UAT-8616: Advanced Persistent Threat Actor Targeting Cisco SD-WAN
An advanced persistent threat (APT) actor attributed to the exploitation of multiple Cisco SD-WAN vulnerabilities in 2026, including CVE-2026-20262.
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
An advanced persistent threat (APT) actor attributed to the exploitation of multiple Cisco SD-WAN vulnerabilities in 2026, including CVE-2026-20262.
ScarCruft, also known as APT37, is a North Korean state-sponsored hacking group known for spear-phishing campaigns and deploying malware like RokRAT and…
APT37, also known as ScarCruft, is a North Korean cyber espionage group that has been active since at least 2012. They are…
Vanilla Tempest, also known as Rapid Brigantine, Vice Society, and Vice Spider, is a financially motivated threat actor known for deploying ransomware…
Fox Tempest, also known as Forging Marauder, is a threat actor that advertised a malware-signing-as-a-service (MSaaS) operation. Microsoft's disruption of this service…
Rapid Brigantine was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Vice Society was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Forging Marauder was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
A Turkish-speaking threat actor is operating a campaign that compromises WordPress sites to inject hidden backlinks for a Private Blog Network (PBN),…
Microsoft assesses with high confidence that the Mastra npm compromise is attributable to Sapphire Sleet, a North Korean threat actor known for…