The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Non-Profit/Volunteering
Breach intelligence, attack campaigns, and threat reports targeting the Non-Profit/Volunteering sector.
Explore Other Sectors
Non-Profit/Volunteering Threat Reports
UTA0565 Exploits Chrome-Windows Zero-Day Chain in Sophisticated Campaign Against Asian Governments
In September 2026, Chinese threat actor UTA0565 exploited a zero-day exploit chain targeting Google Chrome and Microsoft Windows vulnerabilities (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to deploy CLEANGULP malware. The attackers used fake websites masquerading as legitimate media organizations and NGOs to target Asian government entities, particularly through phishing campaigns related to Hong Kong activist Chow Hang-tung. The exploit chain allowed attackers to break out of Chrome's sandbox and achieve remote code execution, demonstrating sophisticated coordinated efforts within the Chinese cyber espionage community. This incident highlights the growing sophistication of state-sponsored actors utilizing coordinated zero-day exploit chains and the increasing targeting of government entities through social engineering campaigns tied to geopolitical events.
1 day ago
Kill Chain
Iran's Handala Hack Weaponizes Telegram for Sophisticated Surveillance Operations
The Iran-linked threat actor Handala Hack, operating under Iran's Ministry of Intelligence and Security (MOIS), has been attributed to a sophisticated Telegram-based surveillance campaign using the HEAVYGRAM backdoor and CRUDEEXCLUDE utility. Active since September 2023, this operation targets Iranian dissidents, journalists, and opposition groups through social engineering on messaging platforms like Telegram, WhatsApp, and Instagram. The malware masquerades as legitimate applications and establishes persistent command-and-control channels via Telegram, enabling comprehensive surveillance including file exfiltration, screenshot capture, microphone activation, and credential theft. This incident highlights the growing trend of state-sponsored actors leveraging popular messaging platforms for covert operations, demonstrating how encrypted communication channels can be weaponized for intelligence collection while evading traditional detection methods.
6 days ago
Kill Chain
Iranian State Hackers Deploy CHOSEN BRICK Malware in Global Espionage Campaign
Iranian state-linked hackers deployed CHOSEN BRICK malware in a sophisticated espionage campaign targeting dissidents, activists, and journalists in the U.S., U.K., and Netherlands throughout 2026. The attack began with social engineering via WhatsApp and Telegram, where threat actors impersonated trusted contacts to deliver malicious files disguised as legitimate applications like Norton Antivirus, Adobe Flash Player, and KeePass. Once installed, CHOSEN BRICK established persistence through Windows Registry modifications, evaded detection by adding Microsoft Defender exclusions, and exfiltrated sensitive data including email communications, Telegram and WhatsApp messages, screenshots, and audio recordings through Telegram bots and cloud storage services. This campaign exemplifies the growing sophistication of nation-state actors leveraging popular communication platforms and cloud infrastructure for command-and-control operations, highlighting the urgent need for enhanced detection capabilities against encrypted communications channels and cloud-based data exfiltration.
1 week ago
Kill Chain
BlueMoon Exploit Kit Weaponizes Chrome and Windows Zero-Days in Multi-Group APT Campaign
Multiple Chinese cyber-espionage groups deployed the BlueMoon exploit kit in August-September 2026, chaining three zero-day vulnerabilities in Chrome and Windows to achieve remote code execution and privilege escalation. The kit exploited CVE-2026-85046 and CVE-2026-87491 in Chrome's V8 JavaScript engine for sandbox escape, combined with CVE-2026-85880 in Windows ALPC for local privilege escalation. Threat actors including JungleBamboo (APT31), UTA0560, UNK_LateNight, and UNK_DoubleCheck targeted NGOs, aerospace companies, and manufacturing firms through spearphishing campaigns that delivered various backdoors including ShadowPad and Grimwedge. This incident demonstrates the increasing sophistication of state-sponsored actors in rapidly weaponizing zero-day vulnerabilities and sharing exploit tools across multiple threat groups. The coordinated use of BlueMoon by different Chinese APT groups signals a concerning trend of exploit kit sharing and collaborative cyber operations targeting critical infrastructure and civil society organizations.
2 weeks ago
Kill Chain
Five Critical WordPress Plugin Flaws Enable Complete Site Takeover
In August 2026, security researchers disclosed five critical vulnerabilities affecting popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws, with CVSS scores ranging from 9.8 to 10.0, enable unauthenticated attackers to achieve complete site takeover through authentication bypass, arbitrary file uploads, privilege escalation, and remote code execution. The vulnerabilities collectively affect millions of WordPress installations, allowing attackers to gain administrator access, execute malicious code, and completely compromise websites without requiring initial authentication. These vulnerabilities highlight the ongoing security challenges in the WordPress ecosystem, where third-party plugins and themes continue to be attractive targets for attackers. With WordPress powering over 40% of websites globally, such widespread plugin vulnerabilities represent a significant attack surface that cybercriminals are increasingly exploiting to establish footholds for ransomware deployment and data theft operations.
3 weeks ago
Kill Chain
Critical GiveWP Plugin Vulnerability Exposes 100K+ WordPress Sites to Remote Code Execution
A critical vulnerability (CVE-2026-82222) in the GiveWP WordPress donation plugin allowed unauthenticated attackers to execute arbitrary commands on hosting servers through a complex chain of PHP deserialization flaws. The vulnerability affected over 100,000 installations running versions 4.16.6 through 4.16.7.1, exploiting unsafe PHP data handling, donation processing flows, and bundled library gadget chains. Attackers could bypass disabled user registration, create accounts, inject malicious serialized objects through crafted donations, and achieve remote code execution when the server processed front-end requests. GiveWP released version 4.16.7.2 on August 27, 2026, addressing the deserialization issues and removing stored malicious payloads from affected databases. This incident highlights the growing sophistication of WordPress plugin vulnerabilities, particularly those targeting donation and e-commerce platforms that handle sensitive financial data. With WordPress powering over 40% of websites and plugin vulnerabilities increasing 35% year-over-year, organizations must prioritize rapid security updates and implement defense-in-depth strategies.
3 weeks ago
Kill Chain
Apple Issues Warnings on Mercenary Spyware Threats in 110 Countries
In August 2026, Apple issued threat notifications to users in 110 countries, alerting them to potential targeting by mercenary spyware attacks. These sophisticated attacks are designed to remotely compromise iPhones, often focusing on individuals such as journalists, activists, politicians, and diplomats. Apple emphasized the severity of these threats and advised recipients to take the notifications seriously. The prevalence of mercenary spyware attacks underscores the evolving landscape of cyber threats, highlighting the need for heightened vigilance and robust security measures among high-risk individuals and organizations.
1 month ago
Kill Chain
Vatican's 'Click to Pray' App Data Breach: A Wake-Up Call for API Security
In July 2026, the Vatican's official prayer application, 'Click to Pray,' experienced a significant data breach exposing the personal information of over 700,000 global users. The breach was due to an insecure direct object reference (IDOR) vulnerability in the app's API, allowing unauthorized access to user data, including names, email addresses, and country of origin. This incident underscores the critical need for robust access controls and regular security assessments in applications handling sensitive personal information. The prevalence of IDOR vulnerabilities highlights the importance of implementing comprehensive authorization checks to prevent unauthorized data access.
2 months ago
Kill Chain
DigitalMint Negotiator's Betrayal: A Wake-Up Call for Cybersecurity
In 2023, Angelo Martino, a ransomware negotiator at DigitalMint, exploited his position by sharing confidential client information with the BlackCat/ALPHV ransomware group. This betrayal enabled the attackers to extort a total of $75.3 million from five U.S. companies. Martino's actions included disclosing victims' negotiation strategies and insurance details, thereby maximizing ransom demands. In July 2026, he was sentenced to 70 months in prison for his role in these conspiracies. This case underscores the critical importance of trust and integrity within cybersecurity roles. The incident highlights the potential risks posed by insider threats and the necessity for organizations to implement stringent oversight and monitoring mechanisms to safeguard sensitive information.
2 months ago
Kill Chain
UN World Food Programme Data Breach: A Wake-Up Call for Humanitarian Cybersecurity
In May 2026, the United Nations' World Food Programme (WFP) experienced a significant data breach when unauthorized actors accessed its self-registration application for Palestine. This breach exposed sensitive personal information—including names, ID numbers, mobile numbers, and location data—of approximately 600,000 Palestinian households in Gaza. The WFP promptly suspended the affected platform to implement security enhancements and initiated a comprehensive investigation into the incident. This incident underscores the critical importance of robust cybersecurity measures for humanitarian organizations handling sensitive beneficiary data. The exposure of such information not only compromises individual privacy but also heightens the risk of identity theft and targeted attacks, emphasizing the need for continuous vigilance and proactive security protocols in the humanitarian sector.
3 months ago
Kill Chain
Critical Drupal Core SQL Injection Vulnerability (CVE-2026-9082) Actively Exploited
In May 2026, a critical SQL injection vulnerability, identified as CVE-2026-9082, was discovered in Drupal Core's database abstraction API. This flaw specifically affects sites utilizing PostgreSQL databases, allowing unauthenticated attackers to execute arbitrary SQL commands. Successful exploitation can lead to information disclosure, privilege escalation, and potentially remote code execution. Drupal released patches for affected versions, including 10.4.10, 10.5.10, 10.6.9, 11.1.10, 11.2.12, and 11.3.10. ([drupal.org](https://www.drupal.org/sa-core-2026-004?utm_source=openai)) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on May 22, 2026, indicating active exploitation in the wild. Organizations are urged to apply the necessary patches promptly to mitigate potential risks. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-9082?utm_source=openai))
4 months ago
Kill Chain
DigitalMint Negotiator's Betrayal: A Stark Warning for Cybersecurity
In April 2026, Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to conspiring with the BlackCat (ALPHV) ransomware group to extort five U.S. companies. Martino exploited his position by sharing confidential information, including victims' insurance policy limits and negotiation strategies, with the attackers. This collaboration led to ransom payments totaling approximately $75.3 million from sectors such as nonprofit, hospitality, financial services, retail, and medical industries. Martino faces up to 20 years in federal prison, with sentencing scheduled for July 9, 2026. This case underscores the critical need for stringent vetting and oversight of cybersecurity professionals, as insider threats can significantly amplify the impact of cyberattacks. The incident also highlights the evolving tactics of ransomware groups, emphasizing the importance of comprehensive security measures and employee integrity in safeguarding organizational assets.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports