Skip to main content

Tag: nation state

994 articles

A typical defense sector industrial setting with a computer workstation in the mid-ground, surrounded by ordinary activity.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks

North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Analyst 207
System administrator looks concerned at phone with Telegram conversation, surrounded by work materials on desk.

Sandworm Hackers Exploit VPN Client in IT Pro Targeting Scam

Beware of fake job interviews! Cyber attackers, linked to the notorious Sandworm group, are targeting IT pros with bogus job offers, tricking them into installing a malicious VPN client to gain access to sensitive info.

Analyst 207
Windows computer workstation on a clean office desk with a blank laptop screen.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack

Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Analyst 207
A dimly lit office space with scattered papers and a faint outline of a voting machine in the distance.

US Abruptly Halts Voting System Security Review

The government's sudden halt of a voting system security review has left experts stunned, with the CEO of Mojave Research, Jason Wareham, calling it one of the worst decisions of his life. The six-week federal engagement, which had grown to involve around 60 people, was abruptly shut down just as the team was set to press forward.

Analyst 207
Air Marshal Stephen Chappell speaks at a podium with a blurred audience and Australian Defence Force emblem nearby.

Australia's Deterrence Framework Risks Conceptual Divergence

Australia's emerging deterrence approach is taking shape with Air Marshal Stephen Chappell's 6C-4D construct, a bold framework that combines capability, credibility, and collective power to disrupt, degrade, destroy, and defeat threats. This innovative approach aims to unify Australia's defence strategy, bringing together joint operations, interagency collaboration, and alliances to strengthen national defence.

Analyst 207
Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware

In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Analyst 207
System administrator surrounded by papers and notes, laptop open to job search website in dimly lit home office.

Sandworm-linked hackers exploit fake job interviews to deploy command-running VPN malware

Hackers linked to the notorious Sandworm group are using fake job interviews to trick IT workers into installing VPN malware that can run commands on their devices. They pose as recruiters from legitimate IT companies, making contact with potential victims after reviewing their resumes on job search websites.

Analyst 207
Employees work at computer desks in a brightly-lit tech facility with city view.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits

Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

Analyst 207
Cluttered home office desk with laptop, smartphone, and notebook, cityscape visible through window.

DeadLock Ransomware Exploits Polygon Smart Contracts

DeadLock Ransomware takes a sophisticated approach by leveraging the Session messaging network and blockchain-backed services to streamline its extortion process, making it harder for victims to recover. Its operators use a clever combination of decentralized chat and a self-contained HTML app to communicate with victims and demand payment in Bitcoin or Monero.

Analyst 207
Well-lit office setting with laptop and papers on a neutral-colored desk.

Researchers Expose North Korean IT Hiring Ploy

Security researchers pulled off a clever experiment, creating a fake DeFi startup and hiring three suspected North Korean IT operatives to uncover the tactics used to secretly place foreign workers in companies, and were surprised to find that none exploited their access. The operatives cleared interviews, signed contracts, and were given access to a work virtual machine, but instead of breaching security, they seemed to be gathering intel.

Analyst 207
Concerned officials stand outside partially closed city hall entrance.

US Local Governments Targeted in Wave of Cyber Attacks

Local governments are under siege, with a growing wave of cyber attacks crippling their operations - just like Suisun City, which was forced to declare a state of emergency after a malicious software attack shut down its entire IT network. The attacks are leaving communities vulnerable, with city services and internal operations grinding to a halt.

Analyst 207
Industrial control room interior with analog and digital equipment, featuring a large control panel and computer workstation.

Gunra Ransomware Targets Infrastructure with Fortinet, Schneider Electric Exploits

Gunra ransomware is on the loose, exploiting vulnerabilities in critical infrastructure from Fortinet and Schneider Electric to wreak havoc on organizations worldwide. This malicious campaign uses double-extortion tactics, combining data theft with file encryption to maximize damage.

Analyst 207
City transit platform with disrupted digital screens and halted trains.

US, South Korea Warn of Gunra Ransomware Threat

Meet Gunra, a highly sophisticated ransomware threat that's been wreaking havoc since April 2025, evolving from a Windows-targeting menace to a cross-platform attacker with a thriving commercial ecosystem. This malicious force has rapidly expanded its reach, morphing into a full-fledged ransomware-as-a-service operation by January 2026.

Analyst 207
Control room with industrial panels, meters, and switches, and a cellular antenna outside a large window.

Hackers Exploit Private Cellular Network to Breach Polish Power Plant Controls

In a chilling breach, hackers infiltrated a Polish power plant's controls, putting the heat supply of 50,000 residents at risk, by exploiting a vulnerable private cellular network used to connect remote equipment. The intruder's route began at a nearby wind farm, where a poorly secured VPN and lack of multi-factor authentication created an easy entry point.

Analyst 207
Industrial control room with cellular router and equipment, network operations center in background.

Hackers Exploit Private APN to Breach Polish Energy Plant

In a groundbreaking cyberattack, hackers exploited a private APN to breach a Polish energy plant, marking the first observed instance of this attack vector in a real-world scenario. CERT Polska tracked the intrusion to a compromised FortiGate VPN/firewall at a wind farm, which served as a springboard for the attack.

Analyst 207
Modern office setting with idle computers, hinting at disruption or concern.

US, South Korea Warn of Gunra Ransomware Gang's Global Reach

US and South Korean authorities are sounding the alarm on the global threat of the Gunra Ransomware Gang, warning that this malicious group has evolved into a sophisticated ransomware-as-a-service operation. The joint advisory aims to alert network defenders to the gang's growing reach and devastating impact on organizations worldwide.

Analyst 207
Military officials gather around a conference table near a large map display of the Indian Ocean region.

Bangladesh Bolsters Maritime Security with Saudi-led Coalition

Bangladesh is joining forces with a Saudi-led coalition to boost maritime security, with a focus on tackling the Houthi threat, while keeping the door open for collaboration with other nations, including Iran. The coalition, made up of 14 founding members, aims to enhance intelligence sharing, joint planning, and coordinated maritime operations.

Analyst 207
Diverse team in conference room with whiteboard and modern technology.

NATO, AI Startup Gain Power to Track Software Vulnerabilities

The cybersecurity landscape just got a major boost: NATO's Cyber Security Centre and AI startup AISLE have joined forces with ENISA to supercharge vulnerability management, bringing the total number of CVE numbering authorities to 20. This powerful collaboration aims to revolutionize the way we track software vulnerabilities and stay one step ahead of cyber threats.

Analyst 207
A typical office setting with computers and a blurred server room door in the foreground.

China-Linked Hackers Deploy StormEncryptor Ransomware via N-central Flaw

Meet StormEncryptor, a sneaky new ransomware strain linked to China that's leaving a trail of encrypted files and ransom notes in its wake. This malicious software, written in C++, is marked by its telltale .encrypted file extension and !!!README_FIRST!!!.txt ransom notes.

Analyst 207
Cluttered server room with computer equipment, cables, and monitors, plus AI development hardware and software tools.

North Korean Spies Deploy Local AI Tools to Bolster Cyber Operations

North Korean spies are taking their cyber operations to the next level by deploying local AI tools, marking a significant shift from experimentation to integration. This development enables them to enhance malware development, data analysis, and attack techniques, posing a more sophisticated threat.

Analyst 207
A cluttered server room with rows of computer servers and networking equipment, highlighting a single organized server.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure

North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

Analyst 207
Rack-mounted servers and cables in a brightly-lit server room, with one isolated rack showing subtle signs of tampering.

TrueConf Server Flaws Targeted to Deploy PhantomCore Backdoor

Security researchers at Kaspersky have uncovered a sneaky plot by threat actor Head Mare to exploit unpatched TrueConf servers and deploy the PhantomCore backdoor to unsuspecting users. The attack relies on a two-stage vulnerability chain that allows attackers to run malicious commands with high-level privileges.

Analyst 207
Cluttered home office desk with MacBook displaying suspicious popup window.

Go-Based Malware Targets macOS Crypto Wallets

Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

Analyst 207
Modern podium with abstract seal in background, in formal institutional setting.

US Targets Shelbit in $6bn Crypto Sanctions Crackdown

The US Treasury Department has cracked down on crypto sanctions, targeting Shelbit, a shadowy crypto conduit, and its founder Siavash Kayvanpour in a $6bn blow to Iran's financial apparatus. This move underscores the Treasury's determination to disrupt Tehran's reliance on digital assets and secret banking networks.

Analyst 207