Tag Mandiant

New Study Connects Unrelated Malware Attacks to Chinese Hackers

A recent report highlights the cyber espionage group APT41, tied to a series of malware campaigns that leverage COVID-themed phishing strategies to target individuals in India. This revelation comes from an analysis by the BlackBerry Research and Intelligence team, which has connected various aspects of the group’s operational infrastructure. According…

Read MoreNew Study Connects Unrelated Malware Attacks to Chinese Hackers

Ransomware Group FIN12 Intensifies Attacks on Healthcare Sector

A financially motivated threat group, identified as FIN12, has been linked to a series of RYUK ransomware incidents since October 2018. This organization demonstrates significant collaboration with TrickBot-affiliated actors while utilizing publicly accessible tools like Cobalt Strike Beacon payloads to penetrate victim networks. Cybersecurity firm Mandiant has attributed these security…

Read MoreRansomware Group FIN12 Intensifies Attacks on Healthcare Sector

Envoy Air (American Airlines) Confirms Oracle EBS Zero-Day Breach Linked to Cl0p Group

On October 17, 2025, Envoy Air, a Texas-based regional airline and the largest carrier under American Airlines, confirmed that it was recently compromised due to a series of cyberattacks exploiting a zero-day vulnerability in a major corporate software application. The hacks were executed by CL0P, a notorious ransomware group known…

Read MoreEnvoy Air (American Airlines) Confirms Oracle EBS Zero-Day Breach Linked to Cl0p Group

Why the F5 Hack Posed an ‘Imminent Threat’ to Thousands of Networks

Numerous digital infrastructures—primarily managed by the US government and major Fortune 500 companies—are currently under an “imminent threat” of breaches from nation-state hacking groups, following an alarming breach of a leading software provider, as warned by federal authorities on Wednesday. F5 Networks, a Seattle-based provider of networking solutions, publicly acknowledged…

Read MoreWhy the F5 Hack Posed an ‘Imminent Threat’ to Thousands of Networks

Emerging Malicious Software Threatens Ukrainian Government and Business Sectors

New Malware Threat “WhisperGate” Targets Ukrainian Entities Amid Geopolitical Tensions On Saturday, cybersecurity experts from Microsoft revealed the emergence of a new malware operation identified as “WhisperGate.” This sophisticated form of malware is primarily aimed at government entities, non-profits, and IT organizations within Ukraine, amid escalating geopolitical tensions with Russia.…

Read MoreEmerging Malicious Software Threatens Ukrainian Government and Business Sectors

Thousands of Customers at Risk Following Nation-State Attack on F5’s Network

F5 Networks Faces Security Concerns Amid Reports of Compromise In a troubling development for cybersecurity, F5 Networks has reported that its BIG-IP appliances, crucial for load balancing and data encryption at the network edge, may have been compromised. These devices are positioned strategically within networks, enabling them to facilitate traffic…

Read MoreThousands of Customers at Risk Following Nation-State Attack on F5’s Network

CISA Includes Acclaim USAHERDS Vulnerability in KEV Catalog Due to Ongoing Exploitation

On December 23, 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of a critical vulnerability affecting Acclaim Systems USAHERDS to its Known Exploited Vulnerabilities (KEV) catalog. This addition follows verifiable evidence that the flaw has been actively exploited. The vulnerability, identified as CVE-2021-44207, has a CVSS…

Read MoreCISA Includes Acclaim USAHERDS Vulnerability in KEV Catalog Due to Ongoing Exploitation

SonicWall Reports That Hackers Accessed All Firewall Backups

In September 2025, SonicWall disclosed a data breach affecting its cloud backup service, initially indicating that fewer than 5% of its clients were impacted. However, this assessment has evolved as SonicWall, in collaboration with incident response firm Mandiant, has confirmed that attackers accessed backup configuration files for all customers utilizing…

Read MoreSonicWall Reports That Hackers Accessed All Firewall Backups