Threats Affecting Serbia
View all threats affecting or targeting Serbia. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Serbia
Click on any threat for detailed analysis and mitigation recommendations
Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability. Join the discussion | AlienVault OTX General | 07/03/2026, 21:26:02 UTC Added: 07/06/2026, 09:21:27 UTC |
An active SMS phishing campaign targets Serbian road users by impersonating Putevi Srbije, Serbia's state road authority. Victims receive text messages claiming they have unpaid traffic fines with urgent payment demands. The fraudulent links lead to cloned government websites designed to steal payment card details. The infrastructure employs JavaScript-based obfuscation techniques to evade automated security scanners and uses disposable domains with uncommon TLDs. Technical analysis reveals connections to both Darcula and Phoenix Phishing-as-a-Service platforms, indicating fraudsters are combining tools from multiple PhaaS vendors. The operation demonstrates coordinated roles including infrastructure setup, SMS distribution, and data harvesting. Similar campaigns have targeted victims globally across government bodies, postal services, and financial institutions. Join the discussion | AlienVault OTX General | 07/01/2026, 16:52:35 UTC Added: 07/06/2026, 10:06:26 UTC |
NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through unsanitized input to potentially disclose sensitive information from the mobile banking application. Join the discussion | CVE Database V5 | 12/30/2025, 22:41:43 UTC Added: 12/30/2025, 22:58:54 UTC |
A ransomware attack targeted the Romanian Water Authority, causing approximately 1000 systems to be taken offline. This incident disrupted critical water management infrastructure, highlighting the vulnerability of essential public services to cyber extortion. The attack was reported recently and has medium severity based on initial assessments. No specific ransomware variant or exploit details have been disclosed, and there is no evidence of known exploits in the wild related to this incident. The disruption of water services can impact public health and safety, making timely mitigation crucial. European organizations managing critical infrastructure should be vigilant against similar ransomware threats. Romania is directly affected, with potential spillover risks to neighboring countries with interconnected infrastructure. Mitigation should focus on robust backup strategies, network segmentation, and incident response readiness. The threat severity is assessed as high due to the critical nature of the affected systems and the scale of disruption despite limited technical details. Defenders must prioritize protecting operational technology environments and ensure rapid recovery capabilities. Join the discussion | Reddit InfoSec News | 12/23/2025, 13:47:41 UTC Added: 12/23/2025, 13:51:01 UTC |
For the latest discoveries in cyber research for the week of 3rd November, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Everest ransomware group has claimed responsibility for a series of attacks impacting AT&T, Dublin Airport, and Air Arabia. The ransomware gang exfiltrated sensitive data including 576,000 AT&T applicant records, 1.5 million […] The post 3rd November – Threat Intelligence Report appeared first on Check Point Research . Join the discussion | Check Point Research | 11/03/2025, 09:53:13 UTC Added: 11/03/2025, 09:58:16 UTC |
0 A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes Source: https://interseclab.org/wp-content/uploads/2025/09/The-Internet-Coup_September2025.pdf Join the discussion | Reddit NetSec | 09/09/2025, 19:40:28 UTC Added: 09/09/2025, 19:40:56 UTC |
Showing 1 to 6 of 6 results