Home Updates Threat Intel APT Encyclopedia Blog
Threat Intelligence

Threat Intelligence

Latest APT activity, actively exploited CVEs, and curated threat intelligence sources.

Hand-curated · Last updated

Latest APT Activity

Kernel Zero-Day Aug 11, 2026 Lazarus Cyllex analysis

Lazarus Burned a Windows Kernel 0-Day on a Fake Job Offer

Operation Dream Job came back carrying CVE-2026-68820, a use-after-free race in afd.sys exploited in the wild for five weeks before the August Patch Tuesday fix. Chain: SEO-poisoned fake vendor sites → trojanized MuPDF viewer → MISTPEN downloader riding the Microsoft Graph API → SYSTEM → FudModule 3.1, which blinds 94 ETW providers and resets Smart App Control's policy state. Defence and aerospace targets in France, Germany, India and Brazil. Full technical breakdown on the blog.

North Korea CVE-2026-68820 FudModule 3.1 T1068 · T1562.001
Actively Exploited Sep 1, 2026 JFrog Artifactory

Artifactory Auth Bypass (CVSS 9.8) Exploited Days After Disclosure

JFrog patched CVE-2026-82329 on Aug 28; by Sep 1 watchTowr was observing attackers minting administrator tokens on default-configuration self-hosted instances, then enumerating users, groups, credentials and federated access to decide whether the environment was worth going deeper into. SaaS is unaffected. An artifact repository is a build-pipeline root of trust, so admin there is downstream code execution everywhere.

CI/CD Supply Chain CVE-2026-82329 7.161.20
Mass Exploitation Aug 2026 Cl0p / Hazy Scorpius

Cl0p Names 43 Victims in the PTC Windchill Campaign

Same playbook as MOVEit and Cleo, new target: CVE-2026-12569 in PTC Windchill and FlexPLM, exploited as a zero-day from early June. The chain pairs a pre-auth information disclosure in the FlexPLM WSDL endpoint with a flaw in the Windchill login servlet for unauthenticated RCE, then drops hex-named JSP webshells under /Windchill/login/. Shell, Philips, Fiserv, Zebra and Largan Precision are among those named on the leak site. PLM systems hold product designs, so the exfil target is engineering IP, not customer records.

Extortion CVE-2026-12569 T1505.003
Espionage Aug 4, 2026 Twill Typhoon

Mustang Panda's FDMTP Backdoor Returns as a Modular .NET Plugin Framework

Darktrace tracked a China-nexus campaign across APJ finance and sports targets using DLL sideloading against legitimate binaries (biz_render.exe, dfsvc.exe) to load a .NET RAT speaking a custom DMTP protocol. Persistence via registry plugin storage plus COM object registration; the framework self-updates every five minutes from icloud-cdn[.]net, AES-decrypting a payload straight into Assembly.Load(). C2 domains impersonate CDNs. A near-complete emulation target: ~12 mapped techniques, no exploit required.

China T1574.001 T1546.015 T1620
Taxonomy Jul 24, 2026 Google GTIG

Google Retires APT Numbering for Two-Word Cryptonyms

Mandiant's APTnn/FINnn numbering and TAG's separate identifiers merge into one scheme: a memorable first word plus a category word: CASTLE (China), RELIC (Russia), NEPTUNE (North Korea), ION (Iran), COMET (cybercrime). APT44 → SANDWORM RELIC, APT41 → SPIRE CASTLE, FIN7 → WILD COMET. Old names stay searchable and UNC survives for unattributed clusters. Practical impact: actor names are aliases, technique IDs are the stable key.

Attribution Naming MITRE mapping

CISA KEV - Latest Additions

CVE-2026-81578 Added Aug 31
PaperCut NG/MF - missing auth on critical function
CVE-2026-82078 Added Aug 31
PaperCut NG/MF - unsafe reflection
CVE-2026-68820 Added Aug 11
Windows afd.sys use-after-free → SYSTEM. Lazarus 0-day
CVE-2026-55040 Added Aug 18
Microsoft SharePoint - weak authentication
CVE-2026-59310 Added Aug 18
VMware vCenter - path traversal
CVE-2026-33824 Added Aug 18
Microsoft IKE - double free
CVE-2026-65400 Added Aug 18
Apple macOS - improper authentication
View Full KEV Catalog

Exploited · Patch Now

Confirmed in-the-wild activity

CVE-2026-82329 CVSS 9.8
JFrog Artifactory auth bypass → admin tokens. Fixed in 7.161.20
CVE-2026-12569 Cl0p
PTC Windchill / FlexPLM unauth RCE → JSP webshell

Most Active Groups

Q3 2026

Cl0p 43 named Extortion
The Gentlemen 300 Ransomware
Qilin / Agenda 289 Ransomware
Lazarus Dream Job North Korea
Twill Typhoon China
knaithe / KnYuan China

146 ransomware brands were active as of June 2026, 61 of them new in the preceding year, so the long tail is now most of the problem. Emulate the shared playbook, not the brand.