Cyber Threat Intelligence
Articles about cyber threat intelligence, APT groups, and nation-state malware campaigns
Progress Software Is Emailing ShareFile Customers to Shut Down Storage Zone Controllers — Here's What We Know
Progress Software has confirmed that a high-severity zero-day path traversal vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers, and has released security updates (versions 5.12.5 and 6.0.2) to patch the flaw affecting all 5.x and 6.x versions.
Threat Actors Weaponized CVE-2026-10520 Within 24 Hours of Ivanti Sentry Disclosure
Threat actors exploited a maximum-severity OS command injection flaw (CVE-2026-10520) in Ivanti Sentry within 24 hours of disclosure, using a public proof-of-concept to achieve root-level RCE. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a three-day patch deadline.
macOS ClickFix Attack Silently Mounts DMGs to Deploy AMOS Infostealer
Following the disruption of malicious code-signing provider Fox Tempest, the operators of the Lorem Ipsum malware pivoted from signed installers to compromised WordPress sites executing ClickFix browser lures, with analysts linking the activity to the Vice Society ransomware syndicate. Optimized for SEO and discoverability.
Threat Actors Weaponize Ivanti Sentry Zero-Day in Rapid Coordinated Campaign
Within 24 hours of public disclosure, threat actors began exploiting CVE-2026-10520, a CVSS 10.0 OS command injection vulnerability in Ivanti Sentry mobile gateway appliances, using a public proof-of-concept exploit to backdoor vulnerable instances and gain root-level access.
Twenty-Four Hours to Pwn: How a Single Endpoint Destroyed Ivanti Sentry's Trust
Threat actors weaponized CVE-2026-10520 within hours of disclosure — here’s how the exploit works, why it’s so dangerous, and what you must do now.
Federal Agencies Must Patch Check Point VPN Flaw Used in Ransomware Attacks Within Three Days
CISA mandates urgent remediation of CVE-2026-50751, a zero-day vulnerability in Check Point Remote Access VPN and Mobile Access deployments exploited by Qilin ransomware affiliates, with federal agencies given until June 11 to apply patches or implement mitigations.
RoguePlanet Zero-Day: Microsoft Defender Race Condition Grants SYSTEM Access
Nightmare Eclipse's RoguePlanet PoC weaponizes Microsoft Defender for SYSTEM-level privilege escalation on fully patched Windows 10 and 11.
The Mistic Backdoor: How KongTuke’s Stealthy Memory-Only Tool Powers Ransomware Intrusions
Mistic is a stealthy, fileless backdoor developed by initial access broker KongTuke to enable long-term persistence for ransomware operators like Qilin and Black Basta. Here’s how it avoids detection, exploits legitimate tools, and why behavioral analysis is essential to stop it.
AI-Triggered Credential Theft: The Microsoft Supply Chain Breach in Focus
An analysis of the recent Miasma supply chain worm that compromised 73 Microsoft-signed open-source packages, targeting developer AI coding assistants.
AryStinger Botnet Hijacks 4,000+ Routers as Malicious Proxy Network
Previously undocumented malware botnet AryStinger has compromised thousands of outdated D-Link routers worldwide, converting them into remotely controlled 'executors' for scanning, proxying, and command execution activities.
Weaponized Urgency: The Critical Lessons Behind the Ivanti Sentry Breach
CVE-2026-10520 analysis, Ivanti Sentry vulnerability, root-level remote code execution (RCE) implications, and defense-in-depth strategies.
ClickFix Malware Campaign: New Analysis Reveals Lorem Ipsum Delivery Technique Linked to Vice Society Ransomware Group
New security research uncovers a sophisticated malware delivery campaign using Lorem Ipsum placeholders as the initial infection vector, with strong indicators linking the operation to the Vice Society ransomware and extortion group.