HAFNIUM (Silk Typhoon) is a China-aligned cyber espionage group known for exploiting internet-facing enterprise infrastructure, including the large-scale Microsoft Exchange attacks that impacted organizations worldwide.
HAFNIUM (Silk Typhoon) is a China-aligned cyber espionage group known for exploiting internet-facing enterprise infrastructure, including the large-scale Microsoft Exchange attacks that impacted organizations worldwide.
Tick (Bronze Butler) is a long-running China-aligned APT group known for stealthy cyber espionage campaigns targeting government, defense, and technology sectors in East Asia.
MCP servers enable fast AI integrations—but they also introduce new protocol-level risks. Explore 10 attack patterns, real-world CVEs, and how to secure MCP adoption with governance and EASM visibility.
FishMonger (AQUATIC PANDA) is a China-aligned advanced persistent threat group conducting long-term cyber espionage against government, academic, and technology sectors worldwide.
Dark Caracal (G0070) is a Lebanon-linked APT conducting long-term mobile surveillance operations targeting government, military, journalists, and activists across MENA.
Liminal Panda is an emerging China-linked cyber-espionage actor targeting semiconductor, AI, and defense sectors through cloud-native intrusion and identity abuse techniques.
The newly emerged Reynolds ransomware group leverages BYOVD and NSecKrnl driver abuse to terminate security tools before encryption. Technical breakdown, IOCs and YARA rules.
Winter Vivern (TAG-70 / UAC-0114 / TA473) is a state-aligned cyber-espionage group targeting NATO and EU entities via credential harvesting, Zimbra exploitation, and persistent phishing operations.
APT-C-36, also known as Blind Eagle, is a Colombia-linked cyber-espionage group active since 2018. Primarily targeting government and financial sectors in Latin America, the actor leverages phishing, commodity RATs, and evolving post-compromise techniques to sustain regional campaigns.
Inception Framework is a long-running Russian-speaking cyberespionage group focused on government, diplomatic, and defense targets using stealthy spearphishing and cloud-based intrusion techniques.