Tag: nation state
998 articles

US Offers Bounty for Hackers Targeting WhatsApp, Signal Users
The US government is cracking down on hackers targeting WhatsApp and Signal users, offering up to $10 million for information that helps track down those behind the attacks. The move aims to take down Russian-linked hacker groups that have been phishing US officials, military leaders, and allied personnel.

Gamaredon Intensifies Ukraine Cyberattacks with Novel Malware Tools
Gamaredon ramped up its cyberattack efforts in Ukraine last year, unleashing 35 targeted spear-phishing campaigns that zeroed in on government and military targets. The group's goal was to siphon off sensitive information to fuel Russian interests in the ongoing conflict.

Nissan Discloses Oracle PeopleSoft Breach Exposing Payroll Records
Nissan has alerted the California Attorney General to a potential data breach, revealing that a cyber attack on Oracle PeopleSoft systems may have exposed sensitive payroll records of hundreds of companies, including Nissan, from May 27 to June 9. The automaker believes it was specifically targeted in the attack, which may have compromised a range of personnel data.

Oracle Flaw Exposes US Citizens' Credit Data in NAIC Breach
A recent breach at the National Association of Insurance Commissioners exposed US citizens' sensitive credit data, prompting swift action and FBI coordination to mitigate the damage. The hack was made possible by a zero-day vulnerability in Oracle PeopleSoft, which was exploited by attackers to gain unauthorized access.

Russia Targets Jaguar Land Rover in Economically Destructive Cyber-Attack
Russian hackers allegedly launched a devastating cyber-attack on Jaguar Land Rover, causing a staggering £1.9bn hit to the British economy. This brazen breach is just the latest example of nation states using underhanded tactics to wreak havoc on a global scale.

FBI Warns of Russian Intelligence Signal Phishing Attacks
Stay vigilant: Russian intelligence agents are masquerading as automated support accounts to trick victims into revealing sensitive Backup Recovery Keys through phishing messages. The FBI has warned that multiple clusters of Russian hackers, including FSB officers and military hackers, are actively targeting high-risk accounts.

China Exposes US Military's Strategic Weaknesses in Iran Conflict Analysis
A recent memo from China's People's Liberation Army reveals that the US military's strengths in tactical execution are overshadowed by strategic weaknesses, leaving it vulnerable in conflicts like the one with Iran. The analysis exposes five key flaws, including diplomatic isolation and self-inflicted damage through information ecosystems.

Russia Targets Messaging Credentials with Fake Support Texts
Beware of fake support texts that could compromise your personal data and sensitive information! A joint investigation by the Security Service of Ukraine and the FBI uncovered a systematic campaign to steal messaging platform credentials from government officials, military personnel, and activists worldwide.

US Strikes Iranian Targets After Drone Attack on Cargo Ship
The US has launched a strong retaliatory strike against Iranian targets after a drone attack on a commercial cargo ship in the Strait of Hormuz, with CENTCOM describing the action as a powerful response to the aggression. The move comes after Iran used a one-way attack drone against the M/V Ever Lovely, prompting a firm US response.

FBI Warns of Russian Hackers Targeting Signal Backup Keys
Stay vigilant, as Russian hackers are now targeting Signal backup keys in an evolved phishing campaign, attempting to gain access to your historical message backups by tricking you into revealing these sensitive keys. Be cautious of messages masquerading as automated support accounts, as they may be part of this sinister plot.

FBI Warns of Russian Hackers Targeting Signal with Recovery Key Phishing
Beware of scammers posing as Signal support - the FBI and CISA warn that Russian hackers are using recovery key phishing to target users, so treat any in-app message from Signal support with extreme caution. Stay safe by being vigilant about unexpected messages.

SharkLoader Malware Targets Global Entities in StrikeShark Cyberattacks
Kaspersky has uncovered a massive global cyberattack campaign, dubbed StrikeShark, that uses SharkLoader malware to target a wide range of organizations across multiple countries and industries. The attacks have hit diplomatic and government bodies, software development companies, and other entities in over a dozen countries.

Threat Actors Exploit OpenAI Invitations to Target Cybersecurity Firms
Threat actors are cleverly exploiting OpenAI invitations to scam cybersecurity firms, creating fake tenants that mimic legitimate companies and sending convincing emails that pass authentication checks. These targeted phishing attacks allow scammers to spread malicious content through a trusted channel.

Chinese APT Deploys TinyRCT Backdoor in Southeast Asia Cyberattacks
A Chinese advanced persistent threat actor, CL-STA-1062, has launched a series of cyberattacks in Southeast Asia, targeting government entities and state-owned energy firms with a new .NET backdoor called TinyRCT. This sophisticated attack tool is part of a hybrid toolkit used by the group, which has been active since March 2022.

CISA Flags Exploited PTC Windchill Flaw Amid Web Shell Attacks
PTC has confirmed that attackers are exploiting a high-severity flaw, CVE-2026-12569, in its Windchill software to drop malicious web shells on vulnerable systems, allowing them to execute arbitrary code remotely. The company has reported heightened threat activity, urging users to take immediate action to protect themselves.

China-Linked Hackers Deploy TinyRCT Backdoor in Southeast Asian Infrastructure Attacks
For years, a stealthy China-linked hacking group has been quietly targeting critical infrastructure in Southeast Asia, with a clear strategic interest in disrupting or monitoring key regional industries. Their sophisticated attacks have zeroed in on state-owned energy and government sectors, using a potent tool called the TinyRCT backdoor.

Cellebrite Tool Used by Russia on Jailed Activist's iPhone Despite Sales Cutoff
Despite Cellebrite's claims to have cut off sales to Russia, a shocking forensics trail on a jailed activist's iPhone reveals that the company's tool was used to extract data as recently as June 2021. This alarming discrepancy raises serious questions about Cellebrite's control over its technology.

Turla Unveils STOCKSTAY Backdoor in Ukraine Espionage Campaigns
Russian hackers, specifically the state-sponsored group Turla, have unleashed a new and stealthy backdoor called STOCKSTAY in a recent espionage campaign targeting Ukraine. This sneaky malware uses a secure WebSocket connection to communicate with its command center, making it a formidable tool for cyber spies.

Chinese Hackers Target Southeast Asia's Energy, Government Sectors
Chinese hackers have launched a stealthy assault on Southeast Asia's energy and government sectors, infiltrating at least ten organizations between October and December 2025. This sophisticated threat, tracked as CL-STA-1062, has been lurking in the shadows since March 2022, using clever tactics like hard-coded encryption keys to evade detection.

Iran Strikes Cargo Vessel, Halts Strait of Hormuz Evacuation Plan
The International Maritime Organization has hit the pause button on an evacuation plan for hundreds of vessels in the Persian Gulf after a cargo ship was struck in the Strait of Hormuz, citing safety concerns. The move aims to ensure that necessary safety guarantees remain in place for ships in the region.

Qihoo 360 Unveils AI Bug-Finder to Rival Anthropic's Mythos
Qihoo 360 CEO Zhou Hongyi has unveiled an AI bug-finder, positioning it as a powerful countermeasure to restricted Western tools, likening Anthropic's Mythos to a "cyber nuclear weapon". This new Chinese innovation aims to level the playing field in cybersecurity.

Loitering Munitions Converge on Long-Range Strike Designs
Loitering munitions have revolutionized long-range strikes, as seen in Ukraine's recent launch of hundreds of LMs at multiple regions, including a daring attack on Russia's Gazprom Neft Moscow Oil Refinery, just 14 km from the Kremlin. This new class of munitions has eliminated the need for high-cost platforms, allowing for more flexible and affordable precision strikes.

Cellebrite Tool Exploited by Russia to Infiltrate Activist's Phone
Russian authorities exploited a loophole in Cellebrite's UFED tool, using it to extract data from activist Andrey Pivovarov's phone, even after the device was no longer receiving updates. This security gap allowed the authorities to access the phone's data as far back as June 2021.

macOS Malware Embeds Fake Errors to Evade AI Analysis
Meet macOS.Gaslight, a sneaky new malware family from a North Korean-linked threat actor that's got a clever trick up its sleeve - embedding 38 fake system messages to throw off AI analysis tools. This tiny 3.5 KB payload is packed with deception, making it a formidable foe for cybersecurity experts.