Threat Actor News

2 articles

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign

Apr 7, 2026

Threat Actor
High

An international operation from law enforcement authorities in partnership with private companies has disrupted FrostArmada, an APT28 campaign hijacking local traffic from MikroTik and TP-Link routers

Read Article

Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool

Mar 10, 2026

Threat Actor
High

The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations. [...]

Read Article

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.