logo

Google Cloud Threat Intelligence

ID: fb64734b-506d-57c5-8bb6-6dd1a06bdf83

STIX ID: identity--fb64734b-506d-57c5-8bb6-6dd1a06bdf83

Feed Type: rss

Earliest post: 2024-06-18

Latest post: 2026-07-16

Frontline Mandiant investigations, expert analysis, tools and guidance, and in-depth security research.

01/01/2020
07/23/2026
Title Date Published Describes IncidentAuthorVisible
Google’s Continued Disruption of Malicious Residential Proxy Networks2026-07-02TrueGoogle Threat Intelligence Group True
The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem2026-06-29TrueGoogle Threat Intelligence Group True
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus2026-06-25TrueGoogle Threat Intelligence Group True
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager2026-06-24TrueMandiant True
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research2026-06-15TrueGoogle Threat Intelligence Group True
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit2026-06-11TrueMandiant True
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms2026-06-05TrueMandiant True
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability2026-05-25TrueMandiant True
2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services2026-05-25TrueGoogle Threat Intelligence Group True
Welcome to BlackFile: Inside a Vishing Extortion Operation2026-05-15TrueGoogle Threat Intelligence Group True
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access2026-05-11TrueGoogle Threat Intelligence Group True
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite2026-04-23TrueMandiant True
The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape2026-04-15TrueGoogle Threat Intelligence Group True
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack2026-03-31TrueGoogle Threat Intelligence Group True
M-Trends 2026: Data, Insights, and Strategies From the Frontlines2026-03-23TrueJurgen KutscherTrue
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors2026-03-18TrueGoogle Threat Intelligence Group True
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape2026-03-16TrueGoogle Threat Intelligence Group True
Look What You Made Us Patch: 2025 Zero-Days in Review2026-03-05TrueGoogle Threat Intelligence Group True
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit2026-03-03TrueGoogle Threat Intelligence Group True
Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign2026-02-25TrueGoogle Threat Intelligence Group True
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day2026-02-17TrueMandiant True
Beyond the Battlefield: Threats to the Defense Industrial Base2026-02-10TrueGoogle Threat Intelligence Group True
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering2026-02-09TrueMandiant True
Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS2026-01-30TrueMandiant True
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network2026-01-28TrueGoogle Threat Intelligence Group True
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-80882026-01-27TrueGoogle Threat Intelligence Group True
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)2025-12-12TrueGoogle Threat Intelligence Group True
Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue2025-12-03TrueGoogle Threat Intelligence Group True
Beyond the Watering Hole: APT24's Pivot to Multi-Vector Attacks2025-11-20TrueGoogle Threat Intelligence Group True
Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem2025-11-17TrueMandiant True
Time Travel Triage: An Introduction to Time Travel Debugging using a .NET Process Hollowing Case Study2025-11-13TrueMandiant True
No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-124802025-11-10TrueMandiant True
Keys to the Kingdom: A Defender's Guide to Privileged Account Monitoring2025-10-28TrueMandiant True
Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials2025-10-23TrueGoogle Threat Intelligence Group True
Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace2025-10-21TrueGoogle Threat Intelligence Group True
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER2025-10-20TrueGoogle Threat Intelligence Group True
New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware2025-10-16TrueMandiant True
DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains2025-10-16TrueMandiant True
Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign2025-10-09TrueMandiant True
Cybercrime Observations from the Frontlines: UNC6040 Proactive Hardening Recommendations2025-09-30TrueMandiant True
Another BRICKSTORM: Stealthy Backdoor Enabling Espionage into Tech and Legal Sectors2025-09-24TrueMandiant True
ViewState Deserialization Zero-Day Vulnerability in Sitecore Products (CVE-2025-53690)2025-09-03TrueMandiant True
Widespread Data Theft Targets Salesforce Instances via Salesloft Drift2025-08-26TrueGoogle Threat Intelligence Group True
Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats2025-08-25TrueGoogle Threat Intelligence Group True
A Cereal Offender: Analyzing the CORNFLAKE.V3 Backdoor2025-08-20TrueMandiant True
From Help Desk to Hypervisor: Defending Your VMware vSphere Estate from UNC39442025-07-23TrueMandiant True
Beyond Convenience: Exposing the Risks of VMware vSphere Active Directory Integration2025-07-23TrueMandiant True
Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor2025-07-16TrueMandiant True
Protecting the Core: Securing Protection Relays in Modern Substations2025-06-30TrueMandiant True
What’s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia2025-06-18TrueGoogle Threat Intelligence Group True

1–50 of 98