Skip to main content

Threat Intelligence

Threat actor activity and indicators

Utility workers stand near rows of battery units and electrical infrastructure at a Texas power grid substation.

Cyberattack on Texas Battery Fleet Threatens Grid Stability

A shocking 92% of battery infrastructure is likely to face a notable cyberattack by 2031, putting millions of lives at risk. Compromising just 1,500 battery units, or 5.4% of Texas' battery fleet, could destabilize the entire grid, impacting 30 million people and causing up to $65 billion in economic damages.

Analyst 207
Traders work around a central console on a dimly lit trading floor with cityscape view.

AI Cyberattacks Threaten Global Financial System Stability

The Financial Stability Board warns that AI-powered cyberattacks could spark a chain reaction of chaos in global markets, exploiting vulnerabilities in sovereign debt, private credit, and asset valuations. This threat is more than just a tech issue - it's a potentially disastrous blow to market confidence.

Analyst 207
Refrigerated case with doors ajar, shelves stocked with food and drinks, digital display blank or out of focus.

DoD Refrigerator Outages Spark Hacking Fears

A defense official has warned of possible refrigeration disruptions at some Defense Commissary Agency commissaries, sparking concerns about the security of military food storage systems. Several bases have already reported outages, including Fort Irwin, F.E. Warren Air Force Base, and Naval Station Newport.

Analyst 207
A typical office interior with cubicles and workers in business attire at desks.

US Disrupts Chinese Cyber Espionage Proxy Network

The FBI has struck a major blow against Chinese cyber espionage, disrupting a proxy network used to sell reconnaissance and operational routing capabilities to malicious actors. This key takedown targeted a technical quartermaster tied to Nanjing Xinjiuwei Network Technology Company, a company linked to the notorious QTYF spy-proxy network.

Analyst 207
Professionals in tech and cybersecurity gather at a headquarters overlooking a cityscape.

Tech Giants Warn of Looming AI-Enabled Cyber Attack Surge

Over 100 tech giants, including OpenAI, Google, and Microsoft, are sounding the alarm: AI-enabled cyber attacks are about to surge, becoming more widespread and sophisticated, threatening critical public services. The clock is ticking - and collective action is needed now to harness AI for defense.

Analyst 207
Police officers surround a handcuffed individual being led away in a suburban setting with police vehicles in the background.

FBI, Australian Police Disrupt TeamPCP Cybercrime Syndicate

In a major cybercrime crackdown, the Australian Federal Police has arrested two men in Perth suburbs for their key roles in the notorious TeamPCP syndicate, seizing electronic devices and cryptocurrency-linked evidence. The FBI collaborated on the investigation, which may lead to further arrests and charges.

Analyst 207
Senior executive looks concerned standing in front of a window with a blurred laptop screen behind.

AI Reshapes Cyber Threat Landscape, Favoring Attackers

The balance of power in cybersecurity has been dramatically upset, with AI capabilities now favoring attackers and rendering traditional defenses obsolete in the face of machine-speed attacks. This marks a generational shift, where attackers have the upper hand and organizations must adapt to keep up.

Analyst 207
Government building with subtle hint of network infrastructure in background.

China Exploits US Infrastructure in Widespread Hacking Campaign

The US Department of Justice has taken a major stand against China's widespread hacking campaign, disabling malicious software and seizing two key hacking platforms, QScan and QTRouter, to protect America's critical infrastructure. This decisive action is a significant blow to state-sponsored hackers preying on the US, with the Attorney General vowing to use every tool at their disposal to keep the American people safe.

Analyst 207
Network operations center with rows of equipment and a single engineer.

FBI Warns of Chinese Hacker Group QTFY's Infrastructure Attacks

Meet QTFY, a notorious Chinese hacker group that's been wreaking havoc on US government and critical infrastructure networks with its custom-built QScan platform, capable of conducting over 2 million scanning and penetration testing tasks in just one day. This sophisticated tool has helped QTFY identify and exploit targets with alarming speed and accuracy.

Analyst 207
Dimly lit server room with rack-mounted equipment and a blurred US map in the background.

FBI Disrupts China-Linked QTFY Hacking Infrastructure

The FBI has successfully dismantled a global hacking operation linked to China, used to target critical US infrastructure, in a major cyber disruption. This crackdown targeted a China-sponsored hacking group, QTFY, and its operator, Nanjing Xinjiuwei Network Technology Company.

Analyst 207
Rows of computer servers and networking equipment under soft ambient lighting in a high-tech laboratory setting.

FBI Disrupts Chinese Espionage Proxy Network

Kudos to the FBI and DOJ for taking down a Chinese cyber espionage proxy network that's been targeting US critical infrastructure - a huge win for national security. This disruption, made possible by Lumen Technologies' Black Lotus Labs' year-long tracking, has crippled the infrastructure used by Chinese hackers to spy on and gather intel from American targets.

Analyst 207
Law enforcement officers from various countries gather around a table in a briefing room with a large map of West Africa on…

Global Crackdown Targets Cybercrime Networks, Arrests 58

In a major win for global security, an international crackdown on cybercrime networks has led to the arrest of 58 individuals and identification of 263 suspects linked to African crime groups. The operation, which ran from November 2025 to June 2026, targeted notorious cybercrime syndicates like Black Axe, known for large-scale financial fraud and romance scams.

Analyst 207
Industrial control room interior with panels, switches, and monitoring equipment.

Iran-linked hackers disrupt UK power plant operations

A recent cyberattack linked to Iran caused a small UK power plant to shut down, but fortunately, the incident was contained and posed no risk to the broader energy system. The UK government assured that the country's energy infrastructure is highly resilient and that they're working closely with the sector to protect it.

Analyst 207
Siemens PLC device mounted on a wall in an industrial control room with a cityscape visible through a window.

US Warns of AI-Powered Attacks on Siemens PLCs

The US government has issued a stark warning: hackers are harnessing the power of artificial intelligence to launch targeted attacks on vulnerable Siemens PLCs, critical infrastructure devices used in water, energy, and manufacturing sectors. This is no hypothetical threat - it's a very real and active danger.

Analyst 207
Blurred laptop and smartphone screens on a quiet office desk, suggesting a secure login page.

Notion Abused to Harvest Authentication Tokens in Targeted Attacks

Researchers uncovered a sneaky phishing campaign where attackers abused Notion to steal authentication tokens, using free accounts to impersonate senior executives and send legit-looking document-sharing notifications. This clever tactic was linked to two phishing-as-a-service platforms and over 600 malicious scripts.

Analyst 207
Person using laptop outdoors in front of government or academic building.

Google Tracks Russian Cyber Spies Abusing OAuth in Targeted Phishing Campaigns

Google is sounding the alarm on Russian cyber spies who are using OAuth to carry out highly targeted phishing campaigns against top industries, and is sharing details of the attacks to help people recognize malicious outreach. The tech giant has identified three distinct groups behind the ongoing operations, which have been targeting individuals in Europe and the US since last year.

Analyst 207
Person sitting at a coffee shop table looks concerned while holding a smartphone, surrounded by blurred cafe patrons and a…

Russian Hackers Exploit Google OAuth, WhatsApp to Hijack High-Value Accounts

Meet the sneaky Russian hackers who are hijacking high-value accounts using clever tricks and fake emails to get their hands on sensitive info. They're using Google OAuth and WhatsApp to pull off their phishing scams, and experts warn that no one is safe.

Analyst 207
Server room with rack-mounted equipment and a single empty rack with a severed Ethernet cable.

Signed Drivers Exposed to Abuse Microsoft Defender Driver Repurposed $10 Million Reward Offered AI Model Exploits Vulnerabilities RCE Flaws Discovered in Gogs, n8n

In a stunning example of old-school ingenuity, a team of investigators finally thwarted a sophisticated espionage campaign by doing something remarkably low-tech: cutting a cable to a compromised router in a Chicago data center. This bold move brought an end to months of digital detective work that had been stymied by the elusive threat actors.

Analyst 207
Employees work at desks in a modern office, one looking concerned and isolated.

Attackers Exploit Trusted Collaboration Platforms for Identity Abuse

Collaboration platforms like Microsoft Teams and Slack have become a prime target for attackers, who are exploiting their trusted status to launch identity abuse attacks through chat phishing operations. These attacks are thriving, with 99% of alerts generated by one study related to chat phishing, signaling a major shift away from traditional email-based attacks.

Analyst 207
Industrial control room with a Siemens S7 Series PLC surrounded by equipment.

Feds Warn of AI-Generated Code Threat to Critical Infrastructure Controllers

The feds have issued a dire warning: AI-generated code is being used to actively threaten critical infrastructure controllers, putting industries like water, energy, and manufacturing at risk. This is a very real and present danger, not just a hypothetical threat.

Analyst 207
Technicians in an industrial control room examine equipment, including a Siemens PLC device on a workbench.

US Agencies Warn of AI-Driven Attacks on Siemens PLCs

US agencies have sounded the alarm on a growing threat: hackers are using artificial intelligence to launch automated attacks on critical infrastructure, including factories, power plants, and water systems, by targeting Siemens PLCs. This active threat has prompted a joint warning from the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency.

Analyst 207
Empty US Department of Justice briefing room with podium and chairs in daylight.

US Charges 17 Iranians in $3.4 Billion Intellectual Property Theft Scheme

The US Department of Justice has charged 17 Iranians with masterminding a massive, state-sponsored scheme to steal $3.4 billion worth of intellectual property from American universities, businesses, and government institutions. This brazen hacking operation allegedly involved a hacking-for-hire company called Mabna Institute.

Analyst 207
Government briefing room with podium, documents, and agency seals in background.

US Recharges Indictment Against Iranian Hackers Tied to Mabna Institute

The US has ramped up its pursuit of justice against Iranian hackers, expanding an indictment to charge 17 individuals affiliated with the notorious Mabna Institute, which allegedly compromised over 100,000 professors' email accounts worldwide. This move marks a significant escalation in the case, with eight new defendants added to the original 2018 indictment.

Analyst 207
Empty server room with rows of equipment racks and monitoring stations.

Jewelbug APT Exploits Dual Agenda with Espionage and Crypto Fraud

Meet Jewelbug, a notorious APT group that's been pulling off a double heist - stealing sensitive info and swindling victims out of crypto - all from the same interconnected operation. Their massive haul includes over 1 million implant check-ins and 580,000 stolen cookies, with targets spanning government systems and service providers across the Middle East, Southeast Asia, and South Asia.

Analyst 207