Threat Actors

Cybersecurity
Threat Actors Are Ramping Up Microsoft Teams Exploitation for Network Access
Cybercriminals are increasingly targeting Microsoft Teams in enterprise attacks, using the platform alongside legitimate tools to gain unauthorized ac...
Threat Actors Repurpose Tycoon 2FA Tools in New Phishing Schemes
News
Threat Actors Repurpose Tycoon 2FA Tools in New Phishing Schemes
Cybercriminals adapt Tycoon 2FA tools for phishing, revealing new security challenges.
Cyberwarfare Within the Underground - Ransomware Gangs Clash
News
Cyberwarfare Within the Underground: Ransomware Gangs Clash
Rival ransomware gangs in a conflict as 0APT warns of exposing Krybit affiliates.
APT28 Deploys PRISMEX Malware Against Ukraine and Its Allies
News
APT28 Deploys PRISMEX Malware Against Ukraine and Its Allies
Russian APT28 exploits spear-phishing in Ukraine with a novel malware, PRISMEX, harnessing advanced steganography and COM hijacking.
Chinese Threat Actors Exploit TrueConf Zero-Day to Breach Asian Governments
News
Chinese Threat Actors Exploit TrueConf Zero-Day to Breach Asian Governments
Chinese threat actors used TrueConf zero-day vulnerability to breach Asian government networks for reconnaissance and payload execution.
Cybercriminals Exploit Empty Properties for Postal Fraud
Cybersecurity
Cybercriminals Exploit Empty Properties for Postal Fraud
Threat actors use vacant homes to snatch mail and perpetrate fraud using Flare's findings.
Russian-Affiliated Attackers Deploy DarkSword Exploit Kit Targeting iOS Devices
News
Russian-Affiliated Attackers Deploy DarkSword Exploit Kit Targeting iOS Devices
Russian-based TA446 group wields DarkSword to compromise iOS devices, escalating cybersecurity threats.
Hackers Exploit a Critical Citrix Vulnerability to Steal Sensitive Data
CVE Vulnerability Alerts
Hackers Exploit a Critical Citrix Vulnerability to Steal Sensitive Data
Critical Citrix vulnerability CVE-2026-3055 is targeted by attackers to steal data.
TeamPCP Strikes Again, This Time Targeting the Python Package litellm
News
TeamPCP Strikes Again, This Time Targeting the Python Package litellm
Malicious versions of Python package litellm contain a credential harvester and persistent backdoor planted by the threat actor TeamPCP.
'PhantomRaven' Supply-Chain Campaign Floods npm Registry with Malicious Packages
Application Security
‘PhantomRaven’ Supply-Chain Campaign Floods npm Registry with Malicious Packages
'PhantomRaven' attacks are affecting JavaScript developers by targeting the npm registry with dozens of malicious packages designed to steal sensitive...