Threats Tagged 't1560.001'
View all threats tagged with 't1560.001'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1560.001'
Click on any threat for detailed analysis and mitigation recommendations
For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports dating back to 2010, exposing personal and case-related information belonging to current and former participants. Japanese car-sharing service Times Car has disclosed a data breach affecting approximately 6.6 million current and former accounts. Exposed information includes personal data, while identity-verification documents, including driver’s-license images, were exposed for about 1.6 million accounts. Payment card information was not affected. South Africa’s air navigation provider has suffered a ransomware attack affecting operational technology supporting aviation weather services. Preliminary findings identified suspicious activity in weather-related environments, while separate reporting cited possible data theft. The provider has sought independent digital forensics to determine the scope of the incident. Fakturownia, a Polish online invoicing platform used by more than 600,000 businesses, has disclosed a data breach after an attacker exploited a system vulnerability. Copied information included account and company data, password hashes, bank account details, authentication tokens, contractor information, and portions of invoices stored on the platform. AI THREATS Researchers observed autonomous AI agents attempting rudimentary hacking techniques while gathering public information from US and Canadian government websites. Activity included failed SQL injection attempts against the US Department of Education and Library and Archives Canada. Officials reported no compromise, while the origin of the agents remains unconfirmed. Researchers demonstrated that malicious Custom GPTs hosted on ChatGPT were used in a ClickFix campaign to deliver remote access malware. Victims were redirected to a Google Sites page and tricked into running commands. Huntress investigated at least 40 related incidents, including two confirmed infections that began through Custom GPTs. Researchers outlined how JadePuffer, an AI-enabled threat actor tracked as Storm-3168, used compromised Azure service principals to automate cloud reconnaissance and destructive actions. The activity included deleting storage and application resources, targeting backup-related assets, and attempting to retrieve access keys, reflecting agent-driven post-compromise operations in cloud environments. VULNERABILITIES AND PATCHES Citrix has issued fixes for critical NetScaler vulnerabilities CVE-2026-88771-2, affecting NetScaler ADC and Gateway. Attackers have exploited the flaws to gain remote access, deploy web shells and tunneling malware, steal credentials, and move from exposed appliances into internal networks. Check Point IPS provides protection against these threats (Citrix NetScaler Multiple Products Buffer Overflow (CVE-2026-88772), Citrix NetScaler Multiple Products Command Injection (CVE-2026-88771)) Cisco has alerted about CVE-2026-76504, a critical (CVSS 9.8) vulnerability in Catalyst SD-WAN Manager. The flaw allows an unauthenticated remote attacker to send crafted requests and gain administrator access. Cisco reported active exploitation and stated that no fixes are available. Check Point IPS provides protection against this threat (Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)) Apple has patched CVE-2026-86950, a CoreGraphics memory corruption vulnerability affecting iPhones, iPads, and Macs. Processing a malicious image or PDF can allow arbitrary code execution. Apple reported exploitation in highly targeted attacks and addressed the flaw through improved bounds checking across affected iOS, iPadOS, and macOS releases. GitLab has released patches for CVE-2… Join the discussion | CVE Database V5 | 10/05/2026, 13:57:30 UTC Added: 09/27/2026, 16:33:34 UTC |
Microsoft Threat Intelligence identified active exploitation of CVE-2026-73570, an unauthenticated OS command injection vulnerability in Zimbra Collaboration Suite's SNMP notification path. Exploitation occurred between patch availability on July 20, 2026 and public disclosure on August 13, 2026. Attackers delivered JSP webshells and reverse shells without requiring authentication, achieving privilege escalation through PAM configuration abuse and establishing persistent access via systemd services. Post-exploitation activity included cluster-wide lateral movement using Zimbra SSH keys, collection of authentication secrets and mailbox data, and attempted exfiltration using cloud-storage tools. Multiple organizations across different regions and industries were affected through both automated payload delivery and hands-on-keyboard operations targeting internet-facing Zimbra mail servers. Join the discussion | CVE Database V5 | 10/01/2026, 12:55:57 UTC Added: 08/13/2026, 15:42:08 UTC |
In August 2026, the Pakistan-nexus threat actor APT36 launched Operation RapidRust, targeting government and defense organizations in India and Afghanistan with an updated arsenal of custom tools. The campaign introduced RUSTYSHADE, a Rust-based backdoor leveraging private GitHub repositories for command-and-control with AES-256-GCM encryption. Additional tools included RUSTYMOVE for USB-based lateral movement to air-gapped networks, PSNATCH and BASHNATCH for file exfiltration from Windows and Linux systems respectively. The attackers registered typosquatted domains impersonating Indian news outlets to stage malicious PowerShell scripts. Post-compromise activities revealed systematic network reconnaissance, credential harvesting, and lateral movement attempts, with operations conducted exclusively on weekdays between 4:00-11:00 UTC, demonstrating disciplined operational security and sustained targeting of South Asian government infrastructure. Join the discussion | AlienVault OTX General | 09/16/2026, 16:57:58 UTC Added: 09/17/2026, 10:31:45 UTC |
An intrusion was investigated that began with exploitation of CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software. The threat actor obtained unauthorized technician access and deployed two previously undocumented malware samples: TaskWeaver and Djinn Stealer. TaskWeaver is a heavily obfuscated Node.js loader that establishes encrypted communications and delivers additional payloads. Djinn Stealer targets credentials across Windows, macOS, and Linux systems, collecting authentication data for cloud platforms, source control, package registries, AI development assistants, browsers, SSH keys, and cryptocurrency wallets. The attacker leveraged legitimate RMM capabilities to transfer files and execute commands across managed systems. Stolen AI assistant tokens provided extensive access to repositories, databases, and cloud accounts. The intrusion demonstrated how a single authentication bypass in trusted management infrastructure can enable widespread credential theft and p... Join the discussion | Bleeping Computer | 09/10/2026, 12:49:58 UTC Added: 06/29/2026, 14:06:27 UTC |
Cisco Talos is tracking active exploitation of two vulnerabilities in Secure Firewall Management Center (FMC) Software. CVE-2026-20079 is a critical authentication bypass vulnerability allowing remote attackers to execute scripts and obtain root access. CVE-2026-20316 enables remote login using low-privileged accounts and can be chained with other vulnerabilities for privilege escalation. Three distinct threat actor clusters have been identified conducting post-compromise activities: UAT-12197 deployed web shells and credential theft tools; UAT-11823, overlapping with Russian APT Sandworm, deployed Cyclops Blink malware and established reverse shells; UAT-11988, a Qilin ransomware operator, conducted extensive reconnaissance, credential harvesting, and deployed ransomware after establishing persistent network access through tunneling tools. Customers are strongly advised to apply available hotfixes immediately. Join the discussion | CVE Database V5 | 09/09/2026, 20:31:35 UTC Added: 09/25/2025, 16:14:56 UTC |
MacSync Stealer is a macOS information stealer and remote-access stager delivered through ClickFix social engineering and malvertising campaigns. Operating under a malware-as-a-service model, it employs sophisticated evasion techniques including process daemonization, single-byte XOR obfuscation, and in-memory AppleScript execution to bypass Apple Gatekeeper, XProtect, and EDR solutions. The malware exfiltrates credentials, browser data, cryptocurrency wallets, and SSH keys through fault-tolerant 10MB chunked uploads to command-and-control infrastructure. MacSync targets professionals in software engineering, cryptocurrency, fintech, and corporate environments across North America, Europe, and Asia-Pacific regions, with campaigns impersonating legitimate services like Google Meet, Claude AI, Docker, and TradingView to trick victims into executing malicious Terminal commands. MediumMalware Join the discussion | AlienVault OTX General | 09/08/2026, 12:29:01 UTC Added: 09/09/2026, 09:22:16 UTC |
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique. Join the discussion | AlienVault OTX General | 08/12/2026, 16:42:10 UTC Added: 08/13/2026, 10:11:14 UTC |
Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor. Join the discussion | AlienVault OTX General | 07/16/2026, 16:15:00 UTC Added: 07/17/2026, 00:32:32 UTC |
ModHeader, a popular Chrome developer extension with over 800,000 users, was flagged and removed by Google for containing hidden spyware. Version 7.0.18 included a covert SDK disguised as a date library (dayjs) that harvested visited domain names, encrypted them using AES-GCM, and was configured to upload the data daily to api.stanfordstudies.com. Although the collection remained dormant due to an empty allowlist, the complete exfiltration infrastructure was present and operational. Additionally, the extension displayed active adware behavior, opening affiliate tabs on every update including on enterprise-managed machines. The malicious code shipped with official Chrome Web Store signatures, affecting both Chrome and Edge users. Forensic analysis revealed the extension locally stored 178MB of sensitive HTTP headers from all browsing activity, though no data was successfully exfiltrated from analyzed systems. Join the discussion | AlienVault OTX General | 07/14/2026, 08:04:43 UTC Added: 07/14/2026, 10:02:33 UTC |
Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor deploys a modular C2 framework built on .NET but compiled into different formats including Mixed-Mode C++/CLI and Native AOT, creating significant anti-analysis challenges. The framework consists of core agents and specialized post-exploitation modules providing capabilities for file system operations, database browsing, LDAP querying, network reconnaissance, and tunneling. Initial access is achieved through abuse of Remote Monitoring and Management software like SysAid. The actor demonstrates supply-chain compromise tactics, using IT providers as stepping stones to reach higher-value targets. Technical overlaps link Cavern Manticore to Iranian MOIS-aligned groups including MuddyWater and Lyceum subgroup of OilRig. Join the discussion | AlienVault OTX General | 07/06/2026, 14:02:13 UTC Added: 07/07/2026, 14:14:38 UTC |
Showing 1 to 10 of 30 results