Threat advisories
Campaigns we compile and cross-check from public reporting: what the activity does, the techniques behind it, the indicators we can corroborate, and what to do about it.
Exploitation of CVE-2024-3400 in Palo Alto Networks Firewalls
An active global campaign is targeting organizations with vulnerable Palo Alto Networks firewalls running specific PAN-OS versions. The campaign exploits CVE-2024-3400 within the GlobalProtect gateway feature to gain unauthorized access. OffPerimeter analysis indicates this activ
TA419 targets AI policy experts via OneDrive adversary-in-the-middle phishing
TA419 is a China-aligned espionage group targeting AI policy experts within the United States. The group employs impersonation of high-profile individuals to conduct phishing attacks against sectors including government, education, legal, and technology. By directing targets to f
JSP webshells deployed via CVE-2026-73570 exploitation in Zimbra Collaboration Suite
Threat actors are exploiting CVE-2026-73570, an OS command injection vulnerability in Zimbra Collaboration Suite, to gain unauthorized access. The attack chain includes out-of-band scanning, the deployment of multiple JSP webshells, and privilege escalation to root. Once access i
Exploitation of Citrix NetScaler Zero-Days to Deploy WHIPSHOT and SLAPSHOT Malware
Since at least early September 2026, suspected state-sponsored actors have been exploiting CVE-2026-88771 and CVE-2026-88772 in Citrix NetScaler ADC and Gateway appliances. The attackers gain unauthenticated remote code execution to install the WHIPSHOT PHP web shell and the SLAP
SalesBleed
The SalesBleed campaign targets technology sector organizations by exploiting vulnerabilities within Salesforce Agentforce. Attackers leverage Web-to-Lead forms to facilitate AI agent hijacking and unauthorized data exfiltration. This activity is used to compromise CRM data and d
TeamPCP exploits TanStack supply chain to steal CrowdSec code
TeamPCP exploited a supply chain vulnerability in TanStack packages to compromise 300 repositories, including those belonging to CrowdSec. The attack involved the insertion of 84 malicious artifacts across 42 TanStack packages, leading to the exfiltration of source code. No custo
Exploitation of CVE-2026-65660 in Microsoft SharePoint to deploy webshell backdoors
An unidentified threat actor is actively exploiting a high severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-65660. The campaign targets government entities to establish a foothold within sensitive networks. OffPerimeter analysis indicat
PRC-Nexus Espionage Actor Exploits GlobalProtect and Abuses Remote Support Tools
A suspected PRC-nexus espionage actor conducted a widespread exploitation campaign targeting the CVE-2026-0257 vulnerability in GlobalProtect VPN portals. The campaign involved advanced evasion and privilege escalation techniques, including the disabling of security controls such
AI agent frameworks used to deploy skimmer malware against online retailers
A threat actor is leveraging three AI tools—Strix, Cairn, and Hermes—to conduct large-scale automated attacks against hundreds of online retailers. The campaign, active since July 2026, utilizes these agents for scanning, exploitation, and orchestration to inject skimmer malware
Carbonato botnet exploits unauthenticated Docker APIs to deploy Hermes Agent AI framework
Carbonato is a botnet that spreads through worm-like scanning of networks for exposed Docker daemons. The campaign leverages the Hermes Agent AI framework, specifically using a GH0ST persona, to interpret commands received via Telegram and execute them on victim hosts. The malwar
Red Heron group exploits wp2shell and ZyXEL flaws to steal govt data
A Chinese-speaking threat actor linked to the Red Heron group has been exploiting vulnerabilities in WordPress, ZyXEL GS1900 switches, and other technologies to steal sensitive data from government and high-value targets. The campaign has compromised over 996 devices and more tha
MovieReaper malware distributed via compromised torrent files targeting global users
The MovieReaper campaign is a multi-stage malware operation that uses compromised torrent files to distribute a modular framework. The malware employs HTTP and blockchain-based C2 infrastructure, including the Solana blockchain, to maintain persistence and evade detection. It has
Storm-2992 deploys EvilTokens PhaaS using device-code phishing on Microsoft 365 accounts
The Storm-2992 threat actor operated the EvilTokens PhaaS platform, which compromised over 12,000 Microsoft accounts across 10,000 organizations. The campaign used device code phishing to bypass MFA protections and deliver BEC attacks. Microsoft, in collaboration with law enforce
ClickFix backdoor distributed via Brevo supply-chain attack on WordPress sites
A supply-chain attack on Brevo compromised a Cloudflare API key, allowing attackers to inject malicious ClickFix scripts into customer websites. The attack affected Brevo's domains and embedded scripts, leading to the distribution of a malicious WordPress plugin named 'Web Media