Skip to main content

Threat Intelligence

Threat actor activity and indicators

Workers inspect a shipping container at a busy Gulf port with cargo ships and cranes in the background.

Chinese Hackers Exploit Middle East War to Target Energy, Maritime Firms

Chinese-aligned hackers are intensifying their attacks on maritime and energy companies in the Gulf region, exploiting the Middle East conflict to expand their espionage operations and gain a strategic advantage for Beijing. This alarming surge in cyber threats has been flagged by cybersecurity researchers at ESET.

Analyst 207
Bustling stadium concourse with spectators, staff, and security personnel, and a large video screen in the background.

Cybercriminals, Hacktivists Target 2026 World Cup Infrastructure

The 2026 FIFA World Cup is set to draw massive crowds of up to six million fans across 104 matches in 16 host cities, making its complex infrastructure a prime target for cyber threats. With its far-reaching network of stadium operations, municipal services, and independent suppliers, the tournament's technical architecture is a vulnerable web waiting to be exploited.

Analyst 207
Briefing room with podium, laptops, and notepads, overlooking cityscape through large window.

Iran's Hackers Coordinate Closely with AI-Polished Tactics

There's no truce in the cyber war, with Iran's state-backed hackers now coordinating their attacks like never before, making them more efficient and formidable foes. Israel's defenses have been on high alert since last year's 12-Day War, as Tehran's cyber units exchange intel and collaborate for maximum impact.

Analyst 207
Law enforcement officers seize servers and equipment in a brightly-lit data center.

Dutch Authorities Disrupt Russian Cyber Operations, Seize 800 Servers

In a major blow to Russian cybercrime, Dutch authorities seized over 800 servers and arrested two individuals in a daring raid that cracked down on illicit online operations. The suspects, a 57-year-old Amsterdam resident and a 39-year-old from The Hague, were charged with violating sanctions law by aiding EU-sanctioned entities.

Analyst 207
Law enforcement officers oversee rows of partially disassembled servers in a brightly-lit data center.

Netherlands Disrupts Russian Cyber Operations with Server Seizure

Dutch authorities have struck a major blow against Russian cyber operations, seizing 800 servers and making several arrests in a crackdown on a web hosting ecosystem accused of enabling cyberattacks, disinformation campaigns, and other malicious activities. This coordinated law-enforcement action aims to disrupt the cyber threat landscape and protect democracy and security.

Analyst 207
Brightly-lit server rack in a cloud computing environment with a security monitoring station in the background.

Nation-State Actors Exploit ROADtools in Cloud Attacks

Cloud attackers are now leveraging ROADtools, a publicly available toolkit, to exploit vulnerabilities in cloud tenants, allowing them to persist, discover, and evade defenses with ease. This dual-use framework's ability to speak Entra ID and Microsoft Graph makes it a red flag for defenders to take notice.

Analyst 207
Law enforcement officers in a briefing room with laptops and papers, background shows natural daylight through tall windows.

Europol Disrupts Major Cybercrime VPN Service

Europol's bold operation has taken down a notorious VPN service used by cybercriminals to hide their tracks, seizing key infrastructure and sowing disruption among ransomware operators, fraudsters, and data thieves. This major win for cybersecurity could lead to further investigations and prosecutions, thanks to the treasure trove of data on thousands of threat actors.

Analyst 207
Government building facade with people walking in distance, laptop screen in foreground showing blurred code.

Webworm APT Expands European Reach with Evolved Tactics

Meet Webworm, a China-aligned APT group that's now setting its sights on European governments and beyond, with a semi-opportunistic approach that's taken its targets to Belgium, Italy, Poland, Serbia, Spain, and even South Africa. This threat actor's evolved tactics signal a concerning expansion of its reach.

Analyst 207
Person sitting at desk with concerned expression, staring at blank laptop screen.

Hackers Exploit Human Behavior to Bypass Security Tools

As cyber threats evolve at an alarming rate, hackers are exploiting human behavior to outsmart security tools, forcing organizations to rethink their defensive strategies. With identity abuse and data extortion on the rise, businesses must stay ahead of the game to protect themselves.

Analyst 207
Seized computer equipment on a table in a law enforcement facility.

Interpol Disrupts Cybercrime Ops Across 13 Countries

In a major win against cybercrime, Interpol's Operation Ramz has resulted in 201 arrests, 53 servers seized, and nearly 4,000 victims identified across 13 countries in the Middle East and North Africa. This groundbreaking four-month sweep marks a significant milestone in the fight against online crime.

Analyst 207
Law enforcement officers gather around a conference table with a large MENA map on the wall.

INTERPOL Disrupts MENA Cybercrime Networks with 201 Arrests

In a major crackdown on cybercrime, INTERPOL's Operation Ramz has led to 201 arrests and identified 382 more suspects across 13 countries in the Middle East and North Africa. The operation, which ran from October 2025 to February 2026, dealt a significant blow to malicious cyber networks, also seizing 53 servers and helping 3,867 victims.

Analyst 207
Officials in formal attire gather in a briefing room, signaling a coordinated law enforcement effort.

MENA Region Launches Landmark Cybercrime Crackdown

In a groundbreaking move, the MENA region has launched a historic crackdown on cybercrime, resulting in the arrest of 201 individuals in a multi-month operation hailed as a first-of-its-kind success. This major milestone marks a significant victory in the fight against online crime.

Analyst 207
Officials from various countries gather at Interpol facility for cybercrime disruption announcement.

Interpol Disrupts Cybercrime Networks in MENA Region with 201 Arrests

In a major win against cybercrime, Interpol's Operation Ramz has led to the arrest of 201 individuals and identification of 382 suspects across the Middle East and North Africa. This cross-border crackdown, involving 13 countries, has brought relief to 3,867 victims and dismantled key cybercrime networks.

Analyst 207
Person receiving phone call in office setting with blurred phone screen and computer in background.

Google Exposes BlackFile Extortion Operation's Tactics

Google's Threat Intelligence Group just exposed the clever tactics of the notorious BlackFile extortion operation, revealing how they use voice phishing and sneaky tech tricks to swindle dozens of organizations worldwide. Their clever scheme starts with a simple phone call, where fake IT helpers trick victims into spilling their secrets.

Analyst 207
Gas station attendant checks fuel level on tank gauge screen in dimly lit storage room.

Iran Targets US Gas Stations with Tank Reader Hacks

US gas stations have been targeted by Iranian hackers, who manipulated fuel level readings at vulnerable sites, sparking concerns of a potentially catastrophic cyber attack. The breach highlights the alarming threat of kinetic cyber attacks, with experts warning of the devastating consequences.

Analyst 207
Control room with exposed management panels and industrial equipment on a neutral-colored wall.

Russia Targets Polish Water Utilities in Hybrid Warfare Campaign

Poland's Internal Security Agency has uncovered a concerning trend: five cyber intrusions into water utilities have been linked to a pro-Russian hybrid campaign, part of a broader Kremlin strategy to target NATO's eastern flank.

Analyst 207
Person in business casual outfit working intently at a laptop in a brightly-lit office security area.

Organizations Fortify Defenses Against Evolving Scattered Spider Threats

As Scattered Spider threats evolve, organizations across finance, healthcare, and telecom are bolstering their defenses against sophisticated identity-driven attacks. They're facing an adaptable adversary that's changing tactics, putting pressure on institutions to respond.

Analyst 207
Person working on laptop with concerned expression in Indian office setting.

India Issues Infosec Alert as Mythos Threat Looms

India's securities regulator is sounding the alarm on a looming cybersecurity threat, warning market players to bolster their defenses and get ahead of AI-powered attacks. With the Mythos threat on the horizon, it's crucial to develop new strategies and solidify cyber-basics to stay safe.

Analyst 207
European lawmakers gather around a table, surrounded by screens and technology, with concerned expressions.

European Lawmakers Urge Swift Action on AI-Driven Cybersecurity Threats

European lawmakers are sounding the alarm, warning that Europe is unprepared for the growing threat of AI-driven cybersecurity attacks and urging swift action to defend against them. They've pressed the European Commission for rapid action, citing the alarming capabilities of advanced AI models like Anthropic's Mythos.

Analyst 207
Formal government building exterior with architectural columns and facade details.

China-Linked UAT-8302 Exploits Shared Malware to Target Global Governments

Meet UAT-8302, a sophisticated China-linked threat group that's been secretly targeting governments worldwide, deploying custom malware to infiltrate and gather intel. Its recent attacks have hit government entities in South America and southeastern Europe, raising global cybersecurity concerns.

Analyst 207
Small defense firm office with networking equipment and abstract cyber threat representation.

Nation-State Hackers Target Small Defense Firms' Network Gaps

Small defense firms are leaving themselves exposed to nation-state hackers, who exploited over 14 zero-day vulnerabilities in edge devices like routers and firewalls in 2025 to gain a foothold in the US defense industrial base. These stealthy cyber espionage groups are investing heavily in reconnaissance and pre-positioning operations to infiltrate and linger in their targets' networks.

Analyst 207
Brightly-lit network operations center with multiple workstations and natural light from floor-to-ceiling windows.

Threat Actors Exploit Blind Spots Beyond Endpoint Defenses

Attackers are now moving at an alarming pace, taking data four times faster than in 2025, and exploiting the blind spots that an over-reliance on endpoint defenses creates. They're striking across multiple surfaces, from cloud services to remote users, to evade detection and get in and out quickly.

Analyst 207
Formal hearing room with officials seated at a table, daylight through tall windows, and a podium in the scene.

US Cyber Command Warns of Election Interference Threats

Get ready for a déjà vu: US Cyber Command warns that foreign interference is likely to disrupt the midterm elections, just like we've seen in the past. Army Gen. Joshua Rudd's warning to the Senate Armed Services Committee is a stark reminder that countries like Russia, China, and Iran are actively trying to undermine our democracy.

Analyst 207
Rows of computer servers and networking equipment in a network operations center overlooking a cityscape through a large…

Attackers Target New Assets Within Minutes of Exposure

The moment a new asset goes live with a public IP address, the clock starts ticking - and within minutes, attackers are circling, waiting to pounce on unsuspecting targets. In just 24 hours, a newly exposed asset can go from discovery to compromise, with threat actors exploiting vulnerabilities at an alarming rate.

Analyst 207