Tag: nation state
994 articles

Cyberattacks Surge 89% as AI Becomes Dual Threat
The threat landscape is evolving at an alarming rate: AI is now being wielded as a powerful tool by cyberattackers, with a staggering 89% surge in AI-enabled attacks. This dual threat - where AI is both the weapon and the target - has adversaries leveraging AI agents at 2.5 times the rate of human-triggered threats.

China Preserves Sovereignty Disputes as Strategic Assets
China has consistently maintained that a decade-old tribunal ruling, which rejected the legal basis for its claims within the nine-dash line, is "null and void" - a stance that has remained unchanged despite ongoing criticism and diplomatic pressure. This unwavering position highlights the strategic value Beijing places on sovereignty disputes.

North Korea's Naval Buildup Complicates Allied Planning in Indo-Pacific
North Korea's rapidly advancing naval capabilities are raising eyebrows among allied planners in the Indo-Pacific, with a focus on complicating and consuming their attention rather than engaging in a traditional blue-water war. At the forefront is the 5,000-tonne Choe Hyon-class destroyer series, unveiled in 2024, touted as a multi-role powerhouse with advanced anti-air, anti-ship, and land-attack capabilities.

US Exposes Hypersonic Edge in Pacific Exercise
The US Air Force made a bold move in the Pacific, kicking off exercise PACIFIC ARCHER on June 17 with a rapid deployment of hypersonic-missile-equipped aircraft to the Second Island Chain, sending a clear message with its show of force.

Red Sea Escort Requests Surge Amid Escalating Houthi Threats
As tensions escalate, commercial vessels are flocking to Operation Aspides for protection, with escort requests surging 39% since February 2026, driven by the growing threat from Houthi attacks in the Red Sea. Rear Admiral Vasileios Gryparis says this increase is a testament to the shipping industry's trust in Aspides as a reliable guardian of safe transit through the High Threat Area.

Trump Misattributes Water Sector Cyberattacks to Minnesota
President Trump sparked confusion by suggesting Minnesota was behind a series of cyberattacks on US water systems, calling the state grossly incompetent. But federal agencies and industry partners have actually attributed the attacks to other culprits - not Minnesota.

Chinese Hacker Exploits DeepSeek AI to Automate Vulnerability Attacks
A Chinese hacker leveraged the DeepSeek AI model to supercharge their vulnerability attacks, using an open-source AI framework to rapidly scan, research, and exploit targets with alarming speed and scale. This alarming automation was achieved through a clever combination of tools, including the Hermes Agent and Telegram.

Chinese Hackers Target Central Asian Governments with OctLurk and SilkLurk Malware
Chinese hackers have launched a stealthy cyberattack on government organizations across six Central Asian countries, infiltrating ministries, hospitals, and schools with sophisticated malware. The targeted countries include Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic.

Hugging Face Breach Exposes Defense Gaps in AI Age
In a shocking revelation, Hugging Face fell victim to a breach that exposed vulnerabilities in AI-powered defenses, with over 17,000 attack events detected across its sandboxes. The incident was linked to a sophisticated attack chain involving OpenAI's models, highlighting the need for stronger security measures in the AI age.

AI-Powered Attacks Target Vulnerable Servers With Autonomous Exploits
Meet the AI-powered attackers who just took autonomous exploitation to the next level - and here's how researchers uncovered their clever tactics. A China-based threat actor's accidental leak exposed a functional, end-to-end AI-driven attack workflow.

CISA Warns of Targeted Cyberattacks on US Water Utilities
CISA is sounding the alarm: if your water utility's programmable logic controllers are exposed to the internet, you're a prime target for cyberattacks - so take action now and remove them from public exposure to safeguard your operations.

Chinese Hackers Leverage DeepSeek for Autonomous Exploits
Meet the sneaky Chinese hackers who've been using an AI-powered tool called DeepSeek to launch autonomous cyber attacks on over 460 targets - and get a glimpse into their clever tactics. With just a single Telegram instruction, DeepSeek can infiltrate and exploit systems all on its own.

AWS Tracks North Korean Group in npm Supply Chain Attacks
AWS has uncovered a string of sneaky supply-chain attacks on popular npm libraries, and their threat intel team is pointing to a notorious North Korean group, known as Saphire Sleet, as the likely culprit. The attacks hit big-name libraries like axios, debug, and chalk, raising concerns about the security of the software supply chain.

Iran Targets Egyptian Mediterranean Port in Drone Strike
Egypt's government has confirmed that a drone strike hit the Mediterranean port of Damietta on July 29, with investigations revealing that the incident involved two vessels, but no one has claimed responsibility yet. The authorities are still working to uncover the full circumstances of the attack.

PLAAF Deploys JL-10 Trainers to South China Sea Patrols
The PLAAF has started deploying JL-10 twin-seat advanced trainers to patrol the waters around Huangyan Island, also known as Scarborough Shoal, in a move that suggests a strategic basing decision rather than a one-off visit. This development reflects a deliberate operational choice, balancing the challenges of island aviation with the need for effective airspace control.

Chinese Threat Actor Exploits AI for Autonomous Cyberattacks
Meet the Chinese threat actor who's taking cyberattacks to the next level with AI - by combining autonomous AI-driven enumeration with manual exploitation to wreak havoc on infrastructure through a arsenal of seven cleverly exploited vulnerabilities. Their cutting-edge toolkit, featuring DeepSeek and Hermes Agent, enables lightning-fast target selection, vulnerability assessment, and decision-making.

Chinese Cyber-Attacks Expose Central Asian Governments to Espionage.
Since January 2025, a sneaky cyber-attack campaign has been targeting government organizations across Central Asia, with victims in six countries, including Afghanistan, Kazakhstan, and Uzbekistan. The attacks, involving customized malware, have hit a wide range of sectors, from healthcare and research to law enforcement and education.

DPRK Hackers Target macOS Users with Crypto-Stealing Malware via Fake Updates
DPRK hackers have launched a sneaky attack on macOS users, using fake update screens to trick them into installing crypto-stealing malware. The clever tactic involves a full-screen fake update that quietly copies an attack command to the clipboard, making it look like the computer is frozen or rebooting.

CISA Issues Guidance on Open-Source Software Security Risks
The Cybersecurity and Infrastructure Security Agency is stepping up to help manage open-source software security risks with a new guidebook titled "Open Source Software: Security Principles and Practices". This move aims to enhance the nation's cybersecurity by providing federal agencies with essential security recommendations.

Azure Flaw Exposes Platform-Wide Key to All Databases
Microsoft patched a vulnerability in Azure Cosmos DB, dubbed CosmosEscape, which exposed a platform-wide key to all databases, but fortunately, no customer data was accessed and no action is required. The flaw was discovered by security firm Wiz, which detailed the exploit chain that could be used to take advantage of the vulnerability.

AI Attacks Expose Enterprise Security Gaps
Nearly a quarter of organizations have been hit with AI-powered attacks, exposing significant security gaps in their defenses. Are your company's critical business platforms protected from the growing threat of artificial intelligence-driven exploitation?

Microsoft Copilot Exposes Hidden Prompts in Word Documents
A security researcher recently uncovered a sneaky vulnerability in Microsoft Copilot that allows hidden instructions to be embedded in Word documents, potentially putting sensitive data at risk. This loophole remains open for exploitation, even after Microsoft deployed partial mitigations.

SilverFox Exploits New Drivers in BYOVD Attacks on Japanese Manufacturer
Meet the sneaky SilverFox hackers who've been exploiting new drivers to launch BYOVD attacks on a Japanese industrial manufacturer, using clever tactics like DLL sideloading and defense evasion to stay one step ahead. Their attack began with a simple yet effective invoice-themed phishing lure, delivered via popular Chinese services QQ and Tencent Cloud.

Hackers Exploit AnySign4PC Flaw via Compromised Korean Sites
Cyber attackers have cleverly exploited a flaw in popular South Korean security software, AnySign4PC, by hijacking legitimate websites to deliver backdoors to unsuspecting users at 72 organizations. The vulnerability, affecting software versions 1.1.4.4 through 1.1.4.6, allows hackers to execute remote code without users even clicking a download prompt.