Threats Affecting Greece
View all threats affecting or targeting Greece. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Greece
Click on any threat for detailed analysis and mitigation recommendations
Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability. Join the discussion | AlienVault OTX General | 07/03/2026, 21:26:02 UTC Added: 07/06/2026, 09:21:27 UTC |
A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications. MediumCampaign Join the discussion | AlienVault OTX General | 05/27/2026, 20:22:10 UTC Added: 05/28/2026, 15:33:32 UTC |
Two distinct phishing campaigns have been identified targeting companies in Greece, Spain, Slovenia, Bosnia and Central American countries to deliver FormBook data-stealing malware. The first campaign uses RAR attachments containing legitimate executables like Sandboxie ImBox.exe, TikTok desktop, Adobe PDF Preview Handler, and XZ Utils, exploiting DLL side-loading with malicious DLL files. The second campaign deploys heavily obfuscated JavaScript that drops encrypted PNG files, uses PowerShell with Base64 encoding, and leverages a custom .NET loader called Mandark to inject the payload into RegAsm process. Both campaigns deliver the same FormBook executable that employs advanced evasion by manually mapping ntdll.dll in memory to bypass user-mode monitoring and perform direct syscalls, enabling credential theft and data collection from browsers while avoiding detection mechanisms. Join the discussion | AlienVault OTX General | 04/22/2026, 12:43:19 UTC Added: 04/22/2026, 15:31:05 UTC |
The ShinyHunters hacker group claimed to have stolen over 350GB of information from European Commission cloud systems. The post European Commission Reports Cyber Intrusion and Data Theft appeared first on SecurityWeek . Join the discussion | SecurityWeek | 03/30/2026, 11:29:45 UTC Added: 03/30/2026, 11:38:17 UTC |
0 An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to execute arbitrary code via uploading a crafted SVG file. Join the discussion | CVE Database V5 | 03/16/2026, 00:00:00 UTC Added: 03/16/2026, 16:50:59 UTC |
The devices have been added to the NATO Information Assurance Product Catalogue (NIAPC). The post Apple iPhone and iPad Cleared for Classified NATO Use appeared first on SecurityWeek . Join the discussion | SecurityWeek | 02/26/2026, 18:04:45 UTC Added: 02/26/2026, 18:10:38 UTC |
PFCloud · Bulletproof Hosting · Datacarry Ransomware MediumMalware Join the discussion | CIRCL OSINT Feed | 02/18/2026, 00:00:00 UTC Added: 06/30/2026, 06:09:09 UTC |
0 CVE-2026-1632 is a critical vulnerability in RISS SRL's MOMA Seismic Station (version 2.4.2520 and earlier) where the web management interface lacks authentication. This allows unauthenticated attackers to access the device's configuration, extract sensitive data, or remotely reset the device. The vulnerability has a CVSS score of 9.1, indicating high severity with network attack vector, no privileges or user interaction required, and impacts confidentiality and integrity. Although no known exploits are currently reported in the wild, the exposure of critical infrastructure devices like seismic stations poses significant risks. European organizations operating these devices could face operational disruptions and data compromise. Mitigations include network segmentation, restricting access to the management interface, deploying compensating controls such as VPNs or firewalls, and monitoring for unauthorized access. Countries with active seismic monitoring infrastructure and critical geological research facilities, such as Italy, Germany, France, and Spain, are most likely to be affected. Join the discussion | CVE Database V5 | 02/03/2026, 22:59:32 UTC Added: 02/03/2026, 23:15:09 UTC |
CVE-2026-24669 is a high-severity vulnerability in the Open eClass platform versions prior to 4.2, caused by insufficient session expiration in the password reset mechanism. It allows local attackers to reuse a valid password reset token after it has already been used, enabling unauthorized password changes and potential account takeover. Exploitation requires local access and user interaction but no privileges. The vulnerability impacts confidentiality, integrity, and availability of user accounts. A patch is available in version 4.2. European organizations using Open eClass should prioritize upgrading to mitigate risks. Countries with significant academic and research institutions using Open eClass are most at risk. No known exploits are currently reported in the wild. Join the discussion | CVE Database V5 | 02/03/2026, 17:00:38 UTC Added: 02/04/2026, 08:01:28 UTC |
CVE-2026-24668 is an improper access control vulnerability in the Open eClass platform versions prior to 4.2. Authenticated students can exploit this flaw to add content to existing course units, an action normally restricted to instructors or administrators. The vulnerability does not affect confidentiality or availability but allows unauthorized modification of course content, impacting data integrity. It requires authentication but no user interaction beyond login, and can be exploited remotely over the network. The issue has been patched in version 4.2. European educational institutions using vulnerable versions are at risk of unauthorized content manipulation, which could undermine course integrity and trust. Mitigation involves upgrading to version 4.2 or later and auditing user permissions. Join the discussion | CVE Database V5 | 02/03/2026, 16:59:48 UTC Added: 02/04/2026, 08:01:28 UTC |
Showing 1 to 10 of 83 results