Category: Threat Intelligence

This Weekly Threat Advisory highlights the latest Ransomware, Malware, CVEs, Threat Actors, and Phishing Kits targeting organizations globally.

Emerging malware strains and ransomware groups are leveraging advanced exploitation techniques to bypass security defenses.

Newly disclosed CVEs are actively being weaponized by threat actors, increasing the risk of targeted attacks.

Phishing kits are evolving, enabling large-scale credential theft and unauthorized access to critical systems.

Security teams must stay vigilant, patch vulnerabilities, enhance detection, and strengthen cyber defense strategies against these evolving threats.

HACKFORLAB Weekly Threat Advisory · June 15-21, 2026 · 55,480 indicator observations across 89 adversary clusters · radar showing intelligence graph with multi-pivot locked cluster · Rhysida-Interlock 219 IOCs, ClickFix 215 IOCs, JetBrains plugin supply chain attack, AI platform abuse, APT37 and UNC6508 active
0 41
Posted in Threat Intelligence

Weekly Threat Advisory: Cluster Analysis & Top IOCs, June 15 – 21, 2026

55,480 indicator observations across 89 adversary clusters this week. A ransomware operator rotated a full multi-pivot kill chain (Rhysida-Interlock, 219 indicators across 4 IOC types). Developer supply chain became this week’s preferred attack surface (15 typosquat code-editor plugins + 8 browser extensions + 6 marketing-CDN typosquats). AI platforms began appearing as adversary infrastructure (19 chat-share redirector domains + 39-indicator AI-generated lure campaign). Full MITRE ATT&CK mapping per cluster, subnet-clustering signals, top 15 IOCs per indicator type, and 4 production-ready Sigma rules.

HACKFORLAB Weekly Threat Advisory · June 8-14, 2026 · 76,205 indicator observations across 154 adversary clusters · radar showing intelligence graph with crosshair locked on featured cluster · DPRK 6x escalation, Velvet Ant APT, Tor anonymisation surge, Mirai wave, Clearfake, Formbook
0 50
Posted in Threat Intelligence

Weekly Threat Advisory: Top Cyber Adversaries, June 8 – 14, 2026

76,205 indicator observations across 154 adversary clusters. Tor anonymisation network surged to 17% of the catalogue, DPRK activity escalated six-fold, and the Velvet Ant network-appliance APT cluster reappeared. Full MITRE ATT&CK technique pressure, Sigma detection recipes, and platform-ready intelligence.

HACKFORLAB Weekly Threat Intelligence Advisory · June 1-7, 2026 · 55,729 indicator observations across 91 adversary clusters · radar showing intelligence graph with crosshair locked on featured cluster · Silent Ransom, DPRK, VShell, Mirai infrastructure flood, AdaptixC2, VerdantBamboo
0 60
Posted in Threat Intelligence

Weekly Threat Advisory: Top Cyber Adversaries, June 1 – 7, 2026

55,729 indicator observations across 91 adversary clusters this week — featuring Silent Ransom Group, DPRK-aligned activity, VShell, and a Mirai-class IoT seeder wave. Trend analysis, severity breakdown, detection recipes, and the platform to query it all.

Weekly Threat Advisory cover · Top Cyber Adversaries May 24 – 31, 2026 · 1.35M observations · 87 adversary clusters · CobaltStrike · Cloud Atlas · DPRK · Kimsuky · Void Dokkaebi · AdaptixC2 · VShell
0 68
Posted in Threat Intelligence

Weekly Threat Advisory: Top Cyber Adversaries May 24 – 31, 2026

Weekly Threat Advisory · May 24 – 31, 2026 · 1.35M observations · 87 adversary clusters · CobaltStrike dominant · DPRK-linked activity (Kimsuky, Void Dokkaebi) · Cloud Atlas · AdaptixC2 / VShell emerging C2 frameworks · MITRE T1190 / T1105 / T1041 / T1082 pressure.

Weekly Threat Advisory cover for May 18-24 2026
0 67
Posted in Threat Intelligence

Weekly Threat Advisory: Top Cyber Adversaries May 18 – 24, 2026

Weekly Threat Advisory | Supply Chain | INJ3CTOR3 | BadIIS | AMOS | Anatsa | SD-WAN CVE-2026-20182