Skip to main content
← All controls

Log retention and SIEM

Description

What this control does

Log retention and SIEM

Associated risks

Risks this control addresses

Live threat patterns this control mitigates:

CRITICAL TA416 resumes European government espionage campaigns Since mid-2025, China-aligned threat actor TA416 has resumed targeting European government and diplomatic organizations after a two-year operational… CRITICAL China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency… Jewelbug is a China-based threat actor conducting dual operations: espionage campaigns targeting foreign governments and militaries, alongside a… CRITICAL Analysis of a Modular Cyber Espionage Framework Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk,… CRITICAL NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using… HIGH Mirage Kitten targets Middle East and Africa region with new malware Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been… CRITICAL Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms… HIGH Westernint.com By eraleign (apt73) Western International Group is a large private conglomerate based in Dubai that operates in the r... HIGH Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns Geopolitical pressure drove much of the state-sponsored cyber activity recorded between October 2025 and March 2026, according to… HIGH Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict The Iranian IRGC-affiliated threat actor Nimbus Manticore launched sophisticated cyber operations during Operation Epic Fury, the US military… HIGH Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns Unit 42 researchers identified six new remote access Trojan variants deployed by Iran-nexus APT group Screening Serpens between… CRITICAL Middle East Malicious Infrastructure Report: 1,350+ C2 Servers Mapped Across 98 Providers Between February and May 2026, over 1,350 active command-and-control servers were identified across 98 infrastructure providers spanning 14…