Tag: nation state
993 articles

US Authorizes Private Cyber Firms to Strike Foreign Targets
The US has just given private cyber firms the green light to take bold action against foreign adversaries, allowing them to manipulate, degrade, disrupt, and even destroy malicious computer networks. This game-changing move marks a new era in cybersecurity, where private companies can play a key role in defending the nation's digital interests.

Jewelbug APT Exploits Dual Agenda with Espionage and Crypto Fraud
Meet Jewelbug, a notorious APT group that's been pulling off a double heist - stealing sensitive info and swindling victims out of crypto - all from the same interconnected operation. Their massive haul includes over 1 million implant check-ins and 580,000 stolen cookies, with targets spanning government systems and service providers across the Middle East, Southeast Asia, and South Asia.

Australia Urges Southeast Asian Nations to Clarify Maritime Incidents
Australia is stepping up its support for Southeast Asian nations to tackle maritime incidents, with a recent pledge of A$10 million to enhance the Philippine Coast Guard's drone technology and training. This move aims to boost the region's maritime domain awareness, but experts warn that more data doesn't always mean more clarity.

US Enlists Private Sector in Cybercrime Hacking Operations
The US government has taken a bold step in the fight against cybercrime, enlisting the help of the private sector to tackle transnational criminal organizations in a newly signed presidential memorandum. This move has sparked reactions ranging from cautious optimism to alarm, as experts weigh the potential benefits and risks of this unprecedented collaboration.

China Exploits New Zealand's Space Sector for Military Intelligence
China's military intelligence efforts have infiltrated New Zealand's space sector, with a local company unwittingly at the center of an attempted space-based spying operation. The plot involved a China-based organization called Purple Mountain Observatory, which tried to install Ground Based Space Infrastructure in New Zealand to track satellites and space debris.

Apple Warns Users of Mercenary Spyware Attacks on iPhones
Got a warning from Apple about a mercenary spyware attack on your iPhone? This means hackers are trying to secretly access your device, and Apple is stepping in to alert and protect you.

Akira Ransomware Actors Exploit Safe Mode to Evade EDR Protections
Cyber attackers have found a sneaky way to bypass EDR protections by exploiting Safe Mode, leaving security systems blind to their malicious activities. In one recent incident, an exposed SonicWall VPN with no multi-factor authentication was all it took for hackers to gain entry and start wreaking havoc.

Armored Likho Expands Cyber-Espionage Arsenal
Meet the Armored Likho group, a cyber-espionage mastermind that's just leveled up its game with a suite of sneaky new implants that can hijack Telegram sessions and eavesdrop on conversations. The latest campaign, uncovered in May 2026, uses a cunning fake donation app to infiltrate targets across Russia.

Jewelbug Hacker Group Exposes Dual Threat of Espionage and Crypto Fraud
Meet Jewelbug, a China-based hacker group that's been wreaking havoc with a dual threat of espionage and crypto fraud, leaving a trail of over a million compromised implant check-ins and thousands of stolen credentials in its wake. By cleverly injecting a single malicious script into a shared webmail template, Jewelbug gained write access to sensitive government webmail accounts, making off with valuable data.

US Grants Private Firms License to Hack Back Against Cybercrime Groups
The US government has just given private cybersecurity firms the green light to hack back against foreign cybercrime groups that threaten American interests, marking a major shift in the country's cyber warfare strategy. This bold move targets transnational crime groups, not nation-states, and paves the way for covert surveillance and cyber operations.

US Authorizes Private Sector in Offensive Cyber Strikes
The White House is taking a bold stance against transnational cyber threats, authorizing the private sector to join forces with federal law enforcement on offensive cyber strikes to disrupt foreign cyber actors targeting the US. This new public-private program unlocks every available tool to protect Americans from cyber-enabled crime.

Iranian F-5s Expose US Air Defense Vulnerabilities
A retired US Air Force general just revealed a shocking vulnerability in US air defense systems, saying that Iranian F-5s were able to evade detection and drop bombs on a US airbase, exposing a major security gap. This embarrassing breach, described as the first of its kind in decades, highlights the urgent need for improved counter-drone defenses.

Ransomware Attacks Pivot to Identity-Based Exploits
Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

City-Forum Attacks Exploit Salesforce, ServiceNow Portals for Data Theft
A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

Iranian Drones Exposed F-15E to Shoulder-Launched Missile
Iranian drones played a deadly role in a recent air engagement, feeding critical targeting data to commanders who used it to launch a shoulder-fired missile that struck a US F-15E jet. The drones provided precise GPS location, speed, and direction, making it a turning point in the April skirmish over southern Iran.

Hackers Deploy AI for Near-Autonomous Attack on Taiwan Government
In a chilling first, hackers unleashed a near-autonomous AI-driven cyber attack on the Taiwanese government, extracting over 2,500 personnel records with alarming ease. This groundbreaking attack was able to adapt and evolve mid-operation, all without human intervention.

Lazarus Exploits Windows Zero-Day to Deploy Trojan Backdoor
Meet the sneaky Trojan backdoor, Troy, that's been secretly infiltrating defense and aerospace companies worldwide by exploiting a newly discovered Windows zero-day vulnerability. This stealthy attack, part of Operation Dream Job, tricks victims with fake job offers on LinkedIn before deploying the malware.

Lazarus Exploits Windows Zero-Day in Targeted Defense Sector Attacks
The notorious Lazarus threat group has been exploiting a newly patched Windows zero-day vulnerability, CVE-2026-68820, to gain SYSTEM privileges and escalate their attacks on high-value targets in the defense sector. This alarming exploit has been active since early July, making it crucial for organizations to stay vigilant.

Fake Remote Workers Exploit Hiring Process Gaps
Scammers are exploiting gaps in the hiring process to land remote jobs, using stolen credentials and impersonating others to get their hands on sensitive corporate information. They're taking advantage of the rise of remote work to gain access to company networks and exfiltrate proprietary data.

Gunra Ransomware Targets Infrastructure via Fortinet Flaws
Gunra Ransomware is exploiting critical Fortinet flaws, including CVE-2024-55591, to gain super-admin privileges and infiltrate government and critical infrastructure networks. This alarming vulnerability allows remote attackers to craft requests and bypass authentication, putting sensitive systems at risk.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics
Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Russian Hackers Breach Polish Power Plant via Private APN
In a chilling cyberattack, Russian hackers infiltrated a Polish power plant by breaching a wind farm's VPN and firewall, then exploited a cellular router to gain control of the plant's systems. The attackers forced a combined heat and power plant into a controlled shutdown, overriding its operations with a password-protected lock.

DeadLock Ransomware Leverages Blockchain to Evade Takedown
DeadLock Ransomware is taking a disturbingly clever approach to evade shutdown by leveraging the Polygon blockchain to conceal its operational addresses, making it a formidable foe for cybersecurity efforts. By cleverly using decentralized building blocks, the group has already amassed a shocking 80 victims, mostly in Europe.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks
North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.