Security news aggregator

Latest coverage for Threat Actor

Stay informed on the latest updates about threat actors in cybersecurity. Discover patterns, tactics, and defenses against malicious entities.

3256 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Threat Actor is a term used in information security to describe an individual or group responsible for an event or series of events that negatively impact the confidentiality, integrity, or availability of information. These actors can be motivated by a range of objectives including financial gain, political activism, espionage, or simply the challenge and thrill of breaching systems.

In the context of information security, threat actors operate by exploiting vulnerabilities within networks, systems, or applications to carry out their malicious activities. They range in sophistication from lone hackers to complex state-sponsored groups and can use a variety of tactics, techniques, and procedures (TTPs) to achieve their goals. Understanding the behaviors and attributes of threat actors is crucial for developing strategies to detect, prevent, and mitigate cyber attacks.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 3256 Filtered view

Attackers spent five months silently stealing emails from a stock exchange executive’s Outlook account in a suspected espionage operation. A threat actor quietly sat inside a senior executive’s Outlook account at a major global stock exchange for roughly 150 days, from October 2025 to March 2026. Broadcom’s Symantec and Carbon Black threat-hunting team investigated the […]

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026

Threat actors are exploiting a critical FortiClient EMS flaw, tracked as CVE-2026-35616, to deploy malware on unpatched systems. Threat actors are exploiting a critical FortiClient EMS vulnerability, tracked as CVE-2026-35616 (CVSS score of 9.1), that allows remote code execution without authentication. Fortinet released fixes in April after confirming zero-day attacks in the wild and urged […]

Microsoft and Resecurity disrupted Fox Tempest, a malware-signing service that used fake Microsoft certificates to make malware look legitimate. Resecurity supported Microsoft’s Digital Crimes Unit (DCU) in its disruption of Fox Tempest, a financially motivated threat actor operating a malware-signing-as-a-service (MSaaS) capability used by cybercriminals to make malicious files appear legitimate. On May 19, 2026, […]

A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitment-themed social engineering and bespoke macOS malware

Loading more headlines...