Tag: nation state
994 articles
Pakistan Builds Integrated Counter-Drone System
Pakistan is upgrading its defense strategy with an integrated counter-drone system, combining cutting-edge radar technology and locally produced ammunition to tackle the growing threat of unmanned aerial systems. This crucial upgrade aims to transform a patchwork of localized defenses into a robust, connected system capable of handling even the most sophisticated drone attacks.

Skyfall Unveils High-Speed Drone Interceptor to Counter Russian Shaheds
Meet the P1-SUN Jetkiller, a high-speed drone interceptor designed in just three months to counter Russian Shaheds, a threat that's being used to replace long-range artillery. This game-changing tech has already been battle-tested, taking down dozens of targets with impressive results.

Malware Targets AI Tools in Software Development Environments
A new wave of malware is targeting the very tools developers rely on to build and deploy software, with a recently discovered worm, Sandworm_Mode, capable of stealing sensitive credentials and accessing critical systems. This emerging threat could compromise the entire AI development stack, from AI assistants to cloud providers and API keys.

Ransomware Risk Amplified by Enterprise GenAI Deployments
With enterprise GenAI deployments on the rise, the ransomware risk is skyrocketing - after all, Microsoft alone detects over 38 million identity risk signals daily, a stark reminder that AI-enabled attacks can strike at any moment. As attackers supercharge their ops with AI, businesses are unwittingly increasing their vulnerability by deploying AI systems that can be exploited.

Ransomware gangs exploit victims' payments, extort again
Paying ransomware attackers doesn't always guarantee relief, with many victims being extorted again. A recent survey found 54% of organizations globally paid a ransom, yet it often doesn't end the attack.

Law Enforcement Disrupts Kratos Phishing Kit Targeting Microsoft 365 Sessions
In a major win for cybersecurity, law enforcement agencies have dismantled the notorious Kratos Phishing Kit, pulling over 200 servers offline and disrupting thousands of phishing campaigns targeting Microsoft 365 sessions. The operation, coordinated with Indonesian authorities, is estimated to have impacted around 1,800 paying customers who were using Kratos to run approximately 15,000 phishing campaigns monthly.

US Spies Warn Congress of China's AI Tech Heist
US intelligence agencies are on high alert, warning Congress that China's relentless pursuit of cutting-edge AI technology poses a significant threat to national security. The country's intelligence community is playing catch-up, lagging behind foreign efforts to acquire advanced AI tech.

UAE's EDGE Group Consolidates Defence Supply Chain Through Strategic Acquisitions
EDGE Group is revolutionizing its defence supply chain through a bold strategy of 13 international acquisitions, 23 joint ventures, and a game-changing ownership approach that prioritizes control over location. By acquiring key players and integrating their outputs, EDGE is poised to dominate the industry with a unique model that sets it apart from the rest.

JADEPUFFER Evolves to Target AI Models with Ransomware
JADEPUFFER's latest move is a game-changer: they're now using ransomware to destroy AI models, leaving encrypted artifacts irretrievable. This devastating attack can cost victims up to $500,000 or more in training and computing losses.

Authorities Disrupt Kratos Phishing Platform in Global Operation
In a major global crackdown, authorities have shut down Kratos, a notorious phishing-as-a-service platform that helped cybercriminals create fake Microsoft login pages to steal sensitive info. The takedown has disrupted a key tool used by over 1,800 customers to commit crimes like business email compromise and data theft.

FakeGit Campaign Exploits GitHub Repos to Spread SmartLoader Malware
Malicious actors have unleashed a massive campaign, using 7,600 fake GitHub repositories to spread the notorious SmartLoader malware, tricking victims into downloading malicious files disguised as popular tools like Gmail and Docker. The operation's convincing fake artifacts and manipulated repository metrics made it a highly effective and long-running threat.

North Korea's IT worker scheme fuels Russia's war effort
A shocking new report reveals that North Korea's IT worker scheme is secretly fueling Russia's war effort, with funds routed through a complex network to support multiple state objectives. The surprising twist: it's not just about North Korea's own weapons program, but also about arming Russia's military.

Zero Trust Bolsters Critical Infrastructure Against Identity Threats
A single compromised account, like the inactive VPN login used to breach Colonial Pipeline in 2021, can have devastating ripple effects - just imagine a national crisis triggered by a simple vulnerability. The Colonial Pipeline ransomware attack is a stark reminder of the catastrophic consequences that can unfold when critical infrastructure is compromised.

North Korean Hackers Expose Web3 Pros to Sophisticated ClickFake Scams
One in three employees have admitted to using company tech for personal gain, and North Korean hackers are exploiting this vulnerability with a clever recruitment scam that can give them access to corporate funds. The sophisticated scheme, attributed to the notorious Famous Chollima group, targets Web3 and cryptocurrency pros with fake job offers on popular platforms like LinkedIn and Telegram.

SonicWall VPN flaws exploited to install custom malware
A threat actor known as UTA0533 has been exploiting two zero-day vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances to install custom malware, starting as early as June 22, 2026. This attack uses a critical server-side request forgery and a high-severity command injection vulnerability to gain unauthorized access.

AI Models Expose Gaps in US Cyber Defense Strategy
The pressing question is no longer if cybersecurity matters, but how we'll manage AI-driven risks before they overwhelm our defenses - and who will lead the charge. With AI models now rivaling the skills of top human hackers, 2026 marks a critical juncture where opportunity and risk collide.

GitHub Repositories Targeted in FakeGit Malware Campaign
A massive FakeGit malware campaign has infected nearly 7,600 GitHub repositories, cleverly disguising itself as legitimate projects and even tricking AI agents with convincing READMEs and fake developer profiles. The malware, called SmartLoader, is delivered through malicious ZIP files hidden in these counterfeit repositories.

Malware Hides in Microsoft 365 Calendars via HOLLOWGRAPH Campaign
Meet HOLLOWGRAPH, a sneaky malware that's hiding in plain sight - using Microsoft 365 calendars to pull off a highly targeted espionage threat. This compact implant is reading and writing secret messages, all while masquerading as a harmless calendar event.

Russian Hackers Exploit IP Cameras to Spy on NATO, Ukraine Military Logistics
Russian hackers are exploiting internet-connected security cameras to spy on NATO and Ukraine's military logistics, with over 87,000 cameras across the EU and Ukraine vulnerable to a known exploit. This alarming operation, revealed by Dutch intelligence, has left sensitive sites exposed to Russian surveillance.

Russian Hacker Exploits Google AI to Control Botnet
A solo Russian hacker, going by the name "bandcampro", cleverly exploited Google's AI tool to build a sneaky botnet operation that was incredibly lightweight, consisting of just three plaintext files totaling 5 KB. This made it easy to replicate and dispose of, allowing the hacker to stay one step ahead.

UK Police Chiefs Push for Cybercrime Risk Orders After TfL Hack
The UK's National Crime Agency has hailed a major cybercrime case as its most complex investigation to date, after two men were jailed for their role in the massive TfL hack, and is now calling for new powers to tackle the growing threat of cybercrime. The case has sparked renewed demands for Cybercrime Risk Orders to help manage and mitigate cyber risk.

RubyGems Packages Targeted in SleeperGem Supply Chain Attack
Researchers have uncovered a sneaky supply chain attack, dubbed SleeperGem, that uses malicious RubyGems packages to infiltrate developer machines and download additional payloads. The attack relies on three rogue packages, each acting as a loader to fetch a second-stage payload.

SonicWall SMA Zero-Days Exploited to Gain Root Access
A newly identified threat actor, UTA0533, has been caught exploiting zero-day vulnerabilities in SonicWall SMA VPN appliances to gain root access, using custom malware and other sophisticated tactics. This alarming attack was uncovered during an incident response in July, with two compromised appliances detected in a single environment.

Russian Hackers Exploit ClickFix CAPTCHAs to Spread Malware in Ukraine
Ukraine's Computer Emergency Response Team (CERT-UA) warns that Russian hackers, part of the notorious Sandworm group, are using manipulated CAPTCHAs to trick victims into downloading malware, specifically targeting Ukraine with data-stealing attacks. They've been linked to a series of social engineering scams that spread malware through legitimate websites.