Tag

#APT / Nation-State

22 published stories tagged with APT / Nation-State.

highAPT / Nation-StateJul 29, 20264 min read

Laundry Bear exploits Exchange OWA zero-day to deploy persistent OWAReaper backdoor via email

The Russian state-sponsored group Laundry Bear (TA488) is using a "half-click" exploit against Microsoft Exchange Outlook Web Access (OWA) to deploy the OWAReaper backdoor.

highAPT / Nation-StateJul 29, 20262 min read

Russian Hackers Maintain Mailbox Access After Credential Rotation via Microsoft OWA Flaw

馃毃 Russian-linked actors are targeting Microsoft Exchange Online environments through vulnerabilities in Outlook Web Access (OWA).

mediumAPT / Nation-StateJul 29, 20263 min read

Unauthenticated attackers exploit hard-coded credentials in Cisco Secure Firewall Management Center

Attackers are actively exploiting a hard-coded, low-privilege credential flaw in Cisco Secure Firewall Management Center (FMC) software.

highAPT / Nation-StateJul 23, 20262 min read

Russian state-sponsored actors target Zimbra Collaboration Suite users through phishing campaigns

New intelligence indicates that Iranian-affiliated cyber actors have been targeting Programmable Logic Controllers (PLCs) used throughout US critical infrastructure.

highAPT / Nation-StateJul 20, 20263 min read

Zero-day vulnerability chain enables root access and malware deployment on SonicWall SMA1000 appliances

Threat actors have been exploiting a chain of two zero-day vulnerabilities in SonicWall SMA1000 appliances for weeks.

highAPT / Nation-StateJul 19, 20262 min read

Attackers exploit SonicWall SMA zero-day vulnerabilities to gain unauthorized root access

馃毃 Attackers are actively exploiting zero-day vulnerabilities within SonicWall Secure Mobile Access (SMA) appliances.

highAPT / Nation-StateJul 17, 20263 min read

Zero-day vulnerability chain enables root access and persistence on Siemens ROX II switches

A chain of three zero-day vulnerabilities in Siemens ROX II industrial switches allows attackers to escalate privileges and gain persistent root access.

highAPT / Nation-StateJul 16, 20262 min read

Crafted CIP packets trigger denial-of-service and halt industrial I/O on Rockwell Flex 5000 adapters

Sending crafted CIP packets to a FLEX 5000 EtherNet/IP adapter can trigger a denial-of-service state that halts industrial I/O. Recovery requires a physical power cycle of the module.

criticalAPT / Nation-StateJul 14, 20262 min read

Unauthenticated attackers exploit zero-day vulnerabilities in SonicWall SMA1000 appliances for code execution

Threat actors are actively exploiting two zero-day vulnerabilities in SonicWall SMA1000 appliances to perform server-side request forgery and arbitrary code execution.

mediumAPT / Nation-StateJul 13, 20262 min read

Attackers can execute remote commands on Cisco 871 routers via CSRF flaw

Cisco has a critical cross-site request forgery (CSRF) flaw in the HTTP Administration component of its IOS software.

highAPT / Nation-StateJul 7, 20262 min read

Unauthenticated attackers can execute remote code via NGINX rewrite module vulnerabilities

A critical flaw in the `ngx_http_rewrite_module` can lead to worker process restarts or remote code execution.

highAPT / Nation-StateJul 6, 20262 min read

Japanese teenager detained following disruptive cyberattack on anime streaming platform

Tokyo police have arrested a high school student suspected of disrupting the Bandad Channel anime streaming service through large-scale unauthorized cancellations.

highAPT / Nation-StateJul 1, 20262 min read

Remote Code Execution Vulnerability in Microsoft SharePoint Under Active Exploitation by Attackers

Attackers are actively exploiting a high-severity deserialization vulnerability in Microsoft SharePoint.

criticalAPT / Nation-StateJun 30, 20263 min read

Critical RCE Flaw in Langflow AI Enables Full Server Compromise and Data Theft

Langflow AI's tool for building AI-powered agents has been exploited for unauthenticated remote code execution (RCE) due to a critical vulnerability in versions prior to 1.9.0.

criticalAPT / Nation-StateJun 29, 20263 min read

Critical Authentication Bypass in SimpleHelp Enables Malware Deployment: Immediate Patch Urged

A critical authentication bypass vulnerability in SimpleHelp (CVE-2026-48558) has been actively exploited by threat actors to deploy new malware.

highAPT / Nation-StateJun 19, 20263 min read

Over 100,000 WordPress Sites at Risk from Unauthenticated Info Disclosure in Gravity SMTP Plugin

Hackers are actively exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, affecting over 100,000 sites.

criticalAPT / Nation-StateJun 16, 20264 min read

Critical Joomla Content Editor Flaw Actively Exploited: Immediate Patch Urged by CISA

A critical vulnerability in the Joomla Content Editor (JCE) extension has been actively exploited, allowing attackers to upload and execute PHP code.

highAPT / Nation-StateJun 15, 20264 min read

CISA Catalogs Two Actively Exploited Vulnerabilities: Critical Patches Urged

Two critical vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog: Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and LiteSpeed cPanel Plugin (CVE-2026-54420).

highAPT / Nation-StateJun 10, 20263 min read

Microsoft Fixes Critical XSS Flaw in Exchange Server Actively Exploited by Threat Actors

Microsoft has patched an actively exploited vulnerability in Exchange Server that allows threat actors to execute arbitrary JavaScript code via cross-site scripting (XSS) attacks.

highAPT / Nation-StateJun 10, 20263 min read

Microsoft's June Patch Tuesday Unveils 206 Fixes: Urgent Patch Needed for Self-Spreading Vulnerability

Microsoft's June Patch Tuesday delivered an unprecedented 206 security fixes, with AI playing a significant role in vulnerability discovery.

highAPT / Nation-StateJun 9, 20262 min read

Unauthorized Access via ServiceNow Vulnerability Highlights Need for AI-Driven Security Measures

A newly identified vulnerability in ServiceNow has been exploited by attackers to gain unauthorized access.

highAPT / Nation-StateJun 2, 20263 min read

Gamaredon Exploits WinRAR Zero-Day: Urgent Patch Needed for Windows Users

The WinRAR vulnerability (CVE-2025-8088) has been actively exploited by Gamaredon to execute arbitrary code through malicious archive files, posing a significant threat to systems using the Windows ve