Skip to main content

Tag: nation state

998 articles

Laptop screen displays Microsoft Teams call on a home office desk with a phone and headset nearby.

Microsoft Teams Abused to Deploy EtherRAT Malware via Fake IT Support Calls

Beware of fake IT support calls on Microsoft Teams - hackers are using convincing tactics, including a phishing email with a malicious PDF, to trick victims into downloading the potent EtherRAT malware. They impersonate system administrators to gain your trust, making it crucial to stay vigilant.

Analyst 207
Modern Israeli government or IT office lobby with people walking in background.

Iran-Linked Hackers Deploy Cavern C2 Framework to Target Israeli Organizations

Iran-linked hackers have launched a sophisticated cyber attack campaign, dubbed Cavern Manticore, targeting Israeli organizations, particularly in the IT and government sectors, using a cutting-edge .NET-based framework. This threat cluster is affiliated with Iran's Ministry of Intelligence and Security, and its tactics overlap with other notorious groups like MuddyWater and Lyceum.

Analyst 207
Marketing professional looks concerned, holding smartphone amidst papers and laptop.

Phishing Campaign Targets Google Accounts with Fake Job Interviews

Beware of fake job interviews that could be phishing scams! A clever new campaign is targeting marketing pros with emails that appear to be from recruiters, aiming to trick them into handing over their Google account credentials.

Analyst 207
Government building in Tel Aviv with people walking nearby, hint of cyber threat in background.

Iran-Linked Cavern Manticore Targets Israel with Modular Cyber Attacks

Meet Cavern Manticore, a highly skilled and disciplined cyber threat group with ties to Iran, targeting Israel's defense and government sectors with modular attacks. Their sophisticated tactics have allowed them to infiltrate organizations with alarming speed and precision.

Analyst 207
Submarine launches ballistic missile over Pacific coastline with islands on the horizon.

China Warns Pacific Allies with Ballistic Missile Test

China fired a warning shot across the bow of its Pacific allies just hours after Australia and Fiji inked a historic defence pact, testing a submarine-launched ballistic missile into the Pacific Ocean. The move has sparked heated debate across the region and raised questions about Beijing's intentions.

Analyst 207
Person sits at cluttered desk with laptop and financial documents, surrounded by papers.

China-nexus Hackers Deploy DcRAT via Fake Indian Tax Utility

Cyber attackers with ties to China are pulling out all the stops to scam Indian taxpayers, using a sophisticated fake tax utility to deploy malware and pilfer sensitive info. Their precision-crafted phishing campaign, dubbed Operation DragonReturn, sends convincing emails and PDFs that even cite real laws to trick victims.

Analyst 207
Rows of servers and racks in a brightly-lit data center with a single workstation in the foreground.

Ransomware Operation Exploits AI to Automate Cyberattack

Meet JadePuffer, a notorious ransomware operation that's taking cyberattacks to the next level with the power of AI, automating attacks with ease. In a shocking example, JadePuffer used a large language model agent to encrypt a staggering 1,342 Nacos service configuration items.

Analyst 207
Secure facility interior with a symbolic payment terminal or encrypted data storage device.

US Government Entity Pays $1 Million to Thwart Data Leak

A US government entity was forced to pay a hefty $1 million ransom to prevent a massive data leak, after a group called Kairos threatened to release 1.6 million files unless their demand was met. The payment was the culmination of a month-long negotiation that began with a $3 million opening demand.

Analyst 207
Cluttered software development workspace with computer screens and terminals, one central laptop lid slightly ajar.

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign

North Korean hackers have unleashed a massive wave of malware, publishing 108 malicious packages and web browser extensions across popular platforms like npm, Packagist, Go, and Google Chrome as part of their sneaky PolinRider campaign. This ongoing operation has already produced 162 malicious release artifacts and compromised thousands of systems worldwide.

Analyst 207
Military airbase with damaged aircraft and scattered vehicles.

Ukraine Targets Russian Air Base in Crimea with Drone Strikes

Ukraine just landed a major blow to Russia's military capabilities with a daring drone strike on the Saki Air Base in Crimea, taking out multiple hangars and at least seven aircraft, including Su-30SM, Su-30, and Su-24 fighter jets and bombers. The bold operation, claimed by the Ukrainian Security Service, dealt a significant hit to Russia's aviation assets.

Analyst 207
Fireworks explode in a clear blue sky, with subtle security presence in the background.

US Celebrates 250th Anniversary Amid Heightened Security Concerns

Happy 250th birthday, America! This milestone anniversary is the perfect excuse to gather with friends and family, enjoy some fireworks, grab a cold one, and take in the aerial show - including an epic flyby that's sure to leave you in awe.

Analyst 207
Government office workspace with computer workstation hinting at cyberattack.

Armored Likho Exposes BusySnake Stealer Campaign

Meet Armored Likho, a sneaky group behind the BusySnake Stealer Campaign, which has already compromised government agencies and power companies in Russia, Kazakhstan, and Brazil. Their clever tactics start with targeted spear-phishing emails, often disguised as harmless attachments like psychological tests or aid applications.

Analyst 207
Dark industrial control room with a lone, open laptop on a metal console.

Armored Likho Exploits Global Targets with BusySnake Stealer

Meet Armored Likho, a sneaky threat actor who's been wreaking havoc globally, exploiting both private individuals and organizations, including government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. With a blend of financially motivated attacks and targeted cyber espionage, Armored Likho is a force to be reckoned with.

Analyst 207
Australian industrial facility with machinery and subtle national emblems.

Australia Unveils Defense Industry Overhaul to Bolster Sovereign Capabilities

Australia is taking a bold step towards securing its future with a groundbreaking overhaul of its defence industry, aimed at strengthening its sovereign capabilities and forging a deeper partnership with local businesses. The move is driven by a clear imperative: a robust Australian defence industrial base is crucial to national security.

Analyst 207
A smartphone lies face down on a simple office desk surrounded by papers and a notebook, conveying vulnerability.

Pegasus Spyware Targets European Parliament Investigator

In a shocking twist, a member of the European Parliament's PEGA Committee, Stelios Kouloglou, was targeted with the notorious Pegasus spyware - the very same spyware his committee is investigating. This brazen move raises serious concerns about surveillance and accountability.

Analyst 207
Law enforcement officials surround a computer server setup in a secure facility.

FBI Disrupts NetNut Proxy Platform Tied to Popa Botnet

In a major cybercrime crackdown, the FBI has seized hundreds of domains linked to NetNut, a residential proxy service allegedly tied to the massive Popa botnet, which controls at least two million devices. This disruption, made possible with the help of industry partners like Google and Lumen, marks a significant blow to the network's operations.

Analyst 207
Modern office setup with laptop on desk, cityscape through window.

Startup Sues Palo Alto Networks Unit Over AI-Generated Espionage Claims

When a cybersecurity report wrongly labeled MeetingTV a part of a Chinese espionage operation, its CEO knew it was a death sentence - and now the video conferencing startup is fighting back with a lawsuit against Palo Alto Networks and Koi Security. MeetingTV alleges the report, generated by AI, was reckless and falsely accused it of criminal conduct.

Analyst 207
Rows of computer servers, routers, and equipment in a brightly-lit network operations area.

Ransomware Groups Exploit Citrix Bleed 2 in Supply Chain Attacks

Ransomware groups are exploiting the Citrix Bleed 2 vulnerability to launch devastating supply chain attacks, using legitimate remote access tools to spread their reach. This critical flaw has already been linked to multiple ransomware families, including Anubis, which has claimed 91 victims so far.

Analyst 207
Military aircraft flies over rugged desert landscape at sunset.

US Airpower Fails to Win Iran War of Disruption

The US may have dominated the skies above 20,000 feet, but its airpower ultimately failed to disrupt Iran's operations, revealing a crucial gap in its military strategy. Despite intense airstrikes, including a six-week campaign hailed as one of the most powerful since the Iraq invasion, America lost the battle of disruption.

Analyst 207
Medical device on hospital bed with blurred computer records in background.

Medtronic Breach Exposes Patient Health Data to Cybercrooks

Medtronic is alerting patients that their personal and health information may have been compromised in a recent data breach, but has reassured them that the incident didn't impact the safe operation of its medical devices. The breach, detected on April 15, occurred between April 13 and 19, and Medtronic is now notifying affected individuals.

Analyst 207
Corporate office setting with laptop on desk and cityscape through window.

ToddyCat APT Exploits OAuth to Breach Gmail via Google API

Meet ToddyCat, a sneaky APT group that's been exploiting OAuth and the Google API to secretly breach corporate Gmail accounts since 2020. Their latest trick involves a cunning malware called Umbrij, which lets them hijack email communications with ease.

Analyst 207
Network operations room with computer servers and equipment showing signs of affected infrastructure.

FortiBleed Exposes Link to Ransomware Ops

A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.

Analyst 207
Young man escorted by law enforcement officers in a federal courthouse setting.

US Extradites Alleged Scattered Spider Hacker

A 19-year-old hacker, Peter Stokes, has been extradited to the US from Finland, where he was arrested while trying to flee to Japan, and now faces charges for his alleged role in the notorious Scattered Spider hacking group. Stokes is accused of helping orchestrate over 100 network intrusions that netted more than $100 million in ransom payments.

Analyst 207
Military base in northern Australia with infrastructure elements.

Australia's Northern Defence Posture Lags in Resilience Testing

Australia's northern defence strategy is at risk due to a lack of practical assessment, with investment outpacing real-world testing of its resilience. Despite visible progress on infrastructure and projects, the system's ability to withstand stress remains unproven.

Analyst 207