Threat Actor Campaigns & Exploitation
Articles on threat actor campaigns, vulnerability exploitation techniques, and attack chains targeting critical infrastructure, government, and military organizations.
The 24-Hour Pivot: How Ivanti's Sentry Appliances Became an Immediate Target
A critical Ivanti Sentry vulnerability, CVE-2026-10520, was exploited by threat actors within 24 hours of disclosure, demonstrating the extreme speed and risk of modern edge-infrastructure cyberattacks.
Federal Agencies Must Patch Check Point VPN Flaw Linked to Active Ransomware Campaign
CISA has issued an emergency directive requiring U.S. federal agencies to patch a critical vulnerability in Check Point Remote Access VPN and Mobile Access systems within three days. The flaw, tracked as CVE-2026-50751, allows unauthenticated attackers to bypass authentication and establish remote access connections. The vulnerability has been actively exploited in zero-day attacks since May 7, with at least one incident linked to the Qilin ransomware operation. Only systems using the deprecated IKEv1 key exchange protocol without machine certificate requirements are affected.
WinRAR’s Forgotten Door: How Russian Actors Turned a Year-Old Patch Into a Backdoor
Shadow-Earth-066 and Earth Dahu exploit CVE-2025-8088 in Ukraine—and beyond—because organizations still haven’t found WinRAR on their networks. It’s not the flaw that’s dangerous; it’s the silence.