Skip to main content

Threat Intelligence

Threat actor activity and indicators

Ominous shadow of a hand reaches for glowing server cables amidst scattered broken screens.

Iranian Campaign Targets 3,900 Devices in US Infrastructure

A recent Iranian cyber campaign has set its sights on a staggering 3,900 exposed devices in US infrastructure, putting energy, water, and government services at risk. This large-scale threat is a clear warning sign that these critical systems may be vulnerable to attack.

Analyst 207
Dismantled router with exposed internal components sits on worn table amidst tangled cables and wires in dimly lit room.

FBI Disrupts APT28's Router-Based Espionage Operations

The FBI recently disrupted a sneaky espionage operation run by APT28, a Russian GRU-linked group notorious for its broad reach, by cutting off their access to a network of routers they used as a launching pad for further attacks. This bold move effectively severed the group's tremendous access, putting a stop to their clever tactics.

Analyst 207
Person in hoodie surrounded by screens displaying code and surveillance footage in dimly lit room with worn world map in…

India-Tied Hack-for-Hire Group Targets MENA Journalists

Meet the shadowy hack-for-hire group with ties to India that's targeting journalists and activists in the Middle East and North Africa, silencing voices and stifling free speech. Their sinister operations have been uncovered by security researchers, revealing a chilling espionage trade where reporters, officials, and dissenting voices are prime targets.

Analyst 207
Desert landscape at dusk with a broken smartphone and scattered papers in the foreground, a lone figure silhouetted in the…

Bitter APT Group Exploits Middle East Spear-Phishing Campaign

The Bitter APT Group has been linked to a sophisticated year-long spear-phishing campaign that targeted the Middle East, using deceptive emails to spread its reach. This hack-for-hire effort, attributed to a South Asian connection, signals a sustained threat to the region's security.

Analyst 207
Dimly lit call center with scattered desks and eerie glowing screens, a single broken ticket in the center.

UNC6783 Hackers Infiltrate BPOs to Steal Corporate Support Tickets

Hackers known as UNC6783 are exploiting business process outsourcing providers to gain access to sensitive corporate support tickets on platforms like Zendesk, putting high-value companies across multiple sectors at risk. This sneaky tactic opens the door for cybercriminals to infiltrate and wreak havoc on unsuspecting organizations.

Analyst 207
Dimly lit control room with computer screens displaying critical infrastructure data and a cityscape at dusk outside.

CISA Warns of Iranian Cyber Actors Targeting US Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm: Iranian-linked cyber actors are targeting US critical infrastructure, posing a threat to public safety, services, and commerce. American organizations must take immediate action to assess their risk and bolster defenses.

Analyst 207
Globe centered on Russia with shattered network, silhouettes of law enforcement disrupting tangled web.

FBI Disrupts Russian Hacker Network with DNS Hijacking Takedown

In a major cyber takedown, the FBI has successfully disrupted a Russian hacker network by pulling the plug on compromised US-based routers, effectively cutting off the threat actor's malicious infrastructure. This bold move allowed authorities to neutralize the threat without relying on individual device owners to take action.

Analyst 207
Dimly lit industrial control room with analog panels and code on screens, with a ghostly US map projection.

Iranian Hackers Infiltrate US Critical Infrastructure via OT Weaknesses

US critical infrastructure providers are reeling from a wake-up call after Iranian-backed hackers exploited weaknesses in internet-exposed operational technology assets, causing disruption and financial loss. The alarming breach, revealed by the Cybersecurity and Infrastructure Security Agency, highlights the high stakes of vulnerable systems.

Analyst 207
Person in a hoodie with obscured face sits in front of laptop displaying cityscape, surrounded by network-like lines and…

Mandiant Report Reveals Evolving Cyber Threat Tactics

Discover the alarming evolution of cyber threats in Mandiant's M-Trends 2026 report, which reveals a stark reality: attackers are now operating under two distinct playbooks, drastically changing the detection, response, and risk landscape. The report uncovers a significant increase in global median dwell time to 14 days, with some attacks lingering for as long as 122 days.

Analyst 207
Cityscape at dusk with cracked glass window reflecting distorted computer screens and code, symbolizing cyber threats.

Kaspersky Report Exposes Shifting Cyberattack Landscape

Get ready to face the future of cyber threats! The Kaspersky Security Services report delivers eye-opening insights into the evolving cyberattack landscape, combining real-world incident response findings with hard data from its Managed Detection and Response service.

Analyst 207
Censys Bolsters AI-Driven Threat Intel with $70M Funding

Censys Bolsters AI-Driven Threat Intel with $70M Funding

Censys just secured $70 million in funding to supercharge its AI-driven threat intelligence platform, giving defenders real-time visibility into the global network's underlying infrastructure. This game-changing tech helps defenders stay one step ahead of attackers by mapping and monitoring the internet's technical surface.

Analyst 207
Microsoft Grapples with Weeks-Long Exchange Online Mailbox Access Disruptions

Microsoft Grapples with Weeks-Long Exchange Online Mailbox Access Disruptions

Weeks of frustrating disruptions have left Outlook mobile and macOS users struggling to access their Exchange Online mailboxes, sparking a flurry of questions about reliability and resolution. Microsoft is actively investigating the issue, but for affected users, the wait for a fix continues.

Analyst 207
US Charges Filed in High-Profile Crypto Hacks and Fentanyl Cases

US Charges Filed in High-Profile Crypto Hacks and Fentanyl Cases

This week's string of high-profile crypto hacks, indictments, and regulatory moves exposes a growing dilemma: as decentralized finance and crypto markets expand, the lines between crime, commerce, and policy are becoming increasingly blurred. From charged crypto hacks to fentanyl cases, the seams where these worlds meet are fraying in plain sight.

Analyst 207
Microsoft Probes Outlook Disruption Tied to Email Delivery Issues

Microsoft Probes Outlook Disruption Tied to Email Delivery Issues

Microsoft is investigating a frustrating issue affecting Classic Outlook users, preventing them from sending emails via Outlook.com due to a bug linked to broader email delivery problems. The disruption is causing inconvenience for users relying on seamless communication.

Analyst 207
Critical Maritime Threat: Alarming Rise in Underwater Attack Drones Spurs Urgent Tech Hunt

Critical Maritime Threat: Alarming Rise in Underwater Attack Drones Spurs Urgent Tech Hunt

The US and UK are racing against time to outsmart a growing maritime threat: underwater attack drones that can devastate ships, harbors, and critical infrastructure. With a joint call for tech tenders and a tight deadline of April 3, they're on a mission to find cutting-edge solutions before it's too late.

Analyst 207
North Korea’s APT37 Exclusive: Dangerous Tool Hits Air-Gap

North Korea’s APT37 Exclusive: Dangerous Tool Hits Air-Gap

Think the most isolated machines are untouchable? North Korea’s APT37 has broadened its toolkit — combining believable lures with new utilities that can defeat air‑gap protections and put highly sensitive systems at fresh risk.

Analyst 207
I Am in the Epstein Files Exclusive: Disturbing Revelations

I Am in the Epstein Files Exclusive: Disturbing Revelations

A throwaway 2016 email from Vincenzo lozzo casually dismissing Bruce Schneier cracks open the Epstein files; what looks like a ledger of crimes is also a map of how the wealthy and tech‑savvy shaped conversations about privacy, security and reputation.

Analyst 207
ThreatsDay Bulletin Exclusive: Essential Cyber Threats

ThreatsDay Bulletin Exclusive: Essential Cyber Threats

Ever wondered what happens when trusted doors are left unlocked? This ThreatsDay Bulletin shows how trusted attack chains—everyday files, SMS, cloud APIs and smart contracts—are being repurposed into stealthy, high‑leverage strikes and what you can do to shut them down.

Analyst 207
AI Exclusive: Corporate Capture Threatens Knowledge

AI Exclusive: Corporate Capture Threatens Knowledge

A decade after Aaron Swartz, AI’s hunger for research risks putting a few corporations in charge of access to knowledge — deciding what we can learn, who benefits, and which ideas get heard.

Analyst 207
KrebsOnSecurity.com: Exclusive Look at 16 Stunning Years

KrebsOnSecurity.com: Exclusive Look at 16 Stunning Years

For 16 years KrebsOnSecurity has pulled back the curtain on the criminal plumbing—bulletproof hosts, access brokers and resilient intermediaries—showing why targeting those enablers, not just the flashy attacks, is the real path to stopping cybercrime.

Analyst 207
Drones to Diplomas: Exclusive Damning Link to Essay Mill

Drones to Diplomas: Exclusive Damning Link to Essay Mill

Think essay mills are just a campus nuisance? A new investigation reveals a $25M ad‑driven cheating network that used Google search ads to funnel students to essay services — and whose money trail ties to a Kremlin‑connected oligarch and a Russian university involved in attack drone development, turning academic dishonesty into a national security worry.

Analyst 207
Drones to Diplomas: Exclusive Damning $25M Essay Mill Link

Drones to Diplomas: Exclusive Damning $25M Essay Mill Link

Get the inside scoop on a $25M essay mill tying drones to diplomas—our exclusive exposé reveals how the scheme works and why it matters for students and educators alike.

Analyst 207
Meet Rey: Exclusive Profile of Controversial Admin

Meet Rey: Exclusive Profile of Controversial Admin

Meet Rey—the pseudonymous face of Scattered LAPSUS$ Hunters—who unexpectedly lifted his veil after KrebsOnSecurity traced him to his father and secured an interview. That admission could shatter the groups anonymity and change the game for investigators, rivals and recruits.

Analyst 207
Cybersecurity Predictions 2026 Exclusive: Worst Risks Ahead

Cybersecurity Predictions 2026 Exclusive: Worst Risks Ahead

AI-enabled threats are already reshaping the attack landscape—making reconnaissance, social engineering and vulnerability hunting faster and cheaper. Bitdefender’s data-driven webinar cuts through the headlines to show boards and C‑suites which risks merit action and which are just noise.

Analyst 207