Threat Advisories
Detailed information and guidance on threats and vulnerabilities, focusing on its characteristics, impact, and remediation steps, released daily and weekly to provide actionable intelligence and aid in rapid response and mitigation efforts.
Strengthen Your Defenses With the Latest Intelligence
Threat Level – Amber | Vulnerability Report
Iranian threat actor targets the Albanian government using ROADSWEEP ransomware
A cyberattack that took place in mid-July momentarily disrupted various Albanian government August 9, 2022 Threat Level – Amber | Vulnerability Report
Woody RAT leverages Follina to target Russia
The unknown threat actor employs the Woody RAT to spear-phish Russian organizations. August 5, 2022 Threat Level – Amber | Vulnerability Report
Manjusaka – Cybercriminal’s new attack framework weapon
Manjusaka is a new attack framework that mimics Cobalt Strike and Sliver. August 5, 2022 Threat Level – Amber | Vulnerability Report
VMware products impacted by an authentication bypass vulnerability and other flaws
VMware has addressed multiple vulnerabilities, including an authentication bypass (CVE-2022-31656), remote code August 4, 2022 Threat Level – Red | Vulnerability Report
LockBit 3.0 makes a comeback by exploiting Log4j
LockBit 3.0 (LockBit Black), a new variant of LockBit Ransomware, is deploying August 4, 2022 Threat Level – Red | Vulnerability Report
KNOTWEED exploits zero-days to target US and Europe
KNOTWEED, an Austria-based private-sector offensive actor (PSOA), are exploiting 0-day vulnerabilities of August 1, 2022 Threat Level – Red | Vulnerability Report
APT37 employs Konni malware to target high-level organizations
The Konni remote access trojan, which is widely used malware by the July 29, 2022 Threat Level – Red | Vulnerability Report
Evilnum strikes commodities and cryptocurrency Forum
In recent campaigns, the Evilnum actor group has targeted the Decentralized Finance July 29, 2022