APTBlueMoon Exploit Kit Gives Four Espionage Groups a Shared Chrome-to-Windows Attack Chain
Four espionage groups use BlueMoon exploit kit chaining Chrome V8 flaws and Windows ALPC bug to escape sandbox and deploy payloads.
APTFour espionage groups use BlueMoon exploit kit chaining Chrome V8 flaws and Windows ALPC bug to escape sandbox and deploy payloads.
APTRapid7 found trojanized HAProxy 2.8.12 in South Korea deploying the ted backdoor to hijack traffic, hide C2, execute commands and steal credentials.
APTOver 2,000 leaked Bauman University files expose Department No. 4 training GRU cyber operators linked to APT28 and Sandworm operations.
APTIran's Nimbus Manticore lures developers with fake LinkedIn coding tests to deploy NodeRabbit and PollCat RATs for cross-platform espionage.
APTSygnia uncovers Fire Ant's cyber-espionage expanding to Cisco IOS XR routers, TACACS servers, and Linux hosts using invisible tunnels and credential theft.
APTOn 13 August 2026, Hunt.io researchers identified an unprotected server in Amsterdam 31.58.209 . 241 exposing a Python SimpleHTTP directory on port 8000.
APTBetween late September 2025 and early April 2026, government and diplomatic organizations in Romania, Spain, and Turkey were targeted by a cyber espionage
APTOn August 27, 2026, CISA added three new vulnerabilities to the Known Exploited Vulnerabilities KEV catalog. The most severe is CVE-2023-49105, an
APTGoCaracal malware by Dark Caracal discovered, with dual variants and Ethereum-based C2 backup for advanced espionage operations.