CVE-2019-19781: Citrix ADC Vulnerability
An N-day vulnerability in Citrix ADC exploited by QTFY.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
An N-day vulnerability in Citrix ADC exploited by QTFY.
An N-day vulnerability in F5 BIG-IP exploited by QTFY.
An N-day vulnerability in Kentico CMS used by QTFY.
The Log4Shell vulnerability in Apache Log4j exploited by QTFY.
An N-day vulnerability in Atlassian Confluence used by QTFY.
An N-day vulnerability in Check Point Quantum Gateway exploited by QTFY.
The U.S. Department of Justice (DoJ) announced the disruption of two hacking platforms, QScan and QTRouter, operated by the Chinese state-sponsored group…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
OpenAI has banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation. The…
Aikido Security has published research recreating an Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the…
Cybersecurity researchers have uncovered a phishing-as-a-service (PhaaS) platform called AnonyMousKIT that uses AI voice agents to trick owners of stolen Apple devices…
The U.S. Department of the Treasury has announced new sanctions targeting Iranian cyber actors as part of Operation Economic Outcast, an economic…
QTFY is a Chinese state-sponsored hacking group linked to Nanjing Xinjiuwei Network Technology Company. Active since 2018, it has targeted U.S. critical…
Cybersecurity researchers have uncovered new infrastructure and previously undocumented malware linked to Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the…
Tortoiseshell, also known as Imperial Kitten and Unyielding Wasp, is an Iranian threat actor active since at least July 2018. It targets…
Charming Kitten, also known as Eclipsed Wasp, is a cluster of Iranian cyber espionage groups. It includes subgroups like Tortoiseshell and Nimbus…
QTRouter is a network traffic obfuscation network that uses compromised IoT devices and commercial proxies to hide the origin of malicious activities.
QTBotnet is a platform used by QTFY to command and control compromised devices, capable of launching DDoS attacks and executing commands.
QScan is a tool used by QTFY to scan and automatically infect IoT devices worldwide, adding them to the QTRouter network for…
Cybersecurity researchers have disclosed a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies, which is used as a proxy to redirect Microsoft 365…
INTERPOL's Operation Jackal IV, an eight-month international law enforcement effort targeting West African organized crime groups, has resulted in the arrest of…
Operation Jackal IV was an eight-month INTERPOL-coordinated law enforcement operation from November 2025 to June 2026, involving 22 countries. It targeted West…
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
The GCIH certification demonstrates proficiency in incident handling and response, often pursued after SANS SEC504 training.
Frontier AI models, such as Anthropic's Mythos, are transforming vulnerability management by identifying zero-day flaws, chaining complex exploits, and adapting in real…
LDR516 is a SANS course taught by Kevin Garvey that covers how vulnerability programs must evolve to address the challenges posed by…
Atlassian Confluence was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Check Point Quantum Gateway was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber…
CrushFTP was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Apache Log4j was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
A Chinese company linked to QTFY, described by the FBI as an enabling company for cyber operations against U.S. critical infrastructure.
DoJ was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Sublime Security is a cybersecurity company that provides AI-powered email security solutions. Sublime observed the DOUBLOON DREDGER threat actor abusing Notion accounts…
ElevenLabs is a company that provides AI-powered text-to-speech and voice generation. The p1bot.io vishing-as-a-service platform uses ElevenLabs' text-to-speech capabilities to generate IVR…
HOSTKEY, a hosting provider, alerted a customer to excessive CPU usage on their virtual server, leading to the discovery of a cryptojacking…
Seven malicious Firefox extensions use threat actor-controlled Supabase projects to dynamically serve phishing or decoy content, abusing the platform's infrastructure.
The 37 sports-score shell extensions share a hard-coded credential for API-Sports, a legitimate sports data service, indicating coordinated infrastructure.
Fifteen malicious Firefox extensions exfiltrate wallet secrets through Cloudflare Workers, leveraging the service for data theft.