Home Updates Threat Intel APT Encyclopedia Blog
Threat Intelligence

Threat Intelligence

Latest APT activity, actively exploited CVEs, and curated threat intelligence sources.

Latest APT Activity

Ransomware Zero-Day Jun 8, 2026 Qilin

Check Point VPN Zero-Day (CVE-2026-50751) Tied to Qilin Ransomware Affiliate

Check Point Research linked active exploitation of an IKEv1 authentication-bypass zero-day in Check Point Remote Access VPN to a Qilin RaaS affiliate. Exploitation began May 7 and hit ~24 organizations globally, with confirmed post-compromise Qilin activity in at least one case.

Ransomware CVE-2026-50751
Zero-Day Active May 7, 2026 CL-STA-1132

Suspected Chinese State Group Exploits Palo Alto Firewall Zero-Day (CVE-2026-0300)

An unauthenticated RCE zero-day in Palo Alto Networks firewalls (User-ID authentication portal) was exploited by suspected Chinese state cluster CL-STA-1132, which deployed open-source tooling (Earthworm, ReverseSocks5) and performed Active Directory enumeration.

China CVE-2026-0300
State Espionage Ongoing · 2026 Salt Typhoon

Salt Typhoon Telecom Espionage Spans 80+ Countries — FBI Says Still Ongoing

China's Salt Typhoon has compromised 200+ organizations worldwide — including AT&T, Verizon, Lumen and T-Mobile — to steal call records and communications of senior officials. The FBI stated in Feb 2026 the campaign is "still very, very much ongoing."

China Telecom
Crypto Heist Apr 30, 2026 Lazarus

North Korea's Lazarus Group Stole 76% of All 2026 Crypto-Hack Value

TRM Labs attributes ~$577M in 2026 crypto theft (through April) to North Korea — 76% of all crypto-hack value this year — driven by two operations: Drift Protocol (~$285M) and KelpDAO via a LayerZero bridge flaw (~$292M).

North Korea ~$577M
Threat Report May 28, 2026 ESET

ESET APT Report: China-Aligned Groups Exploit Iran-War Instability

ESET's Q4 2025–Q1 2026 report details China-aligned groups (FamousSparrow, UNC5221 and others) spying on maritime, energy and political targets across the Gulf amid post-strike instability, while Iran-aligned APT activity declined and Russia's Sandworm stayed active.

China · Russia · Iran ESET Research

CISA KEV - Jun 2026

CVE-2026-50751 Ransomware
Check Point Gateway - IKEv1 auth bypass
CVE-2026-11645 Added Jun 9
Google Chromium V8 - out-of-bounds → RCE
CVE-2026-20245 Added Jun 9
Cisco Catalyst SD-WAN - root command exec
View Full KEV Catalog

Active Groups This Month

Qilin / Agenda Ransomware
The Gentlemen Ransomware
LockBit 5.0 Ransomware
Salt Typhoon China
Lazarus Group North Korea