Threats Tagged 't1133'
View all threats tagged with 't1133'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1133'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-18577: CWE-288 Authentication bypass using an alternate path or channel in N-able N-centralCVE-2026-18577 0 An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 Join the discussion | CVE Database V5 | 08/02/2026, 22:06:18 UTC Added: 08/02/2026, 22:33:37 UTC |
Toy Ghouls’ new toy: the GenieLocker ransomware 0 GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec. Join the discussion | AlienVault OTX General | 07/30/2026, 09:41:18 UTC Added: 07/31/2026, 06:22:12 UTC |
Ongoing PLC Exploitation Against Critical U.S. Infrastructure 0 Multiple federal agencies have updated a joint advisory warning of active exploitation targeting programmable logic controllers (PLCs) in U.S. critical infrastructure. Attackers scan for internet-exposed industrial control systems and connect using legitimate engineering software with valid credentials, appearing as authorized technicians. Once inside, they alter controller logic and manipulate operator displays to hide anomalies. The campaign has expanded beyond Rockwell Automation to include Schneider Electric and Siemens equipment. Unlike a similar 2023 campaign that caused minimal disruption, this ongoing activity has resulted in confirmed operational disruption and financial losses. Targeted sectors include government facilities, water systems, and energy infrastructure. The exploitation leverages architectural weaknesses rather than software vulnerabilities, with attackers accessing systems through ports 22, 102, 502, 2222, and 44818. Join the discussion | AlienVault OTX General | 07/24/2026, 12:34:37 UTC Added: 07/24/2026, 14:52:06 UTC |
CVE-2026-16232: CWE-287: Improper Authentication. in checkpoint Quantum Security ManagementCVE-2026-16232 0 CVE-2026-16232 is a critical authentication bypass vulnerability in Check Point Quantum Security Management's SmartConsole login process. An unauthenticated remote attacker can obtain a login token and gain full administrative privileges, allowing modification of security policies and configurations. Exploitation requires network access to the Management Server IP and permissive Trusted Client settings. Check Point has acknowledged active exploitation affecting a small number of customers. No official patch or remediation guidance has been confirmed yet. Join the discussion | CVE Database V5 | 07/22/2026, 13:53:09 UTC Added: 07/22/2026, 14:08:07 UTC |
Suspected Chinese Operators Use Claude Code and DeepSeek to Breach Government Systems Across Four Countries 0 In June 2026, infrastructure pivoting from TencShell C2 nodes revealed an active intrusion campaign utilizing AI language models for attack automation. Thirteen Hong Kong-based servers across four ASNs exposed an open directory containing victim source code, custom exploits, operational logs, and cloned login pages with notes in Simplified Chinese. The operation employed Claude Code for execution and DeepSeek-v4-pro for attack logic, targeting government systems in Afghanistan, Thailand, and Taiwan, along with reconnaissance against U.S. government portals. The campaign also pursued financial services firms across Europe, Australia, and Asia. Attackers deployed TencShell implants, webshells, and custom exploits including SQL injection and Laravel deserialization attacks, successfully compromising administrative systems and exfiltrating sensitive data including citizen complaints and government employee information. Join the discussion | AlienVault OTX General | 07/14/2026, 21:17:46 UTC Added: 07/15/2026, 14:19:07 UTC |
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement 0 Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an... Join the discussion | AlienVault OTX General | 07/09/2026, 22:16:04 UTC Added: 07/10/2026, 07:47:32 UTC |
Showing 1 to 6 of 6 results