Tag: nation state
1000 articles

Sanders' AI Fund Plan Sparks Debate on Public Control
Imagine a future where a select few billionaires control the fate of humanity through their AI creations, with little to no input from the public - or one where the people have a say and reap the benefits. Senator Bernie Sanders is proposing a bold solution: a U.S. sovereign wealth fund that would give the public a 50% stake in AI companies like Anthropic, OpenAI, and xAI.

ShinyHunters Exploits Oracle Flaw to Breach Universities
A zero-day flaw in Oracle PeopleSoft PeopleTools, known as CVE-2026-35273, has been exploited by ShinyHunters, potentially infiltrating over 100 organizations, with universities being the hardest hit. This vulnerability allows attackers to execute remote code and take over affected servers, posing a significant threat to higher education institutions.

Cyber Force push falters in Senate, but proponents persist
Despite a narrow setback in the Senate Armed Services Committee, supporters of a new Cyber Force remain undeterred, with Senator Kirsten Gillibrand's team vowing to continue the push for its creation. The proposed Cyber Force, which would be housed under the Army, fell just 1 vote short in a 14-13 defeat.

China-Linked Hackers Infiltrate Linux Login Software with Decade-Long Backdoor
A stealthy China-linked hacking group, tracked as Velvet Ant, has been quietly infiltrating Linux login software since 2016, embedding a decade-long backdoor that evades routine security cleanups and password resets. This sophisticated operation, dubbed Operation Highland, has allowed the group to fly under the radar and maintain persistent access to targeted systems.

Experts Cast Doubt on Handala's US Water Hacking Claims
Experts are debunking Handala's claims of being able to shut off water in US cities, with no evidence to back up the group's bold assertions. According to Sean Malone, Chief Information Security Officer at BeyondTrust, the breach appears to be limited to non-critical systems, with no impact on water treatment or distribution.

Novo Nordisk Discloses Cyberattack, Patient Data Stolen
Novo Nordisk revealed that a cyberattack has compromised patient data, specifically information related to clinical-trial participants, though assured that the data is not directly linked to patients by name or other identifiers. The company is working with outside experts to investigate and contain the breach.

Cyber-Attacks Infiltrate 84% of Sports Organizations
Cyber-attacks have hit a staggering 84% of sports organizations in the past year, with over half of those being targeted multiple times - a worrying trend in an industry where timing and spectacle are everything. This alarming statistic highlights the vulnerability of professional sports teams, venues, and event bodies to cyber threats.

China Bolsters Mekong River Patrols With Advanced Weaponry
China is taking its Mekong River patrols to the next level with cutting-edge gear, including remote weapon stations and rocket launchers, to ensure the waterway remains safe and open. This move is part of a long-standing joint security operation with Laos, Myanmar, and Thailand to prevent incidents like the 2011 massacre that sparked the initiative.

China's Influence Silences Dissent in Zambia
In Zambia, a stark reality has emerged: China's growing influence is stifling dissenting voices, with critics like Michael Sata labeling the Chinese presence as parasitic rather than beneficial. The recent postponement of RightsCon, a human rights summit, has starkly illustrated this chilling effect.

ShinyHunters Breaches Universities via Oracle PeopleSoft Zero-Day Exploit
Hackers have struck 68% of breached organizations in the higher education sector, with a whopping majority being US universities, by exploiting a critical zero-day vulnerability in Oracle PeopleSoft. This severe flaw, rated 9.8/10, allows for remote code execution with no login or user interaction required.

Russian national charged in Void Blizzard cyber-espionage scheme
A Russian national, Denis Nikolayevich Obrezko, has been charged with helping facilitate a massive cyber-espionage scheme that infiltrated at least 11 US companies, with authorities suspecting many more victims nationwide. Obrezko allegedly played a key role in the Void Blizzard campaign by buying a virtual private server and registering domain names used in the intrusions.

Malware Campaign Exploits AI Demand with Fake Guides and Dev Tools
Cyber attackers are now disguising malware as legitimate AI learning guides and developer tools, tricking professionals into opening malicious files that look like trusted educational content. They've been distributing booby-trapped archives labeled as AI study guides and developer tools, such as fake AI-ready PostgreSQL and agentic coding guides.

OceanLotus Targets Vietnam Investors with SPECTRALVIPER Backdoor
The notorious 15-year-old APT group, OceanLotus, is now setting its sights on Vietnam's investors with a cunning new backdoor attack called SPECTRALVIPER, showcasing their relentless adaptability and aggressive tactics. This latest move has left experts wondering if it's a temporary shift or a long-term strategy.

FBI Disrupts Chinese Spy Websites Targeting US Security Clearance Holders
The FBI and Justice Department have shut down 13 fake websites pretending to be legitimate consulting firms, targeting US security clearance holders with lucrative job offers that aimed to extract sensitive information for the Chinese government. These seized domains were part of a sophisticated intelligence collection campaign that began in November 2023.

NSO Group Defies Court Order, Continues Targeting WhatsApp Users
Despite a court order blocking it from doing so, NSO Group continues to target WhatsApp users, defying the ruling and putting users at risk. The company is fighting to overturn the order, claiming it will suffer harm if it's forced to comply.

China Exposes Botnet Resurgence, AI Influence Ops Targeting US
A botnet once dismantled by US law enforcement has made a stunning comeback, with over 1,500 compromised routers and IoT devices now under the control of China-nexus actors, who are using it to fuel influence campaigns and recruitment scams. This resurgence poses a significant threat, with the same group of actors still active and causing chaos.

Nations Scramble to Build Critical Mineral Supply Chain Resilience
The conversation about critical minerals is no longer about "if" but "how" - and the Darwin Dialogue 2026 brought together global leaders to shift the focus from diagnosis to delivery. The big question now is why democratic economies struggle to build resilient supply chains at scale and speed.

OpenAI Exposes Chinese Influence Operation Using ChatGPT
OpenAI has uncovered a sneaky Chinese influence operation that used ChatGPT to spread disinformation, posing as American voices to manipulate online debates. The operation, tracked by OpenAI's threat intelligence team, appears to be a classic case of foreign meddling.

China-Linked JDY Botnet Surges to 1,500 Devices for Cyber Reconnaissance
A covert network of over 1,500 devices, linked to China, has been uncovered, feeding sensitive data to nation-state actors in a massive cyber reconnaissance operation. This JDY botnet has rapidly expanded, scanning and mapping vulnerable infrastructure on a massive scale.

China-linked JDY botnet targets US military networks with expanded reconnaissance.
The JDY botnet, linked to China, has more than doubled its malicious reach since January 2024, growing from 650 to over 1,500 compromised devices, with a significant focus on infiltrating US military networks and associated targets. This expanding reconnaissance capability poses a concerning threat to US cybersecurity.

Ukraine Unleashes AI-Powered Drone Strikes on Russian Logistics
Meet the game-changing AI-powered drones taking the fight to Russian logistics, striking at the heart of their supply chain with precision and stealth. Ukraine's innovative tactics are redefining modern warfare, one targeted hit at a time.

Microsoft Patch Tuesday Discloses 3 Zero-Day Flaws Amid 200 Security Fixes
Microsoft just dropped its June Patch Tuesday update, tackling a whopping 200 security flaws, including three zero-day vulnerabilities that need urgent attention. This massive release is a must-address for all organizations running Microsoft software.

Russia-Aligned Groups Exploit WinRAR Flaw to Deploy Stealers in Ukraine
Despite a July 2025 patch, a vulnerability in WinRAR, known as CVE-2025-8088, continues to be exploited by Russia-aligned groups, including SHADOW-EARTH-066, to deploy stealers in Ukraine. This highlights the risks of unmanaged software leaving exploited entry points open long after a fix is released.

US Directs Agencies to Accelerate AI Adoption in National Security
The White House is pushing to supercharge national security with AI, directing agencies to rapidly adopt cutting-edge technology while protecting it from theft and manipulation. President Trump signed a memo that tasks top security offices, including the FBI and the ODNI, with harnessing AI to boost government operations and intelligence analysis.