Google Threat Intelligence Group

Entity category: organization

Cybersecurity

North Korean Hackers Hide Malware on Blockchain

EtherHiding is a technique used by North Korean hackers to hide malware on public blockchains, making it hard for authorities…

Read More »
Cybersecurity

Nation-State Hackers Use “Bulletproof” Blockchains to Spread Malware

State-sponsored hackers, including a North Korean group, are now hiding malware within public cryptocurrency blockchains, creating a resilient and nearly…

Read More »
BigTech Companies

Google: Clop Hackers Stole Major Data in Oracle Breach

The Clop ransomware group breached Oracle's E-Business Suite starting around August 9, exploiting a zero-day vulnerability (CVE-2025-61882) to steal corporate…

Read More »
BigTech Companies

Urgent: Hackers Exploit Unpatched Oracle EBS Vulnerabilities

Oracle has confirmed active exploitation of unpatched vulnerabilities in its E-Business Suite, with hackers sending extortion emails claiming to have…

Read More »
Business

Oracle Ties Clop Ransomware to Critical July 2025 Flaws

Oracle has linked extortion emails from the Clop ransomware group to critical vulnerabilities in its E-Business Suite, which were patched…

Read More »
BigTech Companies

Oracle Warns Known Flaws Fueling Recent Ransomware Attacks

Oracle is warning that known vulnerabilities in its E-Business Suite are being exploited in ransomware attacks, with customers receiving extortion…

Read More »
Business

SonicWall VPN Attacks Intensify, MFA Bypassed

A ransomware group named Akira is exploiting SonicWall SSL VPN appliances, primarily through a known vulnerability (CVE-2024-40766), to bypass multi-factor…

Read More »
Business

‘BRICKSTORM’ Backdoor: Chinese Hackers Target US Firms

A sophisticated cyber espionage campaign using the BRICKSTORM backdoor is targeting U.S. companies, particularly in legal, tech, and SaaS sectors,…

Read More »
BigTech Companies

Google: BrickStorm Malware Stole U.S. Data for a Year

A sophisticated cyber espionage campaign using BrickStorm malware successfully stole sensitive data from American technology, legal, SaaS, and BPO companies…

Read More »
Business

SonicWall SMA100 Update Eradicates Rootkit Malware

SonicWall has released a critical firmware update for its SMA 100 series appliances that can eradicate the OVERSTEP rootkit malware,…

Read More »
Business

Salesloft & Drift Breach: How Attackers Infiltrated Systems

A cybersecurity breach at Salesloft began with unauthorized access to its GitHub account, leading to data theft from customer Salesforce…

Read More »
BigTech Companies

Qualys, Tenable Hit in Salesloft Data Breach

Tenable and Qualys experienced unauthorized access to their Salesforce data due to stolen OAuth tokens from the Salesloft Drift application,…

Read More »
Business

Major Cybersecurity Firms Impacted by Salesloft Data Breach

A data breach at Salesloft impacted over 700 organizations, including major cybersecurity firms, by compromising OAuth tokens to access Salesforce…

Read More »
BigTech Companies

Google: Salesloft AI Agent Data Breach Escalates Significantly

Google has issued a critical alert warning that all security tokens for Salesloft Drift AI should be considered compromised due…

Read More »
Business

Qantas hit by cyberattack amid aviation security breaches

Qantas confirmed a cybersecurity breach affecting customer data on a third-party platform, potentially exposing personal details like names, emails, and…

Read More »
Business

U.S. Insurance Firms Now Prime Targets for Cyber Hackers

Cybercriminals, particularly the hacking group Scattered Spider, are increasingly targeting U.S. insurance companies, shifting from previous attacks on U.K. retail…

Read More »