Tag: nation state
993 articles

Russian Hackers Exploit Google OAuth, WhatsApp to Hijack High-Value Accounts
Meet the sneaky Russian hackers who are hijacking high-value accounts using clever tricks and fake emails to get their hands on sensitive info. They're using Google OAuth and WhatsApp to pull off their phishing scams, and experts warn that no one is safe.

Signed Drivers Exposed to Abuse Microsoft Defender Driver Repurposed $10 Million Reward Offered AI Model Exploits Vulnerabilities RCE Flaws Discovered in Gogs, n8n
In a stunning example of old-school ingenuity, a team of investigators finally thwarted a sophisticated espionage campaign by doing something remarkably low-tech: cutting a cable to a compromised router in a Chicago data center. This bold move brought an end to months of digital detective work that had been stymied by the elusive threat actors.

US Army Cyber Command Trains AI Agents for High-Speed Cyber Operations
Meet the US Army's secret cyber squad: Task Force Lexington is leading the charge in AI-powered cyber operations, training specialized agents to tackle high-speed missions. These agents are being molded to fill specific roles, revolutionizing the way the Army tackles cyber threats.

US Charges 17 Iranians in Massive Cybertheft Campaign
Meet the 17 Iranians behind a massive cyber heist that stole a mind-boggling 31.5 terabytes of sensitive data from hundreds of universities, companies, and government agencies - a staggering digital theft that went on for years. The charges reveal a sophisticated hacking operation linked to Iran's Islamic Revolutionary Guard Corps and other government clients.

AI-Generated Scripts Target Siemens PLCs in US Critical Infrastructure
The US government has issued a warning about an active threat targeting critical infrastructure organizations, where hackers are using artificial intelligence to create exploit scripts that target industrial programmable logic controllers, specifically Siemens S7 Series PLCs. This AI-assisted attack has the potential to affect a wide range of industries and is not limited to Siemens PLCs.

Manic Malware Exploits Offline Phones via Nearby Infected Devices
Meet Manic, a potent Android banking malware that can infect offline phones by exploiting nearby infected devices, putting financial institutions and users at risk. This sneaky threat combines financial fraud with advanced surveillance and device control features, making it a major concern for banks, governments, and fintech services worldwide.

US Agencies Warn Siemens PLC Operators of AI-Driven Attacks
US agencies are sounding the alarm: hackers are now using artificial intelligence to launch targeted attacks on Siemens PLC operators, making it easier for them to breach industrial systems. This emerging threat has prompted a joint warning from CISA, the FBI, and partner agencies.

US Cyber Program Faces Russian Hurdle
The White House is facing a major hurdle in its efforts to team up with private firms for overseas cyber operations, thanks to Russia's murky landscape of government control and affiliations. A key challenge lies in distinguishing between official, affiliated, and acknowledged government entities in Russia.

US Agencies Warn of AI-Fueled Attacks Targeting Industrial Controls
Threat actors are now using AI to supercharge their attacks on industrial control systems, dramatically lowering the bar for technical expertise and development time. This alarming evolution puts critical facilities like water, energy, and food production at risk.

Feds Warn of AI-Generated Code Threat to Critical Infrastructure Controllers
The feds have issued a dire warning: AI-generated code is being used to actively threaten critical infrastructure controllers, putting industries like water, energy, and manufacturing at risk. This is a very real and present danger, not just a hypothetical threat.

Hackers Compromise 14,500 Dahua Cameras in 35-Day Global Campaign
In just 35 days, hackers compromised a staggering 14,530 Dahua IP cameras worldwide, with a surprising focus on Russian and CIS telecom networks. The massive operation, dubbed CameraSwarm, exposed a vast amount of sensitive data, revealing the intruders' tactics and targets.

Clop Exploits PTC Zero-Day in Large-Scale Data Theft Spree
Clop's latest large-scale data theft spree exploited a critical PTC zero-day vulnerability, CVE-2026-12569, affecting supply chain systems used by manufacturers, retailers, and industries like aerospace and automotive. This attack continues Clop's trend of targeting SaaS logistics companies with zero-days to carry out mass-exploitation campaigns.

US Agencies Warn of AI-Driven Attacks on Siemens PLCs
US agencies have sounded the alarm on a growing threat: hackers are using artificial intelligence to launch automated attacks on critical infrastructure, including factories, power plants, and water systems, by targeting Siemens PLCs. This active threat has prompted a joint warning from the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency.

US Charges 17 Iranians in $3.4 Billion Intellectual Property Theft Scheme
The US Department of Justice has charged 17 Iranians with masterminding a massive, state-sponsored scheme to steal $3.4 billion worth of intellectual property from American universities, businesses, and government institutions. This brazen hacking operation allegedly involved a hacking-for-hire company called Mabna Institute.

Hackers Exploit MFA Gaps with 155x Surge in Password Spraying Attacks
Hackers are taking advantage of weaknesses in multi-factor authentication, launching a staggering 155 times more password spraying attacks in the first half of 2026. These attacks aren't about fancy new tools, but rather exploiting old authentication paths that slip past security defenses.

Hackers Exploit Dahua Devices via Credential Attacks and Auth Bypasses
Over 14,530 Dahua devices were compromised in a massive cyberattack, dubbed Operation CameraSwarm, which used credential attacks and authentication bypasses to gain control of cameras and other devices. The attackers hit hard in Ukraine and Russia, infiltrating devices via exposed credentials, flaws, and peer-to-peer relay tech.

China-linked SilkParasite campaign targets Central Asia with custom RATs
Meet SilkParasite, a sneaky espionage operation linked to China that's been targeting government bodies in Central Asia with a custom arsenal of Remote Access Tools. This sophisticated campaign boasts seven unique RAT families, five of which have never been seen before, and hints at AI-assisted development.

Medusa Ransomware Targets Over 500 Infrastructure Orgs, Expands Tactics
Medusa ransomware has hit a staggering 500+ critical infrastructure organizations, with healthcare being a prime target, as reported in a recent FBI advisory. The attacks are happening at an alarming rate, with exploitation windows as short as 24 hours or even less.

Medusa Ransomware Targets Over 500 US Critical Infrastructure Orgs
The Medusa ransomware gang has struck a staggering 500+ US critical infrastructure organizations across multiple sectors, including healthcare, defense, and finance, since June 2021. This alarming surge in attacks has prompted a joint warning from top US agencies, highlighting the urgent need for heightened cybersecurity measures.

US-South Korea Alliance Must Counter North Korea's Battlefield Gains
With President Donald Trump's call to "substantially reduce" joint military exercises with South Korea, the US-South Korea alliance faces a critical juncture that could fundamentally change how the two nations prepare for future conflicts. This sudden shift comes at a particularly challenging time, with factors like cost, diplomatic tensions, and Trump's rapport with Kim Jong Un influencing the decision.

Ukraine Develops Homegrown Glide Bomb to Counter Russian Threats
Meet the Equalizer, a game-changing glide bomb developed by Ukraine to take the fight to Russian forces, capable of striking targets dozens of kilometers behind enemy lines with a 250 kg warhead. This homegrown innovation was brought to life in just 17 months, thanks to the collaboration between DG Industry and Brave1, Ukraine's defense technology incubator.

Indonesia's China Exercise Exposes Non-Alignment Strategy Gaps
A simple "routine passing exercise" between Indonesia and China has sparked a heated diplomatic debate, revealing potential gaps in Indonesia's non-alignment strategy. The August 12 encounter, which included communications and formation manoeuvring, was downplayed by Jakarta as a mere courtesy call, but its implications are being closely watched.

US Recharges Indictment Against Iranian Hackers Tied to Mabna Institute
The US has ramped up its pursuit of justice against Iranian hackers, expanding an indictment to charge 17 individuals affiliated with the notorious Mabna Institute, which allegedly compromised over 100,000 professors' email accounts worldwide. This move marks a significant escalation in the case, with eight new defendants added to the original 2018 indictment.

US Military Tests 3D Printing in War Games to Bolster Pacific Supply Lines
In a high-intensity conflict in the Indo-Pacific, the US military could struggle to meet its repair and resupply needs - a challenge that 3D printing may help alleviate. The Navy recently tested an experimental 3D printing network during the Rim of the Pacific wargames to see if on-demand production could ease logistics in a potential Pacific conflict.