Skip to main content

Threat Intelligence

Threat actor activity and indicators

INTERPOL Stunning Crackdown: 574 Arrested in Africa, Guilty

INTERPOL Stunning Crackdown: 574 Arrested in Africa, Guilty

INTERPOLs month‑long Operation Sentinel arrested 574 suspects across 19 African countries and recovered roughly $3 million — a major strike against business email compromise and digital extortion, but a reminder that arrests must be paired with legal, financial and technical reforms to truly stop these agile cyber gangs.

Analyst 207
State-Sponsored Cyber Attacks: Exclusive Critical Threat

State-Sponsored Cyber Attacks: Exclusive Critical Threat

State-sponsored cyber attacks are escalating — learn how nation-backed hackers target organizations and practical steps you can take to stay one step ahead.

Analyst 207
Bloody Wolf Expands in Central Asia Exclusive Danger

Bloody Wolf Expands in Central Asia Exclusive Danger

As Bloody Wolf expands across Central Asia, attackers are repurposing trusted remote‑administration tools to slip quietly into government networks and exfiltrate sensitive data. That shift from noisy attacks to stealthy intelligence gathering leaves smaller states scrambling to detect and respond.

Analyst 207
Rewiring Democracy Exclusive: Best Paths for Reform

Rewiring Democracy Exclusive: Best Paths for Reform

Rewiring Democracy asks: as AI rewrites our political infrastructure, who will teach the machines to learn — and safeguard — our democratic values? This urgent, clear-eyed book maps the reforms we need before algorithms reshape civic life.

Analyst 207
US: Exclusive Five Plead Guilty in Damaging NK IT Fraud

US: Exclusive Five Plead Guilty in Damaging NK IT Fraud

Five people in the U.S. pleaded guilty this year to helping North Korean hackers secure remote IT jobs with American companies — a wake-up call that remote hiring can be manipulated to mask origins, launder pay, and funnel talent and cash back to Pyongyang.

Analyst 207
Google Forecasts Stunning 2026 EU Cyber-Physical Threats

Google Forecasts Stunning 2026 EU Cyber-Physical Threats

Google warns Europe is likely to face a surge of cyber-physical attacks in 2026 — digital intrusions paired with disinformation that could disrupt power, transport and industry. With legacy control systems, rushed digitization and weak third-party security widening the attack surface, now’s the time to shore up defenses.

Analyst 207
Security Leaders: Exclusive, Alarming Threat Evolution

Security Leaders: Exclusive, Alarming Threat Evolution

Security leaders face an urgent choice: overhaul defenses now or accept a rising tide of risk. Threat evolution has accelerated — commodified crimeware, AI-driven automation and sprawling attack surfaces mean attackers are moving faster than most organizations can respond.

Analyst 207
60% of Security Leaders: Stunning, Critical Threat Shift

60% of Security Leaders: Stunning, Critical Threat Shift

Sixty percent of security leaders warn that threat actors are evolving too quickly for organizations to keep up. Commodified cybercrime, automation and an expanding attack surface are squeezing defenders’ time to detect, respond and contain — and the consequences are real.

Analyst 207
Pakistani-Linked Hacker Group: Exclusive Threat to India

Pakistani-Linked Hacker Group: Exclusive Threat to India

Pakistan-linked operators are quietly slipping DeskRAT into Indian government networks to siphon secrets — a stealthy espionage campaign that makes stronger detection, logging and diplomatic response urgent.

Analyst 207
Lazarus Group Exclusive: Critical Threat to Europe’s Defense

Lazarus Group Exclusive: Critical Threat to Europe’s Defense

Who’s stealing Europe’s drone blueprints — and why? Investigators now point to North Korea’s Lazarus Group and Operation DreamJob, a stealthy campaign targeting small defense firms to grab design files, accelerate domestic drone programs, and probe weaknesses in Europe’s nascent “drone wall.”

Analyst 207
Lazarus Group Exclusive: Dire Threat to European Defense

Lazarus Group Exclusive: Dire Threat to European Defense

Who watches the watchers? Researchers say North Korea’s Lazarus Group—behind Operation “DreamJob”—has quietly infiltrated European drone and counter‑UAS R&D to steal designs, credentials and test data, putting the continent’s push for a layered “drone wall” at real risk of espionage, sabotage and costly setbacks.

Analyst 207
Lazarus Group Exclusive: DreamJob Threatens EU Defenses

Lazarus Group Exclusive: DreamJob Threatens EU Defenses

“If you build it, they will steal it” — North Korea’s Lazarus Group is quietly targeting EU drone engineers, lifting schematics, firmware, and supplier data to speed or sabotage adversaries’ emulation of Western platforms. The result: stolen designs and corrupted files that can derail production and readiness without a single shot fired.

Analyst 207
Iran-Linked MuddyWater Exclusive Dangerous Global Espionage

Iran-Linked MuddyWater Exclusive Dangerous Global Espionage

Iran-Linked MuddyWater is executing a dangerous, far-reaching espionage campaign — find out how this covert groups tactics put organizations worldwide at risk and what steps you can take to defend against them.

Analyst 207
60% of Security Leaders Warn of Rapid Threat Evolution

60% of Security Leaders Warn of Rapid Threat Evolution

Sixty percent of security leaders say attackers are evolving faster than defenses — a wake‑up call as crime gets industrialized into automated, turnkey attacks that prey on cloud, supply‑chain and IoT gaps. The upshot: rising costs, eroding trust and a simple choice for organizations — act now to close the gap or accept escalating risk.

Analyst 207
National Time Service Center: Exclusive Risky Attack

National Time Service Center: Exclusive Risky Attack

China’s MSS claims the NSA used 42 cyber tools to tamper with the National Time Service Center—a charge that, if true, would turn the country’s clocks into a powerful tool for disrupting finance, telecoms and critical infrastructure. Dramatic as the allegation is, the lack of a public forensic dossier leaves the claim hanging between serious threat and strategic rhetoric.

Analyst 207
AI and governance: Stunning Risks and Best Fixes

AI and governance: Stunning Risks and Best Fixes

Think politics is messy now? Bruce Schneier warns AI will rewrite the rules — promising smarter governance and wider participation while risking manipulation, bias, and concentrated power, and his new book kickstarts a crucial debate about whether these tools will strengthen or unravel democracy.

Analyst 207
Russian-affiliated hacker group: Shocking Espionage Risk

Russian-affiliated hacker group: Shocking Espionage Risk

When does teenage curiosity cross into state espionage? A small Dutch town is grappling with that question after prosecutors say three teens — one allegedly linked to a Russian-affiliated hacker group — may have helped a foreign intelligence service, raising tricky legal and ethical questions about intent, culpability and how to guide tech-savvy youth.

Analyst 207
100 trillion signals: Stunning Risk, Best Defense

100 trillion signals: Stunning Risk, Best Defense

Microsoft says its systems process over 100 trillion signals every day to spot threats — but AI-powered attackers are getting faster and craftier, so sheer volume alone won’t keep us safe. That reality means defenders must pair massive telemetry with smarter correlation, stronger identity protections and clearer policies to stay ahead.

Analyst 207
threat hunting: Must-Have Best Defense Against Attacks

threat hunting: Must-Have Best Defense Against Attacks

Posters and training are a great start, but real readiness comes from proactive threat hunting that finds attackers hiding in your systems before alerts do. Pairing strong user awareness with telemetry-driven, human-led hunts shortens dwell time and turns everyday vigilance into lasting defense.

Analyst 207
nationally significant cyber incidents: Stunning Dire Wave

nationally significant cyber incidents: Stunning Dire Wave

The UK’s NCSC recorded a record 204 nationally significant cyber incidents — a staggering 130% jump — forcing a wake-up call about who gets hurt, what counts as “nationally significant,” and whether our defenses can hold against the next wave.

Analyst 207
Scattered Lapsus$ Hunters: Exclusive Risky Hiatus

Scattered Lapsus$ Hunters: Exclusive Risky Hiatus

After the FBI seized their site, teenage collective Scattered Lapsus$ Hunters vowed to go dark until 2026 — a defiant restart in a familiar retire-regroup-return cycle. Whether they stick to it or not, defenders should treat the pause as a chance to patch vulnerabilities, rotate credentials and strengthen defenses.

Analyst 207
Ministry of State Security: Exclusive Risky Ties Exposed

Ministry of State Security: Exclusive Risky Ties Exposed

A new open‑source assessment links the Beijing Institute of Electronics Technology and Application (BIETA) — and a related group called CIII — to China’s Ministry of State Security, raising unsettling questions about where civilian research ends and state cyber operations begin. For technologists and policymakers, the report is a wake‑up call to rethink supply‑chain risk, threat attribution, and how to protect innovation without choking off legitimate collaboration.

Analyst 207
Lone horse stands on cracked asphalt road under distant streetlight, with crumbling cityscape and full moon in background.

Cavalry Werewolf Exclusive: Dangerous State-Grade Threat

BI.ZONE’s new report exposes Cavalry Werewolf, a stealthy campaign that pairs the FoalShell backdoor with StallionRAT to quietly map and then exploit Russian public-sector networks—an urgent reminder that reusable, modular tooling lets attackers scale persistent intrusions. Defenders should prioritize centralized telemetry, network segmentation, MFA and practiced playbooks to spot the subtle reconnaissance before it escalates.

Analyst 207
foreign interference: Exclusive Risky Teen Scandal

foreign interference: Exclusive Risky Teen Scandal

When Dutch authorities arrested several teenagers allegedly linked to foreign interference, it exposed a modern dilemma: how do we protect democracy from digital meddling without criminalizing curious, tech‑savvy kids?

Analyst 207