Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Cyble's mid-year threat report describes a first half of 2026 marked by intense ransomware activity, with 702 attacks in March and 1,138 in the Americas during Q1. Access brokers and blurred nation-state hacktivism have made the landscape faster and more coordinated.
The first half of 2026 has given security teams little room to breathe.
Cyble's mid-year threat trends report warns that the first half of 2026 saw relentless ransomware activity with little respite for defenders. Access brokers commoditized network intrusions, fueling a pipeline of victims for ransomware affiliates.
Check Point Research tracks Cavern Manticore, an Iran-nexus threat actor targeting Israeli government and IT sectors. The actor employs a modular C2 framework built on .NET with anti-analysis features using uncommon compilation formats.
Check Point Research has uncovered a modular command-and-control (C2) framework called "Cavern" used by the Iran-linked threat actor Cavern Manticore, which primarily targets Israeli government and IT sectors. The group, associated with Iran's Ministry of Intelligence and Security (MOIS), shares ties with known Iranian APTs like MuddyWater and Lyceum.
Check Point Research has identified "Cavern Manticore," an Iran-linked advanced persistent threat (APT) group targeting Israeli government and IT sectors using a sophisticated modular command-and-control (C2) framework. The group, affiliated with Iran’s Ministry of Intelligence and Security (MOIS), shares ties with known Iranian threat actors like MuddyWater and Lyceum.