Latest APT activity, actively exploited CVEs, and curated threat intelligence sources.
Check Point Research linked active exploitation of an IKEv1 authentication-bypass zero-day in Check Point Remote Access VPN to a Qilin RaaS affiliate. Exploitation began May 7 and hit ~24 organizations globally, with confirmed post-compromise Qilin activity in at least one case.
An unauthenticated RCE zero-day in Palo Alto Networks firewalls (User-ID authentication portal) was exploited by suspected Chinese state cluster CL-STA-1132, which deployed open-source tooling (Earthworm, ReverseSocks5) and performed Active Directory enumeration.
China's Salt Typhoon has compromised 200+ organizations worldwide — including AT&T, Verizon, Lumen and T-Mobile — to steal call records and communications of senior officials. The FBI stated in Feb 2026 the campaign is "still very, very much ongoing."
TRM Labs attributes ~$577M in 2026 crypto theft (through April) to North Korea — 76% of all crypto-hack value this year — driven by two operations: Drift Protocol (~$285M) and KelpDAO via a LayerZero bridge flaw (~$292M).
ESET's Q4 2025–Q1 2026 report details China-aligned groups (FamousSparrow, UNC5221 and others) spying on maritime, energy and political targets across the Gulf amid post-strike instability, while Iran-aligned APT activity declined and Russia's Sandworm stayed active.