Tag Mandiant

Researchers Uncover Three Hacktivist Groups Advocating for Russian Interests

According to Mandiant, at least three alleged hacktivist groups purportedly aligned with Russian interests are believed to collaborate with state-sponsored cyber operatives. Mandiant, a Google-affiliated cybersecurity firm, has reported with moderate confidence that key figures behind the hacktivist Telegram channels such as ‘XakNet Team,’ ‘Infoccentr,’ and ‘CyberArmyofRussia_Reborn’ are likely coordinating…

Read MoreResearchers Uncover Three Hacktivist Groups Advocating for Russian Interests

Chinese Hackers Compromise Juniper Networks Routers Using Tailored Backdoors and Rootkits

A recent report from Mandiant has revealed that the Chinese cyber espionage group known as UNC3886 is actively targeting outdated MX Series routers from Juniper Networks. This campaign is aimed at deploying custom backdoors, demonstrating a tactical shift towards exploiting internal networking infrastructure. According to Mandiant, the backdoors utilized diverse…

Read MoreChinese Hackers Compromise Juniper Networks Routers Using Tailored Backdoors and Rootkits

Microsoft Reveals Global Cyber Attacks by Sandworm Subgroup Affecting Over 15 Countries

A subgroup of the notorious Russian state-sponsored hacking entity known as Sandworm has been linked to a persistent global access operation, termed BadPilot, which has been under way for several years. The Microsoft Threat Intelligence team recently disclosed this in a report, emphasizing the group’s strategy of compromising internet-facing infrastructure…

Read MoreMicrosoft Reveals Global Cyber Attacks by Sandworm Subgroup Affecting Over 15 Countries

APT29 Leveraged Windows Vulnerability to Breach European Diplomatic Network

A notorious Russia-based cyber espionage group known as APT29 has reportedly exploited a less common Windows feature called Credential Roaming following a successful phishing operation targeting an unmentioned European diplomatic organization. The strategic focus on diplomatic targets aligns with APT29’s historical modus operandi, demonstrating their commitment to gathering intelligence that…

Read MoreAPT29 Leveraged Windows Vulnerability to Breach European Diplomatic Network

Salesloft Drift Breach Linked to GitHub Security Breach and Compromised OAuth Tokens

Recent data breaches have raised concerns about security within popular applications, particularly the use of the Salesloft Drift application to compromise Salesforce data. In an important update, Salesloft has reported that the security incident has been addressed, with containment measures and customer protections now in effect. To investigate the breach,…

Read MoreSalesloft Drift Breach Linked to GitHub Security Breach and Compromised OAuth Tokens

Gootkit Malware Implements New Strategies Targeting Healthcare and Financial Institutions

Recent investigations by Cybereason have revealed that the Gootkit malware, also known as Gootloader, is primarily targeting healthcare and financial entities across the United States, United Kingdom, and Australia. These findings shed light on the evolving threat landscape, emphasizing the need for heightened vigilance in these sectors. In a December…

Read MoreGootkit Malware Implements New Strategies Targeting Healthcare and Financial Institutions

Attackers Take Advantage of Sitecore Zero-Day Vulnerability

Encryption & Key Management, Security Operations Mandiant Uncovers Significant Vulnerability in Sitecore Products Prajeet Nair (@prajeetspeaks) • September 4, 2025 Image: Shutterstock Cybercriminals have exploited a recently patched zero-day vulnerability within Sitecore, a widely used content management system supporting numerous major enterprises, including HSBC, L’Oréal, Toyota, and United Airlines. Sitecore…

Read MoreAttackers Take Advantage of Sitecore Zero-Day Vulnerability

DslogdRAT Malware Exploits Ivanti ICS Zero-Day CVE-2025-0282 in Cyber Attacks in Japan

Recent reports have highlighted the emergence of a sophisticated malware strain known as DslogdRAT, which exploits a recently patched vulnerability in Ivanti Connect Secure (ICS). This vulnerability, tracked as CVE-2025-0282, was initially leveraged by cybercriminals against organizations in Japan in December 2024. It enabled attackers to install both the malware…

Read MoreDslogdRAT Malware Exploits Ivanti ICS Zero-Day CVE-2025-0282 in Cyber Attacks in Japan

Google Reports Troubling Increase in Russian Cyber Attacks Targeting Ukraine

In a significant escalation of cyber warfare, a joint report by Google’s Threat Analysis Group (TAG) and Mandiant reveals that Russian cyber attacks against Ukraine surged by 250% in 2022 compared to two years prior. This dramatic increase coincided with Russia’s military invasion of Ukraine in February 2022, focusing on…

Read MoreGoogle Reports Troubling Increase in Russian Cyber Attacks Targeting Ukraine