CL-STA-1114 — Attack group profile
CL-STA-1114 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
CL-STA-1114 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
A Russian threat actor also known as CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard, responsible for exploiting vulnerabilities in Zimbra and Microsoft OWA…
Void Blizzard was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
TA488 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Group-IB has uncovered a China-nexus cyber operation tracked as JadeProx, which has been targeting government, healthcare, and education organizations across Asia and…
JadeProx is a China-nexus cyber operation tracked by Group-IB, targeting government, healthcare, and education organizations across Asia and Latin America. It uses…
Water Curse is a threat cluster tracked by Trend Micro that operates a GitHub-based ghost network to redirect users to malware-laced payloads.…
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability, CVE-2026-0257 (CVSS score: 7.8), as an entry point…
Qilin ransomware, also known as Agenda, is a ransomware-as-a-service (RaaS) operation. In June 2026, affiliates exploited CVE-2026-0257 in PAN-OS for initial access.…