Threat Actors
65 entries
-
Request, Aggregate, Bypass: How Attackers Can Evade LLM Safety Classifiers
Tue, 06 Oct 2026 01:00 · Blog
-
5th October – Threat Intelligence Report
Mon, 05 Oct 2026 09:57 · Check Point Research
-
Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365
Mon, 05 Oct 2026 01:00 · Blog
-
New in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced Remediation
Mon, 05 Oct 2026 01:00 · Blog
-
Give yourself room to be human
Thu, 01 Oct 2026 14:00 · Cisco Talos Blog
-
The Fine Art of Frustrating the Adversary
Thu, 01 Oct 2026 06:00 · Cisco Talos Blog
-
CrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaS
Thu, 01 Oct 2026 01:00 · Blog
-
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Wed, 30 Sep 2026 06:00 · Cisco Talos Blog
-
Securing the keys to the kingdom: Announcing Executive Threat Detection
Tue, 29 Sep 2026 06:00 · Cisco Talos Blog
-
Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them
Tue, 29 Sep 2026 01:00 · Blog
-
28th September – Threat Intelligence Report
Mon, 28 Sep 2026 09:55 · Check Point Research
-
A Win for Defenders: CrowdStrike and NVIDIA Extend Security Across the AI Stack
Mon, 28 Sep 2026 00:00 · Blog
-
Trust and the enticing consultancy offer
Thu, 24 Sep 2026 14:00 · Cisco Talos Blog
-
CrowdStrike Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
Thu, 24 Sep 2026 01:00 · Blog
-
The Closed Quorum: Inside the first reported autonomous AI C2 implant
Tue, 22 Sep 2026 06:00 · Cisco Talos Blog
-
Introducing CAIRN: Frontier tracking for AI-integrated malware
Tue, 22 Sep 2026 06:00 · Cisco Talos Blog
-
21st September – Threat Intelligence Report
Mon, 21 Sep 2026 19:13 · Check Point Research
-
Should you care about an “AI slowdown?”
Thu, 17 Sep 2026 14:00 · Cisco Talos Blog
-
AI Threat Landscape Digest: July–August 2026
Thu, 17 Sep 2026 10:41 · Check Point Research
-
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Thu, 17 Sep 2026 06:00 · Cisco Talos Blog
-
CrowdStrike Named a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026
Thu, 17 Sep 2026 01:00 · Blog
-
CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
Thu, 17 Sep 2026 01:00 · Blog
-
Securing the unpatchable in an age of AI-driven vulnerabilities
Wed, 16 Sep 2026 06:00 · Cisco Talos Blog
-
CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
Wed, 16 Sep 2026 01:00 · Blog
-
14th September – Threat Intelligence Report
Mon, 14 Sep 2026 08:22 · Check Point Research
-
We've got one word for it, and it's usually the wrong one
Thu, 10 Sep 2026 14:00 · Cisco Talos Blog
-
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
Thu, 10 Sep 2026 10:32 · Check Point Research
-
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Wed, 09 Sep 2026 12:08 · Cisco Talos Blog
-
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Tue, 08 Sep 2026 18:16 · Cisco Talos Blog
-
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Tue, 08 Sep 2026 09:00 · Check Point Research
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
Tue, 08 Sep 2026 06:01 · Cisco Talos Blog
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Tue, 08 Sep 2026 06:00 · Cisco Talos Blog
-
7th September – Threat Intelligence Report
Mon, 07 Sep 2026 10:54 · Check Point Research
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Wed, 02 Sep 2026 06:16 · Check Point Research
-
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Tue, 01 Sep 2026 03:00 · APT reports – Securelist
-
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
Mon, 31 Aug 2026 09:38 · Check Point Research
-
31st August – Threat Intelligence Report
Mon, 31 Aug 2026 08:58 · Check Point Research
-
24th August – Threat Intelligence Report
Mon, 24 Aug 2026 10:07 · Check Point Research
-
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Thu, 20 Aug 2026 09:07 · Check Point Research
-
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Tue, 18 Aug 2026 09:05 · Check Point Research
-
17th August – Threat Intelligence Report
Mon, 17 Aug 2026 09:37 · Check Point Research
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Fri, 14 Aug 2026 05:00 · APT reports – Securelist
-
Armored Likho expands its cyber-espionage toolkit
Thu, 13 Aug 2026 04:00 · APT reports – Securelist
-
Mirage Kitten targets Middle East and Africa region with new malware
Tue, 28 Jul 2026 04:00 · APT reports – Securelist
-
ToddyCat: your hidden email assistant. Part 2
Tue, 30 Jun 2026 06:00 · APT reports – Securelist
-
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
Fri, 22 May 2026 09:00 · Threat Actor Groups Archives - Unit 42
-
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
Fri, 22 May 2026 05:12 · APT reports – Securelist
-
Kimsuky targets organizations with PebbleDash-based tools
Thu, 14 May 2026 07:00 · APT reports – Securelist
-
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
Wed, 06 May 2026 09:00 · APT reports – Securelist
-
Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government
Thu, 26 Mar 2026 18:00 · Threat Actor Groups Archives - Unit 42
-
Boggy Serpens Threat Assessment
Mon, 16 Mar 2026 18:00 · Threat Actor Groups Archives - Unit 42
-
A Peek Into Muddled Libra’s Operational Playbook
Tue, 10 Feb 2026 18:00 · Threat Actor Groups Archives - Unit 42
-
The Shadow Campaigns: Uncovering Global Espionage
Thu, 05 Feb 2026 06:00 · Threat Actor Groups Archives - Unit 42
-
HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns
Tue, 27 Jan 2026 03:00 · APT reports – Securelist
-
The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor
Mon, 29 Dec 2025 05:00 · APT reports – Securelist
-
From Linear to Complex: An Upgrade in RansomHouse Encryption
Wed, 17 Dec 2025 06:00 · Threat Actor Groups Archives - Unit 42
-
Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite
Thu, 11 Dec 2025 06:00 · Threat Actor Groups Archives - Unit 42
-
The Golden Scale: Bling Libra and the Evolving Extortion Economy
Fri, 10 Oct 2025 17:00 · Threat Actor Groups Archives - Unit 42
-
Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite
Tue, 30 Sep 2025 06:00 · Threat Actor Groups Archives - Unit 42
-
Bookworm to Stately Taurus Using the Unit 42 Attribution Framework
Wed, 24 Sep 2025 17:00 · Threat Actor Groups Archives - Unit 42
-
Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)
Fri, 01 Aug 2025 09:00 · Threat Actor Groups Archives - Unit 42
-
Introducing Unit 42’s Attribution Framework
Thu, 31 Jul 2025 06:00 · Threat Actor Groups Archives - Unit 42
-
2025 Unit 42 Global Incident Response Report: Social Engineering Edition
Wed, 30 Jul 2025 06:00 · Threat Actor Groups Archives - Unit 42
-
The Covert Operator's Playbook: Infiltration of Global Telecom Networks
Tue, 29 Jul 2025 17:00 · Threat Actor Groups Archives - Unit 42
-
Muddled Libra Threat Assessment: Further-Reaching, Faster, More Impactful
Fri, 25 Jul 2025 06:00 · Threat Actor Groups Archives - Unit 42
← Back to home