Unknown cyber spies breached over 70 govt and critical infrastructure orgs
TGR-STA-1030 relies on an extensive toolkit of frameworks, web shells, tunneling utilities to maintain long-term access.
TGR-STA-1030 relies on an extensive toolkit of frameworks, web shells, tunneling utilities to maintain long-term access.
DKnife is a post-compromise framework designed for traffic monitoring and adversary-in-the-middle (AitM) attacks.
The campaign, tracked by US and allied authorities, has previously targeted telecommunications providers and other critical infrastructure abroad.
In brief: Russian hackers exploit a Microsoft Office flaw, Citrix NetScaler infrastructure targeted in a coordinated campaign, and more.
Amaranth Dragon began exploiting CVE-2025-8088 on August 18, 2025, just days after a working exploit became public.
Attackers modify legitimate NGINX configuration files by injecting malicious “location” blocks.
A contractor improperly accessed customer information affecting approximately 30 users.
The activity, tracked between January 28 and February 2, indicates deliberate infrastructure mapping rather than opportunistic crawling.
With valid login details, threat actors can take over accounts, gain internal access or use the data for additional follow-on fraud.
Researchers estimate that approximately 3,500 exposed React Native Metro servers are currently accessible online.
Showing elements 341 - 350