
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it alongThreat actor activity and indicators

A recent investigation by TrendAI has uncovered a concerning China-linked espionage campaign, with a novel spy group infiltrating over a dozen critical networks across Poland and Asia, leaving behind a lingering threat that's experts' biggest worry. The threat group, tracked as Shadow-Earth-053, has been actively compromising networks since December 2024.

A 19-year-old hacker, known online as "Bouquet," has been arrested in Finland and charged in the US with extortion and cyber intrusion as a key player in the notorious Scattered Spider hacking collective. The dual US and Estonian citizen was caught at Helsinki airport while trying to flee to Japan.

Cybercrime players are now treating operational security as a sophisticated game-changer, and it's time for you to level up your security strategy beyond just using VPNs. A battle-tested three-tier infrastructure model has emerged, separating exposure, execution, and monetization to safeguard high-stakes operations.

In a major breakthrough, 34-year-old Chinese national Xu Zewei has been extradited to the US to face charges for his alleged role in the massive Silk Typhoon cyber attacks that hit over 12,700 US organizations. Xu appeared in a Houston federal court over the weekend, facing serious charges including wire fraud, unauthorized computer access, and identity theft.

A Chinese national, Xu Zewei, has been extradited to the US from Italy to face charges for his alleged role in the notorious HAFNIUM cyber attacks, a vast intrusion campaign that compromised over 12,700 US organizations. Xu's arrival in US court marks a significant step in holding him accountable for his actions.

The US Department of Justice has extradited Chinese national Xu Zewei from Italy to face charges of conducting cyberespionage operations on behalf of China's intelligence services, targeting victims including COVID-19 researchers. Xu's alleged hacking activities, directed by China's Ministry of State Security, spanned over a year, from February 2020 to June 2021.

The threat group TGR-STA-1030 is ramping up its espionage efforts in Central and South America, with sustained and widespread activity observed across multiple countries since February. This persistent campaign has recently intensified, with a heavy focus on regions within Central and South America.

The US government has sounded the alarm on a critical threat: foreign adversaries are launching coordinated, large-scale campaigns to steal American AI capabilities, specifically targeting the distillation of advanced US AI models into smaller, lighter-weight versions. To combat this, the White House is directing federal agencies to collaborate with the private sector to develop best practices for protection.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
China-nexus cyber actors have dramatically changed their game, ditching solo operations for massive networks of hacked devices - and it's a threat you need to know about. A joint advisory from top cyber agencies worldwide warns of this new tactic, urging vigilance in the face of large-scale cyber attacks.

Be on high alert: China-linked hackers are secretly building global covert networks using compromised routers and devices, putting anyone who's a target at risk of devastating cyber attacks and data theft. This sinister plot, revealed by a joint advisory from 16 government agencies worldwide, has far-reaching implications for organizations and individuals alike.

The UK's National Cyber Security Centre has warned that Chinese hacking groups are using a sophisticated network of proxies to evade detection, with multiple covert networks constantly being updated and used by multiple threat actors. This alarming shift in tactics has prompted a coordinated warning from the NCSC-UK and nine international partners.

ESET researchers have uncovered a treasure trove of clues, analyzing 6,044 Slack messages and 3,005 Discord messages that reveal the covert operations of a China-linked APT group, dubbed GopherWhisper, which has been active since at least 2023. The recovered logs provide a rare glimpse into the group's tactics, thanks to hardcoded credentials in Go-based backdoors that gave investigators access to the group's command and control channels.

In today's hyper-fast cyber threat landscape, operating at machine speed is no longer a choice - it's a necessity, as expert Tom Kellermann warns, highlighting the urgent need for advanced threat intelligence to combat AI-driven attacks.

The old security measures are no longer enough - a 'passed' audit only tells you where you've been, not where you are now, in a threat landscape rapidly changed by AI-driven attacks. Advanced AI tools can now discover and exploit weaknesses at unprecedented speeds and scales, outpacing traditional security methods.

Meet ProxySmart, a sneaky software powering "SIM Farm as a Service" operations worldwide, with a massive footprint of 94 phone farms across 17 countries and 19 US states. Its creators, a Belarus-based vendor, have made it easy for operators to run mobile proxy infrastructure at commercial scale.

Meet Tyler Robert Buchanan, the 24-year-old mastermind behind the notorious Scattered Spider cybercrime gang, who has pleaded guilty to federal charges of conspiracy and identity theft. With a potential 22-year prison sentence looming, Buchanan's guilty plea marks a major win for law enforcement in the fight against cybercrime.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
As the modern workplace becomes increasingly decentralized, organizations face a daunting challenge: protecting their dispersed workforce from sophisticated threats powered by artificial intelligence. Fresh thinking is needed to secure hybrid work environments from these emerging AI-driven threats.

Microsoft is sounding the alarm on a growing threat: hackers are exploiting Microsoft Teams' external collaboration features to impersonate helpdesk teams and gain access to enterprise networks. They're using the platform's own tools to move undetected, posing a major challenge for defenders.

Pro-Iran hackers are stepping up their game, targeting US infrastructure with increasing frequency, as seen in the recent breach of the Los Angeles Metro. The federal government is sounding the alarm, warning that critical systems remain vulnerable to these escalating cyberattacks.

Iran's cyber threat landscape is escalating, with phishing, hacktivist operations, and criminal activity converging to create a complex risk picture. A recent Unit 42 threat brief offers valuable insights and practical guidance to help defenders stay ahead of these emerging threats.

Imagine a network of seemingly ordinary remote workers secretly infiltrating over 100 companies - only to discover they were all part of a massive scam run by North Korea. Two Americans have been jailed for helping the rogue nation pull off this daring cyber deception.

Feeling overwhelmed by the endless stream of cybersecurity threats? Every Thursday morning, you're faced with a daunting question: how to stay informed without getting bogged down by a never-ending parade of old and new threats.

New intelligence suggests a pro-Iranian operative is behind the L.A. Metro cyberattack, shifting the focus from the disruption caused to the motivations and strategic intentions of the attacker. This development elevates the incident from a local service outage to a complex geopolitical issue.

As a new AI tool, Claude Mythos, raises red flags with its potential to aid hacking, US and UK cyber leaders are scrambling to contain the threat and reassess their cybersecurity strategies. This emerging concern marks a new front in AI and cybersecurity, where commercially available models are now viewed as a potential operational risk.