REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
34 reports · page 1 of 1

mandiant · tlp:amber · 7/16/2026, 2:00:00 PM
Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report , the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/ai-assisted-vulnerability-managementmandiant · tlp:amber · 7/15/2026, 2:00:00 PM
The Risk of Exposed Cloud Functions and How to Harden Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RF…
mandiant · tlp:amber · 7/7/2026, 2:00:00 PM
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021 , remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapimandiant · tlp:amber · 7/2/2026, 2:00:00 PM
Google’s Continued Disruption of Malicious Residential Proxy Networks Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the following…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networksmandiant · tlp:amber · 6/29/2026, 2:00:00 PM
The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to m…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-influence-ecosystemmandiant · tlp:amber · 6/25/2026, 2:00:00 PM
STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military or…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gatheringmandiant · tlp:amber · 6/24/2026, 11:00:00 AM
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability ( CVE-2026-20245 ) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account …
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-managermandiant · tlp:amber · 6/15/2026, 2:00:00 PM
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromis…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-researchmandiant · tlp:amber · 6/11/2026, 2:00:00 PM
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273 , a critical remote code execution vulnerability (CVSS 9.8) in the E…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploitmandiant · tlp:amber · 6/5/2026, 2:00:00 PM
Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United Stat…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firmsmandiant · tlp:amber · 5/25/2026, 2:00:00 PM
2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region. …
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-servicesmandiant · tlp:amber · 5/25/2026, 2:00:00 PM
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (R…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerabilitymandiant · tlp:amber · 5/15/2026, 2:00:00 PM
Welcome to BlackFile: Inside a Vishing Extortion Operation Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass tra…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operationmandiant · tlp:amber · 5/11/2026, 2:00:00 PM
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response …
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-accessmandiant · tlp:amber · 4/23/2026, 2:00:00 PM
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrus…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malwaremandiant · tlp:amber · 4/16/2026, 2:00:00 PM
Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/defending-enterprise-ai-vulnerabilitiesmandiant · tlp:amber · 4/15/2026, 2:00:00 PM
The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously ob…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscapemandiant · tlp:amber · 4/2/2026, 2:00:00 PM
vSphere and BRICKSTORM Malware: A Defender's Guide Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. These operations directly target the VMware vSphere ecosystem, specifically the vCenter Server Appliance (VCSA) and ESXi hypervisors. To help organizations stay ahead of these risks, we will focus on the essential hardening strate…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/vsphere-brickstorm-defender-guidemandiant · tlp:amber · 3/31/2026, 2:00:00 PM
North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack Written by: Austin Larsen, Dima Lenz, Adrian Hernandez, Tyler McLellan, Christopher Gardner, Ashley Zaya, Michael Rudden, Mon Liclican, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) is tracking an active software supply chain attack targeting the popular Node Package Manager (NPM) package " axios ." Between March 31, 2026, 00:21 and 03:20 UTC, an attacker int…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/north-korea-threat-actor-targets-axios-npm-packagemandiant · tlp:amber · 3/23/2026, 2:00:00 PM
M-Trends 2026: Data, Insights, and Strategies From the Frontlines Every year, the cyber threat landscape forces defenders to adapt to evolving adversary tactics, techniques, and procedures (TTPs). In 2025, Mandiant observed a clear divergence in adversary pacing that closely aligns with the trends we have been documenting for defenders over the past year. On one end of the spectrum, cyber criminal groups optimized for immediate impact and deliberate recovery denial. On the o…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026mandiant · tlp:amber · 3/18/2026, 2:00:00 PM
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors Introduction Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chainmandiant · tlp:amber · 3/16/2026, 2:00:00 PM
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark Introduction Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ra…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscapemandiant · tlp:amber · 3/6/2026, 2:00:00 PM
Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platforms . Background Threat actors leverage destructive malware to destroy data, eliminate evidence of malicious activity, or manipulate systems in a way that renders them inoperable. Destructive cyberatt…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/preparation-hardening-destructive-attacksmandiant · tlp:amber · 3/5/2026, 2:00:00 PM
Look What You Made Us Patch: 2025 Zero-Days in Review Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan Executive Summary Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025. Although that volume of zero-days is lower than the record high observed in 2023 (100), it is higher than 2024’s count (78) and remained within the 60–100 range established over the previous four years…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-reviewmandiant · tlp:amber · 3/3/2026, 2:00:00 PM
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit Introduction Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023) . The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehen…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kitmandiant · tlp:amber · 2/25/2026, 2:00:00 PM
Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign Introduction Last week, Google Threat Intelligence Group (GTIG), Mandiant, and partners took action to disrupt a global espionage campaign targeting telecommunications and government organizations in dozens of nations across four continents. The threat actor, UNC2814, is a suspected People's Republic of China (PRC)-nexus cyber espionage group that GTIG has tracked since 2017. This prolific, el…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaignmandiant · tlp:amber · 2/17/2026, 2:00:00 PM
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day Written by: Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson, Jr., Rich Reece Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines , tracked as CVE-2026-22769 , with a CVSSv3.1 score of 10.0 . Analysis of incident response en…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-daymandiant · tlp:amber · 2/12/2026, 2:00:00 PM
GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use Introduction In the final quarter of 2025, Google Threat Intelligence Group (GTIG) observed threat actors increasingly integrating artificial intelligence (AI) to accelerate the attack lifecycle, achieving productivity gains in reconnaissance, social engineering, and malware development. This report serves as an update to our November 2025 findings regarding the advan…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/distillation-experimentation-integration-ai-adversarial-usemandiant · tlp:amber · 2/10/2026, 2:00:00 PM
Beyond the Battlefield: Threats to the Defense Industrial Base Introduction In modern warfare, the front lines are no longer confined to the battlefield; they extend directly into the servers and supply chains of the industry that safeguards the nation. Today, the defense sector faces a relentless barrage of cyber operations conducted by state-sponsored actors and criminal groups alike. In recent years, Google Threat Intelligence Group (GTIG) has observed several distinct ar…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-basemandiant · tlp:amber · 2/9/2026, 2:00:00 PM
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering Written by: Ross Inman, Adrian Hernandez Introduction North Korean threat actors continue to evolve their tradecraft to target the cryptocurrency and decentralized finance (DeFi) verticals. Mandiant recently investigated an intrusion targeting a FinTech entity within this sector, attributed to UNC1069 , a financially motivated threat actor active since at least 2018. This investigation r…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/unc1069-targets-cryptocurrency-ai-social-engineeringmandiant · tlp:amber · 1/30/2026, 2:00:00 PM
Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS Introduction Mandiant is tracking a significant expansion and escalation in the operations of threat clusters associated with ShinyHunters-branded extortion. As detailed in our companion report, 'Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft' , these campaigns leverage evolved voice phishing (vishing) and victim-branded credential harves…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saasmandiant · tlp:amber · 1/30/2026, 2:00:00 PM
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft Introduction Mandiant has identified an expansion in threat activity that uses tactics, techniques, and procedures (TTPs) consistent with prior ShinyHunters-branded extortion operations. These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) cred…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theftmandiant · tlp:amber · 1/28/2026, 2:00:00 PM
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network Introduction This week Google and partners took action to disrupt what we believe is one of the largest residential proxy networks in the world, the IPIDEA proxy network. IPIDEA’s proxy infrastructure is a little-known component of the digital ecosystem leveraged by a wide array of bad actors. This disruption, led by Google Threat Intelligence Group (GTIG) in partnership with other teams, in…
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-networkmandiant · tlp:amber · 1/27/2026, 2:00:00 PM
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 Introduction The Google Threat Intelligence Group (GTIG) has identified widespread, active exploitation of the critical vulnerability CVE-2025-8088 in WinRAR, a popular file archiver tool for Windows, to establish initial access and deliver diverse payloads. Discovered and patched in July 2025, government-backed threat actors linked to Russia and China as well as financially motivated threat actors …
Read original ↗https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability