Skip to main content

Threat Intelligence

Threat actor activity and indicators

People in a high-tech building corridor with a large network display, conveying a sense of urgency.

Five Eyes Agencies Warn of AI-Driven Cyber Threat Escalation

Don't wait - get the basics of cyber resilience right now or face devastating operational and financial crises, warn the intelligence leaders of the Five Eyes nations, as AI-driven cyber threats escalate at an alarming rate. Frontier AI will accelerate threats and change the risk landscape, making it crucial to act urgently.

Analyst 207
Modern conference room with laptop and sleek table overlooking brightly-lit facility.

Intel Agencies Warn of AI-Driven Cybersecurity Overhaul

Get ready for a seismic shift in cybersecurity: AI-driven threats are on the horizon, and intelligence agencies warn that the clock is ticking, with advanced AI models expected to become publicly available within months, not years. The Five Eyes agencies are sounding the alarm, urging a proactive overhaul of cybersecurity defenses to counter the impending storm.

Analyst 207
Person looks concerned while viewing laptop screen in modern office setting.

INTERPOL Warns of Rising Cybercrime in Asia-Pacific

Cybercriminals are wreaking havoc in Asia-Pacific, using cutting-edge tactics like AI and ransomware to scam and steal on a massive scale. Phishing is the region's most costly and widespread crime, with a third of countries reporting over 10,000 cases in just 15 months.

Analyst 207
Formal setting with podium in front of large window, neutral color palette.

Nation-States Drive 75% of UK Critical Infrastructure Cyber-Attacks, NCSC Warns

The UK's National Cyber Security Centre has warned that a staggering 75% of critical infrastructure cyber-attacks in the UK are driven by nation-states, with 200 incidents reported in the past year alone. This alarming trend highlights the growing threat of state-sponsored cybercrime, with countries like Russia, China, and Iran linked to many of these attacks.

Analyst 207
Cluttered room with stacked laptops and equipment, cables visible through laptop screen.

North Korean Hiring Scam Exposed with AI, US Laptop Farms

Meet the ingenious AI-powered sting operation that busted a North Korean hiring scam, exposing a massive laptop farm churning out fake remote IT workers. A suspicious resume sparked the investigation, leading to a shocking discovery of a closet full of machines impersonating candidates for Western companies.

Analyst 207
Government building stands under bright sunlight with a hint of unease.

Google Uncovers China Espionage Group UNC6508 Lurking Undetected Since 2023

Google's Threat Intelligence Group has uncovered a stealthy Chinese espionage group, UNC6508, that had been secretly lurking in networks since 2023, targeting key sectors in the US and Canada. The full extent of the damage is still unknown, leaving experts concerned about potential long-term security breaches.

Analyst 207
Medical staff walk down a hospital corridor with a computer in the background.

China-linked UNC6508 Targets Medical Research Institutions

A sophisticated cyber threat group linked to China, known as UNC6508, has launched a targeted attack on medical research institutions in North America, exploiting vulnerabilities in REDCap servers to gain a foothold. The intrusions, which began in September 2023, aim to compromise sensitive research data.

Analyst 207
Hospital corridor with laptop in foreground, natural light through large windows.

Chinese Spies Exploit Medical, Military Networks for Over a Year

Google's Threat Intelligence Group uncovered a sneaky espionage campaign by Chinese spies that infiltrated medical and military networks in North America for over a year, making off with a treasure trove of sensitive data. The group, tracked as UNC6508, targeted top medical providers, academic centers, and military organizations, leaving no stone unturned in their quest for classified information.

Analyst 207
Dimly lit control room with computer screens and industrial systems hinting at hidden network presence.

Chinese Hackers Maintain Decade-Long Spy Operation in Isolated Network

Chinese hackers pulled off a stunning 10-year cyber-espionage heist, infiltrating a supposedly airtight network and gaining unfettered access to every login, command, and secret. The masterminds behind Operation Highland, linked to the Velvet Ant cluster, expertly embedded their digital fingerprints into the network's authentication process.

Analyst 207
Law enforcement officials stand near a podium with symbolic objects, including a laptop and papers, in a brightly-lit…

FBI dismantles $1.9B China cybercrime network

In a major breakthrough, the FBI, with the help of Google and Lumen Technologies, has dismantled a massive $1.9 billion China-based cybercrime network that impersonated trusted brands to scam hundreds of thousands of victims. This coordinated takedown, part of Operation Riptide, seized key infrastructure and domains used by the group.

Analyst 207
Russian defendant sits in federal courtroom with officer nearby.

Russian national charged in Void Blizzard cyber-espionage scheme

A Russian national, Denis Nikolayevich Obrezko, has been charged with helping facilitate a massive cyber-espionage scheme that infiltrated at least 11 US companies, with authorities suspecting many more victims nationwide. Obrezko allegedly played a key role in the Void Blizzard campaign by buying a virtual private server and registering domain names used in the intrusions.

Analyst 207
Formal government briefing room with podium, American flags, and seals, daylight streaming through tall windows.

FBI Disrupts Chinese Spy Websites Targeting US Security Clearance Holders

The FBI and Justice Department have shut down 13 fake websites pretending to be legitimate consulting firms, targeting US security clearance holders with lucrative job offers that aimed to extract sensitive information for the Chinese government. These seized domains were part of a sophisticated intelligence collection campaign that began in November 2023.

Analyst 207
Smartphone on a plain surface with subtle screen reflection in natural light.

NSO Group Defies Court Order, Continues Targeting WhatsApp Users

Despite a court order blocking it from doing so, NSO Group continues to target WhatsApp users, defying the ruling and putting users at risk. The company is fighting to overturn the order, claiming it will suffer harm if it's forced to comply.

Analyst 207
Satellite dish on a rooftop with subtle radio frequency interference under a clear blue sky.

Russia's Satellite Exposes GPS Vulnerability with Targeted Bursts

Researchers have uncovered a concerning pattern of targeted GPS disruptions, with at least 75 brief outages detected across northern Europe between 2019 and 2026, all triggered by high-powered radio energy bursts. These 10-second jamming events, occurring at a frequency used by GPS and European navigation satellites, coincided with navigation antenna failures from Romania to Greenland.

Analyst 207
Analysts monitor online activity on a large screen displaying a US map with indicators and markers.

OpenAI Exposes Chinese Influence Operation Using ChatGPT

OpenAI has uncovered a sneaky Chinese influence operation that used ChatGPT to spread disinformation, posing as American voices to manipulate online debates. The operation, tracked by OpenAI's threat intelligence team, appears to be a classic case of foreign meddling.

Analyst 207
Radar system installed on a raised platform in a desert landscape under a clear blue sky.

Handala's Israeli Radar Claim Sparks Skepticism

Can a mysterious Iranian-linked hacker group really take down Israel's radar systems? Handala claims it did on the same day Israel and Iran exchanged missile fire, but experts are raising an eyebrow.

Analyst 207
Dimly-lit data center with rows of computer workstations and server racks.

Open Source Faces Hard Fork Amid AI-Fueled Security Crisis

The open source community is facing a daunting security crisis fueled by AI, giving rise to a new category of threat dubbed "Mythos" - a complex chain of low-level issues that can be combined to create devastating attacks. This emerging threat is not just a single bug or false positive, but a game-changing phenomenon that demands immediate attention.

Analyst 207
Employees work at desks with laptops and computers, some with blurred screens, in an office with a cityscape visible…

Verizon DBIR Exposes Growing Browser-Based Threats

Employees are unwittingly putting sensitive data at risk by using AI tools like ChatGPT and Gemini on corporate devices, with 67% accessing these services with personal accounts and 45% using them regularly. This Shadow AI phenomenon is rapidly escalating, with a fourfold year-over-year increase in insider risk.

Analyst 207
Compromised web server in a data center with a focus on the targeted server on a rack.

China-Linked OP-512 Targets IIS Servers with Custom Web Shells

Meet OP-512, a China-linked threat cluster with a taste for espionage, recently caught targeting IIS servers with custom web shells in a stealthy bid for sensitive intel. This sneaky operation aligns with China's intelligence priorities, putting certain sectors and geographies firmly in its crosshairs.

Analyst 207
Concerned person in a brightly-lit office setting with a sense of urgency and accelerated activity.

AI Agents Expose Hidden Risks as Insider Threats Evolve

The alarm bells are ringing: cyberattacks now unfold at breakneck speeds, with malicious actors able to wreak havoc in as little as 10-30 minutes, leaving defenders scrambling to keep up. This accelerated threat landscape is fueled by the growing sophistication of AI agents and their integration into business networks.

Analyst 207
Generic office building with neutral-colored wall and glass façade.

Chinese Cybercrime Group TA4922 Expands Global Reach

Stay vigilant, organizations worldwide: a rapidly evolving Chinese cybercrime group, TA4922, is expanding its global footprint, rewriting the rules for corporate network exploitation and monetization. From East Asia to the UK, Germany, and beyond, this financially driven threat actor is localizing its attacks to hit closer to home.

Analyst 207
A sleek, brightly-lit tech company headquarters with a hint of tension in its modern architecture.

Australia Seeks to Leverage Stability in AI Infrastructure Race

In a concerning escalation, cyberattacks against Israeli targets skyrocketed by 700 percent over just two days following the June 2025 strikes, with Israel accounting for 12.2 percent of all geopolitically motivated cyberattacks worldwide in 2025. This alarming surge highlights the growing threat of cyber warfare in the region.

Analyst 207
Campaign office with computers, phones, and papers on a desk near a window overlooking a blurred cityscape.

Cybersecurity Threats Target Election Campaign Systems

As the 2026 midterms approach, a new report warns that cybersecurity threats are increasingly targeting the online accounts, platforms, and websites used by election campaigns, donors, and voters, rather than voting machines or ballot-counting systems. This shift in focus allows attackers to exploit vulnerabilities and manipulate public perception with alarming ease and realism.

Analyst 207
Modern sports stadium with ticketing booth, broadcast control room, and concourse, set against a blurred city skyline.

World Cup Faces New Cyber Threats in AI-Driven Era

As the World Cup kicks off on June 11, it's not just a sporting spectacle - it's a high-stakes target for cyber threats, with billions of people, devices, and transactions converging online at once. This massive influx creates a perfect storm of vulnerability, exposing ticketing, payments, broadcasts, and infrastructure to unprecedented risk.

Analyst 207