Skip to content
You can now search across every topic, entity and event.What's new
Timeline

Mandiant

Google Cloud threat intelligence and IR firm; authors M-Trends; tracks state-sponsored APTs.

21 of 21 entries (20 events, 1 interactions)

Filters
#11 16 Jul
#10 8 Jul
#8 18 Jun

Mentioned in: Splunk lands its first-ever KEV entry

Cybersecurity: Threats and Defences
#7 9 Jun
#4 11 May

Published attribution report on 11 May 2026 documenting AI-generated zero-day and AI-augmented threat clusters

Cybersecurity: Threats and Defences: GTIG names the first LLM-written working zero-day
#4 11 May

Confirmed @shadanai/openclaw and @qqbrowser/openclaw-qbot as additional WAVESHAPER.V2 distribution vectors

Cybersecurity: Threats and Defences: UNC1069 expands the npm WAVESHAPER supply chain
#4 11 May

Published attribution naming UNC6780 as the Cisco repository breach operator

Cybersecurity: Threats and Defences: UNC6780 takes Cisco AI Defense source code
#4 8 May

Named UNC6780 as the operator behind the LiteLLM intrusion and documented the 36-hour exploitation window

Cybersecurity: Threats and Defences: LiteLLM SQL injection hits in 36 hours
#3 7 May
#3 5 May

Co-disclosed UNC1069 activity with GTIG on 5 May

Cybersecurity: Threats and Defences: UNC1069 planted WAVESHAPER.V2 in Axios via maintainer phishing
#2 29 Apr
#2 28 Apr
#2 24 Apr
#2 23 Apr

Published disclosure of UNC6692 SNOW malware ecosystem and Teams-based social engineering campaign

Cybersecurity: Threats and Defences: UNC6692 runs SNOW through Microsoft Teams
#1 23 Mar

Mentioned in: CitrixBleed 3 lands on SAML broker

Cybersecurity: Threats and Defences
#1 11 Mar
#1 1 Mar

Published M-Trends 2026 report disclosing UNC5221 BRICKSTORM campaign with 393-day average dwell time

Cybersecurity: Threats and Defences: BRICKSTORM dwell hits 393 days, Mandiant
#1 1 Mar
StatedM2M-Trends 2026
published threat intelligence report
Cybersecurity: Threats and Defences · source event