russia’s SVR spy agency scanned for Microsoft Exchange Server bug, UK and US sayCyberScoop·May 7, 17:05 UTC · May 7, 2021Exploit / PoC in the wild160
Russian intelligence agency SVR sets up dark web whistleblowing platformThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Vulnerability142
Passwords and much more for 540K SVR Tracking accounts leaked onlineSecurity Affairs·Sep 24, 08:30 UTC · Sep 24, 2017Data breach57
Russia's SVR Targets Zimbra, TeamCity Servers for Cyber EspionageInfosecurity Magazine·Oct 11, 10:45 UTC · Oct 11, 2024Threat actor57
CISA Issues Alert on APT29’s Cloud Infiltration TacticsInfosecurity Magazine·Feb 26, 17:15 UTC · Feb 26, 2024Threat actor57
Fears grow of Russian spies turning to industrial espionageThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Threat actor57
US Issues Russian SVR WarningInfosecurity Magazine·Apr 16, 17:57 UTC · Apr 16, 2021VulnerabilityCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs47
White House slaps sanctions on Russian cyber activities while blaming SVR for SolarWinds campaignCyberScoop·Apr 15, 18:31 UTC · Apr 15, 2021Threat actor in the wild60
German political party targeted by SVR-linked group in spearphishing campaign, Mandiant saysCyberScoop·Mar 22, 17:52 UTC · Mar 22, 2024Threat actor in the wild60
Russia's SVR alleges US is plotting to interfere in presidential electionSecurity Affairs·Mar 12, 14:56 UTC · Mar 12, 2024Threat actor57
Agencies warn about Russian government hackers going after unpatched vulnerabilitiesCyberScoop·Oct 11, 15:58 UTC · Oct 11, 2024Vulnerability in the wild60
Russian SVR-Linked APT29 Targets JetBrains TeamCity Servers in Ongoing AttacksThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Threat actor in the wildCVE-2023-4279360
Former NSA and Cyber Command Chief Keith Alexander on SolarWinds, Cyberwar, and ChinaThe Record·Nov 17, 17:00 UTC · Nov 17, 2022Vulnerability30
Evidence suggests Russia's SVR is still using 'WellMess' malware, despite US warningsCyberScoop·Jul 30, 14:19 UTC · Jul 30, 2021Malware in the wild60
U.S. government accuses Russian companies of recruiting spies, hacking for MoscowCyberScoop·Apr 16, 13:48 UTC · Apr 16, 2021Exploit / PoC in the wild60
Russia cyber spies behind SolarWinds breach adopting new tactics, warn Five Eyes agenciesThe Record·Feb 26, 14:03 UTC · Feb 26, 2024Vulnerability30
US seizes two domains used by the SVR in recent hacking campaignThe Record·Dec 12, 00:00 UTC · Dec 12, 2022Threat actor57
Threat Advisory: NSA SVR Advisory CoverageCisco Talos·Apr 15, 15:45 UTC · Apr 15, 2021AdvisoryCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs147
Passwords For 540,000 Car Tracking Devices Leaked OnlineThe Hacker News·Sep 22, 17:15 UTC · Sep 22, 2017Data breach57
BlueBravo Uses Ambassador Lure to Deploy GraphicalNeutrino MalwareRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Malware42
Cozy Bear Hackers Target JetBrains TeamCity Servers in Global CampaignInfosecurity Magazine·Dec 14, 15:30 UTC · Dec 14, 2023Threat actorCVE-2023-4279360
Russia-linked APT29 spotted targeting JetBrains TeamCity serversSecurity Affairs·Dec 14, 15:12 UTC · Dec 14, 2023Threat actorCVE-2023-4279360
More Russian SVR Supply-Chain AttacksSchneier on Security·Oct 28, 11:12 UTC · Oct 28, 2021Threat actor57
UK/US: Patch These 11 Bugs Now to Thwart Russian SpiesInfosecurity Magazine·May 10, 11:40 UTC · May 10, 2021Vulnerability42
Russia-linked APT29 group changes TTPs following April advisoriesSecurity Affairs·May 7, 21:03 UTC · May 7, 2021Threat actorCVE-2021-26855CVE-2018-13379CVE-2019-1653+9 CVEs50
SOLARDEFLECTION C2 Infrastructure Used by NOBELIUM in Company Brand MisuseRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actor145
Russia-linked APT29 switched to targeting cloud servicesSecurity Affairs·Jun 30, 12:31 UTC · Jun 30, 2024Threat actor57
Five Eyes Agencies Expose APT29's Evolving Cloud Attack TacticsThe Hacker News·Feb 28, 03:29 UTC · Feb 28, 2024Threat actor57
Five Eyes nations warn of evolving Russian cyberespionage practices targeting cloud environmentsCyberScoop·Feb 26, 17:18 UTC · Feb 26, 2024Threat actor in the wild60
CISA, FBI, NSA reveal five enterprise bugs exploited by Russia's APT29 groupThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Threat actorCVE-2018-13379CVE-2019-9670CVE-2019-11510+2 CVEs60
Russian cyberspies targeted the Slovak government for monthsThe Record·Dec 13, 00:00 UTC · Dec 13, 2022Exploit / PoC60