Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Operation Dream Job Attacks
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched Microsoft Windows…
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched Microsoft Windows…
RelayShell is a previously undocumented PHP web shell used by Lazarus Group to compromise Roundcube webmail servers. It enables command and response…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
CVE-2024-42009 is a critical cross-site scripting (XSS) vulnerability in Roundcube webmail with a CVSS score of 9.3. Exploitation requires the victim to…
CVE-2025-49113 is a vulnerability in Roundcube webmail servers that was exploited by the Lazarus Group to install a previously undocumented PHP web…
UNK_MassTraction is a suspected China-aligned threat activity cluster first detected by Proofpoint in May 2026. It targets physics and engineering departments at…
IceCube is a JavaScript malware deployed by UNK_MassTraction after exploiting CVE-2024-42009 in Roundcube. It steals credentials, 2FA tokens, cookies, and browser information,…
SquareShell is a web shell deployed by UNK_MassTraction using a PHP gadget shell command after exploiting CVE-2025-49113 in Roundcube. It is accessible…
Roundcube was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…