Threat Actors

Cybersecurity
Operation HookedWing: 4-Year Campaign Compromises 500 Orgs
SOCRadar uncovered Operation HookedWing, a 4-year credential-harvesting campaign that compromised 2,000+ accounts across 500+ organizations in aviation, energy, government, and critical infrastructure using GitHub-hosted phishing ...
Application Security
Checkmarx Jenkins Plugin Backdoored in TeamPCP Supply Chain
TeamPCP backdoored the Checkmarx Jenkins AST scanner plugin in a third supply chain wave, following March Trivy and April KICS attacks. Version 2026.5.09 was compromised; ...
Cybersecurity
ShinyHunters Leaks 50GB After Vishing Breach at Cushman & Wakefield
Cushman & Wakefield confirmed a vishing-enabled breach after ShinyHunters and Qilin ransomware listed the firm separately. ShinyHunters published a 50GB Salesforce dataset after the May ...
Cybersecurity
TrickMo Android Banker Routes C2 Traffic Through TON Blockchain
ThreatFabric identified Trickmo.C, a TrickMo Android banking trojan routing C2 through TON blockchain with SSH tunneling, SOCKS5, and NFC capabilities targeting European banking users.
Cybersecurity
RansomHouse Breaches Trellix; Source Code Repositories Accessed
Trellix confirmed unauthorized access to its source code repositories after RansomHouse posted photographic evidence of the breach. Law enforcement has been notified.
Cybersecurity
Germany, Spain Dismantle Rebooted Crimenetwork, Arrest Operator
German and Spanish authorities shut down the relaunched Crimenetwork dark web marketplace and arrested its 35-year-old German operator in Mallorca under a European arrest warrant.
Nation-State Actors Exploited PAN-OS CVE-2026-0300 for Nearly a Month
CVE Vulnerability Alerts
Nation-State Actors Exploited PAN-OS CVE-2026-0300 for Nearly a Month
State-sponsored actors exploited CVE-2026-0300, a critical CVSS 9.3 RCE flaw in PAN-OS, for roughly one month before disclosure. CISA deadline is May 9.
PCPJack Malware Exploits Five CVEs to Worm Across Cloud Environments
Cybersecurity
PCPJack Malware Exploits Five CVEs to Worm Across Cloud Environments
Nation-state-linked PCPJack malware framework worms across cloud environments via five CVEs, using parquet file evasion to harvest credentials from cloud and financial systems.
Two Americans Jailed for Running North Korean IT Worker Laptop Farms
Cybersecurity
Two Americans Jailed for Running North Korean IT Worker Laptop Farms
Matthew Knoot and Erick Prince received 18-month federal sentences for laptop farm operations that placed North Korean IT workers inside U.S. companies under stolen American ...
GothFerrari Gets 6.5 Years for $250M Crypto Home-Invasion Theft Ring
Cybersecurity
GothFerrari Gets 6.5 Years for $250M Crypto Home-Invasion Theft Ring
California man Marlon Ferro, alias GothFerrari, received a 78-month federal sentence for home invasions, iCloud surveillance of victims, and money laundering in a ring that ...