ProBackend
Cyber Threat Intelligence

Cyber Threat Intelligence

Articles about cyber threat intelligence, APT groups, and nation-state malware campaigns

cyber threat intelligenceJul 13, 20265 min

Progress Software Is Emailing ShareFile Customers to Shut Down Storage Zone Controllers — Here's What We Know

Progress Software has confirmed that a high-severity zero-day path traversal vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers, and has released security updates (versions 5.12.5 and 6.0.2) to patch the flaw affecting all 5.x and 6.x versions.

cyber threat intelligenceJul 13, 20266 min

Threat Actors Weaponized CVE-2026-10520 Within 24 Hours of Ivanti Sentry Disclosure

Threat actors exploited a maximum-severity OS command injection flaw (CVE-2026-10520) in Ivanti Sentry within 24 hours of disclosure, using a public proof-of-concept to achieve root-level RCE. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a three-day patch deadline.

cyber threat intelligenceJun 30, 20265 min

macOS ClickFix Attack Silently Mounts DMGs to Deploy AMOS Infostealer

Following the disruption of malicious code-signing provider Fox Tempest, the operators of the Lorem Ipsum malware pivoted from signed installers to compromised WordPress sites executing ClickFix browser lures, with analysts linking the activity to the Vice Society ransomware syndicate. Optimized for SEO and discoverability.

cyber threat intelligenceJun 30, 20264 min

Threat Actors Weaponize Ivanti Sentry Zero-Day in Rapid Coordinated Campaign

Within 24 hours of public disclosure, threat actors began exploiting CVE-2026-10520, a CVSS 10.0 OS command injection vulnerability in Ivanti Sentry mobile gateway appliances, using a public proof-of-concept exploit to backdoor vulnerable instances and gain root-level access.

cyber threat intelligenceJun 29, 20263 min

Twenty-Four Hours to Pwn: How a Single Endpoint Destroyed Ivanti Sentry's Trust

Threat actors weaponized CVE-2026-10520 within hours of disclosure — here’s how the exploit works, why it’s so dangerous, and what you must do now.

cyber threat intelligenceJun 29, 20264 min

Federal Agencies Must Patch Check Point VPN Flaw Used in Ransomware Attacks Within Three Days

CISA mandates urgent remediation of CVE-2026-50751, a zero-day vulnerability in Check Point Remote Access VPN and Mobile Access deployments exploited by Qilin ransomware affiliates, with federal agencies given until June 11 to apply patches or implement mitigations.

cyber threat intelligenceJun 29, 20263 min

RoguePlanet Zero-Day: Microsoft Defender Race Condition Grants SYSTEM Access

Nightmare Eclipse's RoguePlanet PoC weaponizes Microsoft Defender for SYSTEM-level privilege escalation on fully patched Windows 10 and 11.

cyber threat intelligenceJun 25, 20265 min

The Mistic Backdoor: How KongTuke’s Stealthy Memory-Only Tool Powers Ransomware Intrusions

Mistic is a stealthy, fileless backdoor developed by initial access broker KongTuke to enable long-term persistence for ransomware operators like Qilin and Black Basta. Here’s how it avoids detection, exploits legitimate tools, and why behavioral analysis is essential to stop it.

cyber threat intelligenceJun 23, 20263 min

AI-Triggered Credential Theft: The Microsoft Supply Chain Breach in Focus

An analysis of the recent Miasma supply chain worm that compromised 73 Microsoft-signed open-source packages, targeting developer AI coding assistants.

cyber threat intelligenceJun 22, 20263 min

AryStinger Botnet Hijacks 4,000+ Routers as Malicious Proxy Network

Previously undocumented malware botnet AryStinger has compromised thousands of outdated D-Link routers worldwide, converting them into remotely controlled 'executors' for scanning, proxying, and command execution activities.

cyber threat intelligenceJun 22, 20265 min

Weaponized Urgency: The Critical Lessons Behind the Ivanti Sentry Breach

CVE-2026-10520 analysis, Ivanti Sentry vulnerability, root-level remote code execution (RCE) implications, and defense-in-depth strategies.

cyber threat intelligenceJun 19, 20264 min

ClickFix Malware Campaign: New Analysis Reveals Lorem Ipsum Delivery Technique Linked to Vice Society Ransomware Group

New security research uncovers a sophisticated malware delivery campaign using Lorem Ipsum placeholders as the initial infection vector, with strong indicators linking the operation to the Vice Society ransomware and extortion group.