Tag: nation state
993 articles

Australian Cyber Agency Warns of Widespread TeamCity Server Exploit
A critical TeamCity server flaw, tracked as CVE 2026-63077, is being actively exploited, allowing unauthenticated attackers to bypass security checks and execute malicious commands, posing significant risks to organizations. This vulnerability, with a near-perfect CVSS score of 9.8, is a high-priority threat that demands immediate attention.

US Targets Mabna Institute Hackers with Sanctions Over Iranian Cyber-Attacks
The US has imposed sanctions on 17 alleged Mabna Institute hackers responsible for a massive cyber-attack spree targeting over 300 universities, 50 private companies, and several government agencies since 2013. This crackdown, dubbed Operation Economic Outcast, aims to cut off the financial lifelines sustaining Iran's cybercrime operations.

CISA Warns of Actively Exploited Oracle WebLogic Flaw
A critical Oracle WebLogic flaw, CVE-2026-21962, is being actively exploited, allowing hackers to wreak havoc on your system by creating, deleting, or modifying sensitive data. This severe vulnerability has a CVSS score of 10.0, making it a high-priority threat that demands immediate attention.

US Army Cyber Command Forges Integrated Cyber Warfare Capability
The US Army Cyber Command's Joint Integrated Fire Cell proved to be a game-changer, seamlessly integrating Joint Force Headquarters with Army Cyber to tackle complex cyber challenges with unprecedented speed and agility. By synchronizing cyber effects in real-time, the team achieved a major milestone in coordinated cyber warfare.

Senate Bill Targets Energy Sector's Quantum Cybersecurity Gaps
The clock is ticking: as quantum technology advances, our critical energy systems are vulnerable to devastating cyberattacks - that's why Sen. Chris Coons is pushing for the Quantum-GUARD Act to safeguard our nation's infrastructure. This crucial bill would empower the Federal Regulatory Energy Commission to proactively defend against quantum-enabled threats.

China's New Ambassador in Australia Signals Assertive Stance with United Front Ties
China's new ambassador to Australia, Liu Jinsong, made a bold statement on his first day in Sydney by posing for a photo with two high-profile figures tied to the United Front, a move that signals a more assertive approach to his role. This striking image, published on the Chinese embassy's website, immediately linked Liu to organised groups promoting the Chinese Communist Party's interests.

US Treasury Targets Iranian Hackers in Cyber Sanctions Push
The US Treasury Department has launched a bold crackdown on Iranian hackers, designating four individuals for sanctions for their alleged roles in targeting critical US infrastructure and stealing sensitive information. This economic onslaught aims to disrupt Iran's global financial connections and hold its malicious cyber actors accountable.

Malware Spreads via Fake Minecraft Clients Using SEO Poisoning
Malware is sneaking its way into gamers' computers through fake Minecraft clients, using clever tricks like search engine manipulation and spreading malicious links on popular platforms like Discord and YouTube. Over 6,300 attempts to access these malicious sites have already been blocked by McAfee Labs.

Iran Targets UK Power Grid with Cyberattack
A small UK power plant was taken offline for four days in July after a cyberattack, potentially linked to Iran, but officials quickly reassured that the broader energy system was never at risk. The incident has still been flagged as a major escalation in cyber threats, highlighting the need for continued vigilance.

Iran-linked hackers disrupt UK power plant operations
A recent cyberattack linked to Iran caused a small UK power plant to shut down, but fortunately, the incident was contained and posed no risk to the broader energy system. The UK government assured that the country's energy infrastructure is highly resilient and that they're working closely with the sector to protect it.

Medusa Ransomware Gang Targets Over 500 Organizations, Experts Warn
The Medusa Ransomware gang has hit over 500 organizations since June 2021, and experts are sounding the alarm. This active and rapidly expanding Ransomware-as-a-Service campaign has prompted urgent warnings from top US security agencies.

US Warns of AI-Powered Attacks on Siemens PLCs
The US government has issued a stark warning: hackers are harnessing the power of artificial intelligence to launch targeted attacks on vulnerable Siemens PLCs, critical infrastructure devices used in water, energy, and manufacturing sectors. This is no hypothetical threat - it's a very real and active danger.

China-nexus Operation QUICSILVER Targets Myanmar with QUICAgent Backdoor
Meet Operation QUICSILVER, a sneaky cyber espionage campaign targeting Myanmar's government and tech sectors with a multi-stage backdoor delivery chain, likely orchestrated by a China-nexus threat actor. The attack begins with clever social-engineering lures disguised as official materials, like graduation invites and fake holiday messages.

Iranian Hackers Expose UK Power Plant Vulnerability
Can a UK power plant vulnerability leave millions in the dark? Iranian hackers recently caused a four-day blackout at an unnamed UK facility, raising concerns about the potential for a larger, more critical attack.

China's Lunar Ambitions Hit Snag with Chang'e-7 Delay
China's ambitious lunar plans have hit a roadblock with the sudden delay of its Chang'e-7 launch, a crucial mission to scout out a future research base on the Moon's south pole. The postponement throws a wrench into the country's quest to establish a foothold on the lunar surface and set the rules for future exploration.

ToxicPanda Malware Exploits VPN Permissions to Evade Google Play Security Checks
Meet ToxicPanda, a sneaky malware that's evolved to outsmart Google Play's security checks by exploiting VPN permissions and controlling device traffic. This cunning threat can now target nearly 350 apps and execute over 160 remote commands, putting your mobile security at risk.

Think Tank ASPI Marks 25 Years of Shaping Australia's National Security Policy
Celebrating a quarter century of influence, the Australian Strategic Policy Institute (ASPI) was launched with a rare show of bipartisan unity, backed by both the Coalition and Labor parties. Founded 25 years ago with a bold vision of independence, ASPI was set free to challenge conventional thinking and shape Australia's national security policy.

ASPI Celebrates 25 Years of Shaping National Security Debate
For 25 years, ASPI has been at the forefront of shaping Australia's national security debate, providing critical insights that challenge the status quo and inform government decision-making. From its roots in 2001, ASPI has remained committed to delivering contestable advice, fostering public discussion, and cultivating the next generation of security leaders.

NSA Deputy Warns of China's Pervasive Threat Across Domains
China's influence is a game-changer, touching every aspect of national security, and the competition is heating up, with artificial intelligence playing a major role. The NSA Deputy Director warns that Beijing is disrupting the status quo, acting as a spoiler from Greenland to the Korean Peninsula.

Rust Crates Targeted in Supply Chain Attack to Steal Developer Credentials
For a brief but alarming period, a widely-used Rust package was compromised, funneling malicious code into developer machines and putting sensitive credentials at risk. The attack was launched through a cleverly hidden payload in the build script of a popular crate called proc-macro1.

North Korean Hackers Target Rust Supply Chain
North Korean hackers have been caught targeting the Rust supply chain, compromising a trusted open-source maintainer's account to sneak a backdoor into three popular Rust crates. The attackers cleverly modified package manifests to download and execute an unauthorized payload during automated builds.

OpenAI Exposes Hugging Face AI Model Vulnerability
OpenAI recently revealed a vulnerability in a Hugging Face AI model, showcasing impressive cyber offense work in a presentation at Black Hat. The incident's details can be found in Simon Willison's step-by-step timeline.

ASPI's 25-Year Experiment Champions Contestability in National Security Policy
At the heart of ASPI's 25-year journey is a bold experiment: championing contestability in national security policy by fostering open debate and diverse perspectives. This pioneering approach, seeded by Hugh White, has become the institute's DNA, driving stronger strategic policy through constructive disagreement and collaboration.

Google Tracks Russian Cyber Spies Abusing OAuth in Targeted Phishing Campaigns
Google is sounding the alarm on Russian cyber spies who are using OAuth to carry out highly targeted phishing campaigns against top industries, and is sharing details of the attacks to help people recognize malicious outreach. The tech giant has identified three distinct groups behind the ongoing operations, which have been targeting individuals in Europe and the US since last year.