Skip to main content

Threats Affecting Israel

View all threats affecting or targeting Israel. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Country:IsraelIsrael

Threats Affecting Israel

Click on any threat for detailed analysis and mitigation recommendations

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]

Join the discussion

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

Join the discussion
0

Three implants named SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS have been found embedded in ZBT router firmware distributed globally, including in the US, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor on port 9992 providing root shell access with trivial MAC address bypass. SPEAKINGSTONE is a phone-home implant capable of DNS hijacking, ISP credential theft, and remote command execution. These implants use plaintext protocols without authentication, making them vulnerable to hijacking by network adversaries. The compromised hardware is found in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commercial devices. A sinkholed backup domain revealed 392 devices, mostly in China, and internet scans found 203 DARKLANTERN instances in 22 countries.

Join the discussion

This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303.

Join the discussion

A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.

Join the discussion

This report highlights a cyber espionage campaign attributed to the Iranian APT group Charming Kitten, targeting eight countries and eight critical sectors simultaneously. The campaign, dubbed Operation Olalampo, affects Egypt, Saudi Arabia, UAE, Turkey, Hungary, Turkmenistan, Israel, and South America, focusing on government, healthcare, financial services, energy, education, telecommunications, defense, and industrial sectors. The information is sourced from a Reddit post linking to a GitHub repository simulating adversary tactics. No specific vulnerabilities or exploits are detailed, and no affected software versions are identified.

Join the discussion

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek .

Join the discussion

A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]

Join the discussion

Kaspersky identified a new .NET Native AOT communication module for Project CAV3RN, a sophisticated cyberespionage framework targeting Israel. This module replaces the previous HTTP/WebSocket component by exchanging commands through Outlook calendar events accessed via Microsoft Graph API. Commands and results are stored in a fixed time window (2050-05-13 22:00-23:00 UTC) using specific subject patterns to identify heartbeats, commands, and outputs. The module implements RSA and AES-GCM encryption for secure communications. If Microsoft Graph authentication fails, it retrieves replacement configuration settings through DNS AAAA record responses from actor-controlled nameservers. The infrastructure analysis and behavioral patterns suggest low-confidence attribution to OilRig (APT34), based on the use of Microsoft-hosted services for command and control and compromised regional infrastructure.

Join the discussion

A sophisticated espionage campaign has been identified leveraging malware that exploits Microsoft Graph API to transform compromised Microsoft 365 calendars into covert command-and-control infrastructure. The malware creates calendar events dated to 2050 with encrypted attachments to exfiltrate files and receive instructions. A secondary DNS tunneling channel using IPv6 AAAA records refreshes Microsoft Entra ID credentials for authentication. Communications are secured using hybrid RSA and AES-256-GCM encryption with separate key pairs for inbound and outbound channels. Twelve infected systems have been identified, primarily targeting Israeli entities, with only three actively communicating with attackers. The operation demonstrates high technical sophistication and disciplined targeting, suggesting a well-resourced adversary conducting focused espionage operations since at least June 2026.

Join the discussion

Showing 1 to 10 of 333 results

Filters:Country: Israel
Page 1 of 34
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses