Skip to main content

Threat Intelligence

Threat actor activity and indicators

Government building exterior with subtle hint of computer infrastructure.

Jewelbug Hacker Group Exposes Dual Threat of Espionage and Crypto Fraud

Meet Jewelbug, a China-based hacker group that's been wreaking havoc with a dual threat of espionage and crypto fraud, leaving a trail of over a million compromised implant check-ins and thousands of stolen credentials in its wake. By cleverly injecting a single malicious script into a shared webmail template, Jewelbug gained write access to sensitive government webmail accounts, making off with valuable data.

Analyst 207
Well-lit office setting with laptop and papers on a neutral-colored desk.

Researchers Expose North Korean IT Hiring Ploy

Security researchers pulled off a clever experiment, creating a fake DeFi startup and hiring three suspected North Korean IT operatives to uncover the tactics used to secretly place foreign workers in companies, and were surprised to find that none exploited their access. The operatives cleared interviews, signed contracts, and were given access to a work virtual machine, but instead of breaching security, they seemed to be gathering intel.

Analyst 207
Security practitioner examines notes and laptop at office desk.

Prompt Injection Tops List of LLM Threats

Despite having relatively few recorded incidents, prompt injection tops the list of LLM threats due to the significant efforts and resources security teams invest in preventing it. This threat's prominence highlights the substantial risk it poses, even if it doesn't always make the public headlines.

Analyst 207
Control room of a water treatment plant with operators and industrial equipment.

Iran Targets US Water Systems in Multi-State Cyberattacks

A recent cyberattack on US water systems, potentially linked to Iran, has sparked a heated debate, with some officials downplaying the incident and shifting blame. Fortunately, it appears that no significant damage was done, but the incident is still under investigation.

Analyst 207
Control room of a water treatment plant with industrial systems and computer workstations.

Iran-linked hackers target US water systems in multi-state cyberattacks

Fortunately, all affected US water systems continued to operate safely, with local operators swiftly addressing issues and resolving them without any public health concerns. Michigan and Georgia confirmed the cyberattacks, joining Minnesota in reporting hostile activity, but officials stress that there were no lasting impacts on public health.

Analyst 207
Modern tech facility with sleek conference table and laptop, hinting at tension.

Cyberattacks Surge 89% as AI Becomes Dual Threat

The threat landscape is evolving at an alarming rate: AI is now being wielded as a powerful tool by cyberattackers, with a staggering 89% surge in AI-enabled attacks. This dual threat - where AI is both the weapon and the target - has adversaries leveraging AI agents at 2.5 times the rate of human-triggered threats.

Analyst 207
Water treatment plant control room with industrial systems and equipment.

CISA Warns of Targeted Cyberattacks on US Water Utilities

CISA is sounding the alarm: if your water utility's programmable logic controllers are exposed to the internet, you're a prime target for cyberattacks - so take action now and remove them from public exposure to safeguard your operations.

Analyst 207
Modern law firm reception area with laptop and smartphone on desk.

AiTM Phishing Overtakes Credential Theft as Top Law Firm Threat

Law firms are under siege from a new type of phishing attack, with AiTM phishing now accounting for 28.57% of initial access events in the sector, overtaking conventional credential theft as the top threat. This sophisticated attack method has become the go-to tactic for hackers, bypassing even multifactor authentication defenses.

Analyst 207
Telecommunications equipment array on a cell tower against a daytime sky.

US Military Left Vulnerable to Telecom Attacks

The US military's vulnerability to telecom attacks has been exposed, with numerous successful breaches resulting in stolen location data, intercepted communications, and even manipulation of American voters through text messages. This alarming threat isn't caused by a new malware strain, but rather a decades-old signaling system that underpins global telephony and has been left open to exploitation.

Analyst 207
Municipal water treatment plant exterior with industrial infrastructure.

Iran-linked CyberAv3ngers targets US water systems

A coordinated cyberattack recently hit over 30 community water systems in Minnesota, prompting a swift response from state officials to ensure public health and safety. The Minnesota Department of Health is working closely with affected facilities to mitigate the impact and prevent any disruptions to drinking water supplies.

Analyst 207
Formal government briefing room with podium, empty chairs, and laptop on a table near a window.

FBI Warns of AI-Powered Vulnerability Exploits

The FBI is sounding the alarm on a new threat: AI-powered vulnerability exploits that can target the very foundation of our digital infrastructure, including operating systems, security, web infrastructure, and encryption. This emerging threat has the potential to revolutionize the way law enforcement approaches cybersecurity.

Analyst 207
Law enforcement office with computer screen and blurred emblem on wall.

Europol Disrupts The Com's Online Ecosystem with 4,340 URL Takedowns

In a major crackdown, Europol and its partners have taken down 4,340 URLs linked to The Com, a notorious online network accused of radicalizing young people and facilitating illicit activity. This coordinated effort is part of a broader mission to protect vulnerable youth and disrupt the online ecosystem of recruiters and extortionists.

Analyst 207
Government officials gather at a podium in a briefing room with an agency emblem in the background.

US Targets Overseas Cybercrooks with Visa Cancellations

The US is cracking down on overseas cybercrooks by cancelling their visas, a move aimed at curbing the $10 billion+ in scams that defraud American citizens every year. This targeted approach will deny visas to foreign nationals involved in cybercrime, including those behind investment scams and sextortion schemes that prey on vulnerable victims.

Analyst 207
Critical infrastructure site with private 5G network equipment and industrial machinery.

Government Urged to Harden Private 5G Networks Against China-Backed Threats

Imagine having an invisible backdoor to your most sensitive information - that's what happened when China-backed hackers infiltrated private 5G networks, leaving no limits to what they could access or manipulate. Government agencies and cybersecurity experts warn that these threats, known as Salt Typhoon and Volt Typhoon, have been targeting US networks for years.

Analyst 207
Brightly-lit industrial control room with various control systems and equipment in the background, hinting at network…

Iranian Hackers Expand Target Scope in US Industrial Control Systems

US cybersecurity authorities have issued a critical warning: Iranian hackers are now targeting a wider range of industrial control systems, including those from Schneider Electric and Siemens, beyond their previously known focus on Rockwell Automation/Allen-Bradley devices. This expanded threat alert urges companies to bolster their defenses against increasingly aggressive and opportunistic cyber attacks.

Analyst 207
Industrial control room with programmable logic controller on workbench surrounded by equipment.

CISA Warns of Iranian Hackers Targeting Industrial Control Systems

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about Iranian hackers targeting Industrial Control Systems, specifically programmable logic controllers (PLCs) used in critical infrastructure organizations. This alert comes after the FBI observed malicious activity, including data manipulation and operational disruption, at a US-based facility.

Analyst 207
Brightly-lit city transit platform with a sense of unease, hinting at vulnerability to evolving threats.

Network Defenses Must Evolve to Counter AI-Equipped Threats

The alarming reality is that 79% of attacks now occur without malware, forcing defenders to rethink their strategies and respond faster than ever. Traditional defenses are being outsmarted by clever tactics like credential theft and DLL side-loading, leaving organizations vulnerable to rapid breaches.

Analyst 207
Rows of computer equipment in a dimly lit server room lie in disarray, cables scattered and screens flickering with error…

AI Emerges as Force Multiplier in Cyberattacks

As AI continues to evolve, it's crucial to treat AI-driven threats as a top priority, as they can significantly accelerate and scale attacks. By leveraging AI, cyber attackers can speed up their operations, but their tactics remain familiar, including credential theft, phishing, and ransomware.

Analyst 207
Government building with tall windows and daylight streaming in, abstract agents in background.

US Indicts Russians for Running Bulletproof Hosting Services

The FBI has struck a major blow against cybercrime by indicting three Russian nationals and two companies for operating bulletproof hosting services that enabled devastating attacks on US critical infrastructure. This significant move disrupts the backbone of cybercriminal operations, dealing a crucial win for online safety.

Analyst 207
Modern tech lab with people working, sleek workstation and laptop in foreground.

AI Empowers Cyberattacks with Operational Efficiency

As AI continues to evolve, it's crucial to treat AI-driven threats as a top priority, using the technology to supercharge their attacks and compress timelines. AI is being used by attackers to automate routine work, streamline reconnaissance, and shorten development cycles, turning what once took days into operations that can be executed in just hours.

Analyst 207
Formal facade of a British court building with a government emblem.

UK Prison Sentences Target Scattered Spider Cyber Duo

In a landmark case, two young cybercriminals, Owen Flowers and Thalha Jubair, have been sentenced to five years and six months in prison for their roles in a massive cybercrime operation that targeted Transport for London. The case marks the largest cybercrime prosecution ever brought before UK courts.

Analyst 207
Person in professional attire sits at desk in government agency setting with computer and phone in background.

Telegram Disrupts Links Tied to Sanctioned VPN Service

Telegram swiftly disabled links connected to a sanctioned VPN service after the US Office of Foreign Assets Control took action, demonstrating its commitment to compliance with international regulations. The move came after Domain.Me, the operator of Telegram's t.me shortlinks, identified and suspended the linked domain for approximately a day.

Analyst 207
Federal courthouse interior with subtle law enforcement presence.

US Charges Russian Nationals for Bulletproof Hosting Services

US authorities have charged three Russian nationals with operating illicit bulletproof hosting services that enabled cybercrime, affecting victims across 21 states, including banks, schools, hospitals, and media companies. The accused, Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin, allegedly facilitated a range of malicious activities through their services.

Analyst 207
Large data center with rows of servers and racks, hinting at security vulnerability.

OAuth Client ID Spoofing Enables Credential Validation in Microsoft Entra ID Attacks

Researchers have uncovered a sneaky way attackers exploit a blind spot in Microsoft Entra ID's cloud sign-in telemetry, using OAuth Client ID spoofing to validate stolen credentials without triggering a successful sign-in event. By submitting fake client IDs, hackers can cleverly probe accounts and verify login details.

Analyst 207