Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

8 / 38 results
Active filter:tag: #apt✕ clear
Kimsuky Targets South Korean Military and Corporate Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Kimsuky Targets South Korean Military and Corporate Sectors

Kimsuky (also tracked as Velvet Chollima, Black Banshee, Emerald Sleet, and THALLIUM) is a North Korean state-sponsored advanced persistent threat group.

The Hacker News03:57 UTC
MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loadinghighperson_alertThreat Actor
person_alertThreat Actor

MuddyWater Q1 2026 espionage campaign hits nine countries via DLL side-loading

MuddyWater (also tracked as Earth Vetala, MERCURY, Static Kitten, and Seedworm) is an Iranian state-sponsored APT group attributed to Iran's Ministry of Intelligence and Security (MOIS).

The Hacker News13:48 UTC
Lazarus Group deploys RemotePE cross-platform RAT against finance sectorhighperson_alertThreat Actor
person_alertThreat Actor

Lazarus Group deploys RemotePE cross-platform RAT against finance sector

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to the Reconnaissance General Bureau (RGB). The group is financially motivated, conducting operations to generate revenue for the DPRK regime through th…

The Hacker News07:32 UTC
Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malwarehighperson_alertThreat Actor
person_alertThreat Actor

Screening Serpens: Iranian APT Targets Tech and Defense with RAT Malware

Screening Serpens is an Iranian APT group attributed by Unit 42, conducting cyber espionage operations. The group is motivated by intelligence collection targeting technology and defense sectors, consistent with Iranian state interests in acquiring s…

Unit 42 (Palo Alto)11:00 UTC
ROADtools Framework Misused in Nation-State Cloud Intrusionshighperson_alertThreat Actor
person_alertThreat Actor

ROADtools Framework Misused in Nation-State Cloud Intrusions

Multiple threat actors, including nation-state groups, are misusing the open-source ROADtools framework for cloud intrusions. ROADtools is a legitimate Azure AD reconnaissance toolkit designed for security assessments, but has been co-opted by advers…

Unit 42 (Palo Alto)08:00 UTC
Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph APIhighperson_alertThreat Actor
person_alertThreat Actor

Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API

Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.

Microsoft10:51 UTC
NCSC UK Issues Guidance on China-Nexus Covert Device Networkshighperson_alertThreat Actor
person_alertThreat Actor

NCSC UK Issues Guidance on China-Nexus Covert Device Networks

China-nexus threat actors are state-sponsored groups linked to the People's Republic of China. These actors are motivated by strategic intelligence collection, espionage, and maintaining persistent access to foreign networks.

NCSC UK10:00 UTC
NCSC UK Issues Advisory on China-Linked Covert Network Tacticshighperson_alertThreat Actor
person_alertThreat Actor

NCSC UK Issues Advisory on China-Linked Covert Network Tactics

China-linked threat actors employing covert network tactics to conceal malicious cyber activity. These actors are characterized by their use of sophisticated techniques to maintain persistent, stealthy access to compromised networks.

NCSC UK10:00 UTC