← All Intelligence

APT Threat Intelligence

24 briefings0 vulnerability reports

Advanced Persistent Threats are state-sponsored or state-affiliated hacking groups that conduct long-term espionage and sabotage operations against government, defense, and critical infrastructure targets. defend.network monitors APT activity reported by threat intelligence vendors, government advisories, and incident response disclosures, tracking which groups are active and which sectors they target.

24
briefings
3
critical
8
high
26%
of all briefings

Threat Briefings

2026-06-16

China espionage dwell 1 year, Microsoft 200 patches, Cisco SD-WAN actively exploited

China-linked UNC6508 maintained undetected access to North American medical, military, and academic research networks for over a year via compromised REDCap servers. Microsoft issued record 200 patches with evidence of active exploitation. Cisco SD-WAN vManage CVE-2026-20262 exploited in the wild.

2026-06-14

Splunk RCE, Arch Linux supply-chain hijack, Velvet Ant decade-long backdoor

Splunk Enterprise CVE-2026-20253 (CVSS 9.8) enables unauthenticated RCE; 400+ Arch Linux AUR packages hijacked with infostealer/rootkit; China-linked Velvet Ant maintained decade-long PAM/OpenSSH backdoor.

2026-06-11

Langflow RCE exploited, JDY botnet expands U.S. military targeting, npm security hardened

CVE-2026-5027 in Langflow actively exploited for unauthenticated RCE; JDY botnet expands to 1,500 devices targeting U.S. military networks. CISA mandates 3-day patching for critical flaws.

2026-06-01

PAN-OS GlobalProtect actively exploited; Russian infrastructure dismantled; Linux kernel flaw

Palo Alto PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) actively exploited; Dutch authorities arrest two hosting operators supporting Russian cyberattacks; Linux kernel CIFSwitch flaw allows privilege escalation.

2026-05-21

GitHub breach, SonicWall VPN MFA bypass, Drupal critical flaw demand patching

GitHub suffered breach of 3,800+ internal repos via TeamPCP. Microsoft disrupted malware-signing operation. SonicWall VPN and Drupal require urgent patching.

2026-04-27

FIRESTARTER federal Cisco persistence; Chinese APT GopherWhisper

Critical threats include FIRESTARTER backdoor persistence on federal Cisco devices, Russian military token theft via router exploitation, Chinese APT GopherWhisper attacks, and four actively exploited CISA KEV vulnerabilities with May 2026 federal patching deadline.

2026-04-26

FIRESTARTER on federal Cisco gear; 4 critical CVEs added to CISA KEV

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches; Russian state actors harvesting Office tokens via router exploits; four critical CVEs added to CISA KEV with May 2026 deadline; APT campaigns targeting U.S. defense sector; AI-powered phishing escalates to personalized 1-to-1 attacks.

2026-04-25

FIRESTARTER persists on federal Cisco; APT spear-phishes NASA

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches. Russian military intelligence harvesting Office tokens via router exploits. Chinese APT targeting NASA and defense sector with spear-phishing. AI-powered phishing and FakeWallet credential theft escalating.

2026-04-22

Russian APT token theft; Gentlemen ransomware claims 1,570 victims

Russian state-backed APT harvesting Microsoft tokens, 1,570+ Gentlemen ransomware victims, critical SD-WAN and RMM exploits, Windows Defender flaws—urgent patching required across infrastructure.

2026-04-14

Adobe zero-day exploited; APT37 attacks; AI-powered exploitation

Critical Adobe zero-day under active exploitation, Russian state-sponsored token harvesting, and APT37 social engineering campaigns compound with AI-powered vulnerability discovery threats.

2026-04-12

Iran PLC attacks; Marimo RCE exploited in 10h; GlassWorm IDE infection

Critical threats span Iranian PLC targeting, Russian token harvesting, Marimo RCE exploitation within 10 hours, and GlassWorm IDE infections. Immediate patching and detection deployment required.

2026-04-10

Adobe Reader zero-day exploited; APT28 router credential theft

Critical zero-day in Adobe Reader, state-sponsored credential theft via routers, and major supply-chain compromises demand immediate action across all organizations.

2026-04-09

APT28 PRISMEX on NATO; ActiveMQ 13-yr RCE; Russian router token theft

APT28 deploys PRISMEX malware targeting NATO allies; 13-year-old ActiveMQ RCE and Russian router-based token theft critical; new botnets and healthcare ransomware disruptions.

2026-04-08

APT28 DNS hijack via routers; Iran hits PLCs; Docker RCE

Russian APT28 conducting large-scale DNS hijacking via compromised routers for token theft; Iranian hackers targeting U.S. critical infrastructure PLCs; critical Docker and Flowise vulnerabilities under active exploitation.

2026-04-07

Iran & DPRK target Microsoft 365; GitHub C2 supply-chain attacks

State-sponsored APT campaigns targeting Microsoft 365 and supply chains escalate with GitHub C2 usage and zero-day exploits deployed within 24 hours of breach.

2026-04-06

FortiClient RCE exploited; DPRK & Chinese APTs hit EU institutions

State-sponsored DPRK and China-linked APT campaigns, critical FortiClient RCE exploit, and cascading supply chain attacks affecting European institutions and npm ecosystem.

2026-04-05

TA416 PlugX on EU govts; UNC1069 Axios npm; device code phishing 37x

Nation-state campaigns targeting European governments and supply chain infrastructure. TA416 resumes targeting with PlugX. North Korean UNC1069 compromises Axios npm. Device code phishing surges 37x.

2026-04-04

TrueConf zero-day; TA416 hits EU govts; UNC1069 npm compromise

Critical zero-day in TrueConf, resurgent Chinese APT targeting European governments, North Korean npm supply chain compromise, and third-party vendor breaches require immediate response

2026-04-01

TrueConf zero-day exploited; North Korea Axios npm compromise

Critical zero-day exploits in TrueConf and North Korean Axios compromise, plus wiper attacks and AI platform over-privilege vulnerabilities demand immediate response across cloud, government, and healthcare sectors.

2026-03-30

FBI Director email breached; Citrix & F5 zero-days exploited

FBI Director's email breached by Iran-linked hackers; critical Citrix and F5 vulnerabilities under active exploitation; wiper attacks target Stryker; nation-state exploit kits leaked publicly.

2026-03-29

Iran breaches FBI Director email; Citrix & F5 zero-days unpatched

Iran-linked actors breached FBI Director Kash Patel's email and launched wiper attacks on Stryker. Critical Citrix and F5 vulnerabilities under active exploitation with no patches available.

2026-03-27

Chinese APT in telecom backbone; Langflow zero-day exploited

State-sponsored Chinese APT embedded in telecom backbone, critical Langflow AI vulnerability actively exploited, wiper malware targeting Iran systems, and zero-click AI assistant vulnerabilities require immediate response.

2026-03-26

AI autonomous espionage; device code phishing at 340+ orgs

AI-powered autonomous cyber espionage, device code phishing at 340+ organizations, and critical infrastructure vulnerabilities require immediate defensive action across all sectors.

2026-03-23

Russian phishing on Signal/WhatsApp; Oracle RCE exploited

Russian intelligence conducting mass Signal/WhatsApp phishing; critical Oracle RCE vulnerability; Trivy supply-chain attack spreads CanisterWorm across 47+ npm packages; VoidStealer bypasses Chrome encryption; Iran-backed wiper attacks on medical technology.

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.