Threats Affecting Latvia
View all threats affecting or targeting Latvia. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Latvia
Click on any threat for detailed analysis and mitigation recommendations
A coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus has been exposed, originating from fraudulent SMS messages impersonating Romania's government payment portal Ghișeul.ro. Investigation revealed 1,628 malicious URLs linked by a single 128-character campaign identifier, targeting government portals, traffic police departments, postal services including DPD and SEUR, tax authorities, and telecommunications providers like T-Mobile and Vodafone. The infrastructure utilizes 32 backend IP addresses distributed across Tencent Cloud, Alibaba Cloud, Cloudflare CDN, and ALEXHOST Moldova. Threat actors employ two distinct phishing templates: a Vue.js single-page application and a Bootstrap-based clone, executing a four-stage credential harvesting process that collects complete payment card details through fabricated traffic fines, toll payments, and delivery notifications. MediumCampaign Join the discussion | AlienVault OTX General | 05/27/2026, 20:22:10 UTC Added: 05/28/2026, 15:33:32 UTC |
Investigation of DPRK-linked fake IT worker infrastructure began after cryptocurrency researcher ZachXBT identified domain luckyguys[.]site connected to illicit payments. Analysis of 30 days of network activity associated with IP 163.245.219[.]19 revealed concentrated VPN usage patterns, with Astrill VPN (37.5%), Mullvad (32.25%), and Proton VPN (6.25%) being prominent. American and Latvian residential IPs communicated with the infrastructure, showing frequent Astrill VPN usage and connectivity to Gmail, ChatGPT, and Workana freelance platform. A second IP, 216.158.225[.]144, was discovered through X509 certificate analysis. Traffic dropped sharply following public exposure, consistent with adversary behavior of abandoning attributed infrastructure. The activity suggests a distributed network of remote IT workers participating in sanctions evasion workflows, leveraging AI tools and freelance platforms to obtain employment under false identities. Join the discussion | AlienVault OTX General | 04/23/2026, 03:27:33 UTC Added: 04/23/2026, 09:06:03 UTC |
An exposed open directory revealed a comprehensive Roundcube exploitation toolkit used by APT28 to target Ukrainian government entities. The toolkit includes XSS payloads, a Flask-based C2 server, CSS injection tools, and a Go-based implant. It enables credential harvesting, persistent mail forwarding, bulk email exfiltration, address book theft, and 2FA secret extraction. The primary target was identified as mail.dmsu.gov.ua, Ukraine's State Migration Service. Technical analysis shows significant overlaps with previously documented APT28 operations, while introducing new capabilities such as CSS-based side-channel attacks and browser credential theft. The toolkit's modular approach and sophisticated evasion techniques demonstrate APT28's evolving tactics in compromising webmail platforms for long-term intelligence gathering. Join the discussion | AlienVault OTX General | 03/18/2026, 10:51:37 UTC Added: 03/18/2026, 11:12:34 UTC |
A new campaign targeting Ukrainian entities has been identified, attributed to actors linked to Russia. The campaign uses judicial and charity-themed lures to deploy a JavaScript-based backdoor called DRILLAPP, which runs through the Edge browser. This backdoor enables various actions including file manipulation, microphone access, and webcam capture. Two variants of the campaign have been observed, with the second variant introducing additional capabilities. The attackers utilize the browser's capabilities to evade detection and gain access to sensitive resources. The campaign shares tactics with a previously reported Laundry Bear operation, leading to a low-confidence attribution to this group. Join the discussion | AlienVault OTX General | 03/17/2026, 11:01:38 UTC Added: 03/17/2026, 11:27:29 UTC |
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers grant moderator privileges to users, execute scheduled tasks, move posts to trash, and accept friend requests on behalf of the user. This vulnerability is fixed in 2.18.1. Join the discussion | CVE Database V5 | 03/09/2026, 22:13:24 UTC Added: 03/09/2026, 22:34:17 UTC |
[This is a Guest Diary contributed by John Moutos]
 Join the discussion | SANS ISC Handlers Diary | 02/19/2026, 19:43:30 UTC Added: 02/19/2026, 19:46:13 UTC |
A new hacking group called Punishing Owl has emerged, targeting Russian critical infrastructure. Their first attack on December 12, 2025, compromised a Russian state security agency, leaking internal documents. The group used DNS manipulation, created fake subdomains, and sent phishing emails to the victim's partners. They employed a PowerShell stealer called ZipWhisper to exfiltrate browser data. Punishing Owl's attacks are politically motivated and focus exclusively on Russian targets, including government agencies, scientific institutions, and IT organizations. The group has established a presence on cybercriminal forums and social media, likely operating from Kazakhstan. Experts predict this group will continue to be a persistent threat in the Russian cyberspace. Join the discussion | AlienVault OTX General | 02/04/2026, 15:26:42 UTC Added: 02/04/2026, 21:00:08 UTC |
The attacks targeting Europe were analyzed by Ukraine’s CERT-UA and the cybersecurity company Zscaler. The post Russia’s APT28 Rapidly Weaponizes Newly Patched Office Vulnerability appeared first on SecurityWeek . Join the discussion | SecurityWeek | 02/03/2026, 11:22:52 UTC Added: 02/03/2026, 11:29:18 UTC |
The KMSAuto malware, linked to a Lithuanian suspect recently arrested, infected approximately 2.8 million systems globally. This malware is known for unauthorized activation of Microsoft software products, often bundled with additional malicious payloads. Although no CVSS score is available, the widespread infection and potential for system compromise indicate a medium severity threat. European organizations using unlicensed or pirated Microsoft software are particularly at risk, as KMSAuto targets such environments. The malware can lead to unauthorized access, data integrity issues, and potential lateral movement within networks. Mitigation requires organizations to enforce software licensing compliance, deploy endpoint detection tools capable of identifying KMSAuto variants, and conduct thorough network scans for infections. Countries with high Microsoft software usage and historical malware targeting, such as Germany, France, the UK, Poland, and the Baltic states, are most likely affected. The arrest may disrupt ongoing operations but does not eliminate the threat from existing infections. Defenders should prioritize detection and remediation efforts to reduce impact and prevent further spread. Join the discussion | Reddit InfoSec News | 12/30/2025, 13:28:11 UTC Added: 12/30/2025, 22:18:54 UTC |
A destructive cyberattack targeted a Danish water utility, with Denmark attributing the attack to Russian actors. The attack disrupted critical water infrastructure, raising concerns about national security and public safety. Although technical details are limited, the incident highlights the increasing use of cyber operations against critical infrastructure in Europe. No known exploits or patches have been reported yet. The attack underscores the need for enhanced cybersecurity measures in water utilities and other critical sectors. European organizations, especially those in critical infrastructure, face heightened risks from state-sponsored cyber threats. Mitigation requires tailored defenses, including network segmentation, anomaly detection, and incident response readiness. Countries with strategic water infrastructure and geopolitical tensions with Russia are most likely to be affected. The severity of this threat is assessed as high due to its potential impact on availability and public safety, ease of exploitation by a capable adversary, and the critical nature of the target. Join the discussion | Reddit InfoSec News | 12/19/2025, 18:05:08 UTC Added: 12/19/2025, 18:15:20 UTC |
Showing 1 to 10 of 50 results