
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentThreat actor activity and indicators

A shocking 92% of battery infrastructure is likely to face a notable cyberattack by 2031, putting millions of lives at risk. Compromising just 1,500 battery units, or 5.4% of Texas' battery fleet, could destabilize the entire grid, impacting 30 million people and causing up to $65 billion in economic damages.

The Financial Stability Board warns that AI-powered cyberattacks could spark a chain reaction of chaos in global markets, exploiting vulnerabilities in sovereign debt, private credit, and asset valuations. This threat is more than just a tech issue - it's a potentially disastrous blow to market confidence.

A defense official has warned of possible refrigeration disruptions at some Defense Commissary Agency commissaries, sparking concerns about the security of military food storage systems. Several bases have already reported outages, including Fort Irwin, F.E. Warren Air Force Base, and Naval Station Newport.

The FBI has struck a major blow against Chinese cyber espionage, disrupting a proxy network used to sell reconnaissance and operational routing capabilities to malicious actors. This key takedown targeted a technical quartermaster tied to Nanjing Xinjiuwei Network Technology Company, a company linked to the notorious QTYF spy-proxy network.

Over 100 tech giants, including OpenAI, Google, and Microsoft, are sounding the alarm: AI-enabled cyber attacks are about to surge, becoming more widespread and sophisticated, threatening critical public services. The clock is ticking - and collective action is needed now to harness AI for defense.

In a major cybercrime crackdown, the Australian Federal Police has arrested two men in Perth suburbs for their key roles in the notorious TeamPCP syndicate, seizing electronic devices and cryptocurrency-linked evidence. The FBI collaborated on the investigation, which may lead to further arrests and charges.

The balance of power in cybersecurity has been dramatically upset, with AI capabilities now favoring attackers and rendering traditional defenses obsolete in the face of machine-speed attacks. This marks a generational shift, where attackers have the upper hand and organizations must adapt to keep up.

The US Department of Justice has taken a major stand against China's widespread hacking campaign, disabling malicious software and seizing two key hacking platforms, QScan and QTRouter, to protect America's critical infrastructure. This decisive action is a significant blow to state-sponsored hackers preying on the US, with the Attorney General vowing to use every tool at their disposal to keep the American people safe.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Meet QTFY, a notorious Chinese hacker group that's been wreaking havoc on US government and critical infrastructure networks with its custom-built QScan platform, capable of conducting over 2 million scanning and penetration testing tasks in just one day. This sophisticated tool has helped QTFY identify and exploit targets with alarming speed and accuracy.

The FBI has successfully dismantled a global hacking operation linked to China, used to target critical US infrastructure, in a major cyber disruption. This crackdown targeted a China-sponsored hacking group, QTFY, and its operator, Nanjing Xinjiuwei Network Technology Company.

Kudos to the FBI and DOJ for taking down a Chinese cyber espionage proxy network that's been targeting US critical infrastructure - a huge win for national security. This disruption, made possible by Lumen Technologies' Black Lotus Labs' year-long tracking, has crippled the infrastructure used by Chinese hackers to spy on and gather intel from American targets.

In a major win for global security, an international crackdown on cybercrime networks has led to the arrest of 58 individuals and identification of 263 suspects linked to African crime groups. The operation, which ran from November 2025 to June 2026, targeted notorious cybercrime syndicates like Black Axe, known for large-scale financial fraud and romance scams.

A recent cyberattack linked to Iran caused a small UK power plant to shut down, but fortunately, the incident was contained and posed no risk to the broader energy system. The UK government assured that the country's energy infrastructure is highly resilient and that they're working closely with the sector to protect it.

The US government has issued a stark warning: hackers are harnessing the power of artificial intelligence to launch targeted attacks on vulnerable Siemens PLCs, critical infrastructure devices used in water, energy, and manufacturing sectors. This is no hypothetical threat - it's a very real and active danger.

Researchers uncovered a sneaky phishing campaign where attackers abused Notion to steal authentication tokens, using free accounts to impersonate senior executives and send legit-looking document-sharing notifications. This clever tactic was linked to two phishing-as-a-service platforms and over 600 malicious scripts.

Google is sounding the alarm on Russian cyber spies who are using OAuth to carry out highly targeted phishing campaigns against top industries, and is sharing details of the attacks to help people recognize malicious outreach. The tech giant has identified three distinct groups behind the ongoing operations, which have been targeting individuals in Europe and the US since last year.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Meet the sneaky Russian hackers who are hijacking high-value accounts using clever tricks and fake emails to get their hands on sensitive info. They're using Google OAuth and WhatsApp to pull off their phishing scams, and experts warn that no one is safe.

In a stunning example of old-school ingenuity, a team of investigators finally thwarted a sophisticated espionage campaign by doing something remarkably low-tech: cutting a cable to a compromised router in a Chicago data center. This bold move brought an end to months of digital detective work that had been stymied by the elusive threat actors.

Collaboration platforms like Microsoft Teams and Slack have become a prime target for attackers, who are exploiting their trusted status to launch identity abuse attacks through chat phishing operations. These attacks are thriving, with 99% of alerts generated by one study related to chat phishing, signaling a major shift away from traditional email-based attacks.

The feds have issued a dire warning: AI-generated code is being used to actively threaten critical infrastructure controllers, putting industries like water, energy, and manufacturing at risk. This is a very real and present danger, not just a hypothetical threat.

US agencies have sounded the alarm on a growing threat: hackers are using artificial intelligence to launch automated attacks on critical infrastructure, including factories, power plants, and water systems, by targeting Siemens PLCs. This active threat has prompted a joint warning from the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency.

The US Department of Justice has charged 17 Iranians with masterminding a massive, state-sponsored scheme to steal $3.4 billion worth of intellectual property from American universities, businesses, and government institutions. This brazen hacking operation allegedly involved a hacking-for-hire company called Mabna Institute.

The US has ramped up its pursuit of justice against Iranian hackers, expanding an indictment to charge 17 individuals affiliated with the notorious Mabna Institute, which allegedly compromised over 100,000 professors' email accounts worldwide. This move marks a significant escalation in the case, with eight new defendants added to the original 2018 indictment.

Meet Jewelbug, a notorious APT group that's been pulling off a double heist - stealing sensitive info and swindling victims out of crypto - all from the same interconnected operation. Their massive haul includes over 1 million implant check-ins and 580,000 stolen cookies, with targets spanning government systems and service providers across the Middle East, Southeast Asia, and South Asia.