Tag: nation state
994 articles

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks
North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Sandworm Hackers Exploit VPN Client in IT Pro Targeting Scam
Beware of fake job interviews! Cyber attackers, linked to the notorious Sandworm group, are targeting IT pros with bogus job offers, tricking them into installing a malicious VPN client to gain access to sensitive info.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack
Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

US Abruptly Halts Voting System Security Review
The government's sudden halt of a voting system security review has left experts stunned, with the CEO of Mojave Research, Jason Wareham, calling it one of the worst decisions of his life. The six-week federal engagement, which had grown to involve around 60 people, was abruptly shut down just as the team was set to press forward.

Australia's Deterrence Framework Risks Conceptual Divergence
Australia's emerging deterrence approach is taking shape with Air Marshal Stephen Chappell's 6C-4D construct, a bold framework that combines capability, credibility, and collective power to disrupt, degrade, destroy, and defeat threats. This innovative approach aims to unify Australia's defence strategy, bringing together joint operations, interagency collaboration, and alliances to strengthen national defence.

Head Mare APT Exploits Unpatched TrueConf Servers to Deliver PhantomCore Malware
In a sneaky move, the Head Mare group exploited unpatched TrueConf servers to spread PhantomCore malware, using a chain of vulnerabilities to swap out legitimate client installers with infected ones. This allowed them to secretly deliver a backdoor to unsuspecting meeting participants.

Sandworm-linked hackers exploit fake job interviews to deploy command-running VPN malware
Hackers linked to the notorious Sandworm group are using fake job interviews to trick IT workers into installing VPN malware that can run commands on their devices. They pose as recruiters from legitimate IT companies, making contact with potential victims after reviewing their resumes on job search websites.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.

DeadLock Ransomware Exploits Polygon Smart Contracts
DeadLock Ransomware takes a sophisticated approach by leveraging the Session messaging network and blockchain-backed services to streamline its extortion process, making it harder for victims to recover. Its operators use a clever combination of decentralized chat and a self-contained HTML app to communicate with victims and demand payment in Bitcoin or Monero.

Researchers Expose North Korean IT Hiring Ploy
Security researchers pulled off a clever experiment, creating a fake DeFi startup and hiring three suspected North Korean IT operatives to uncover the tactics used to secretly place foreign workers in companies, and were surprised to find that none exploited their access. The operatives cleared interviews, signed contracts, and were given access to a work virtual machine, but instead of breaching security, they seemed to be gathering intel.

US Local Governments Targeted in Wave of Cyber Attacks
Local governments are under siege, with a growing wave of cyber attacks crippling their operations - just like Suisun City, which was forced to declare a state of emergency after a malicious software attack shut down its entire IT network. The attacks are leaving communities vulnerable, with city services and internal operations grinding to a halt.

Gunra Ransomware Targets Infrastructure with Fortinet, Schneider Electric Exploits
Gunra ransomware is on the loose, exploiting vulnerabilities in critical infrastructure from Fortinet and Schneider Electric to wreak havoc on organizations worldwide. This malicious campaign uses double-extortion tactics, combining data theft with file encryption to maximize damage.

US, South Korea Warn of Gunra Ransomware Threat
Meet Gunra, a highly sophisticated ransomware threat that's been wreaking havoc since April 2025, evolving from a Windows-targeting menace to a cross-platform attacker with a thriving commercial ecosystem. This malicious force has rapidly expanded its reach, morphing into a full-fledged ransomware-as-a-service operation by January 2026.

Hackers Exploit Private Cellular Network to Breach Polish Power Plant Controls
In a chilling breach, hackers infiltrated a Polish power plant's controls, putting the heat supply of 50,000 residents at risk, by exploiting a vulnerable private cellular network used to connect remote equipment. The intruder's route began at a nearby wind farm, where a poorly secured VPN and lack of multi-factor authentication created an easy entry point.

Hackers Exploit Private APN to Breach Polish Energy Plant
In a groundbreaking cyberattack, hackers exploited a private APN to breach a Polish energy plant, marking the first observed instance of this attack vector in a real-world scenario. CERT Polska tracked the intrusion to a compromised FortiGate VPN/firewall at a wind farm, which served as a springboard for the attack.

US, South Korea Warn of Gunra Ransomware Gang's Global Reach
US and South Korean authorities are sounding the alarm on the global threat of the Gunra Ransomware Gang, warning that this malicious group has evolved into a sophisticated ransomware-as-a-service operation. The joint advisory aims to alert network defenders to the gang's growing reach and devastating impact on organizations worldwide.

Bangladesh Bolsters Maritime Security with Saudi-led Coalition
Bangladesh is joining forces with a Saudi-led coalition to boost maritime security, with a focus on tackling the Houthi threat, while keeping the door open for collaboration with other nations, including Iran. The coalition, made up of 14 founding members, aims to enhance intelligence sharing, joint planning, and coordinated maritime operations.

NATO, AI Startup Gain Power to Track Software Vulnerabilities
The cybersecurity landscape just got a major boost: NATO's Cyber Security Centre and AI startup AISLE have joined forces with ENISA to supercharge vulnerability management, bringing the total number of CVE numbering authorities to 20. This powerful collaboration aims to revolutionize the way we track software vulnerabilities and stay one step ahead of cyber threats.

China-Linked Hackers Deploy StormEncryptor Ransomware via N-central Flaw
Meet StormEncryptor, a sneaky new ransomware strain linked to China that's leaving a trail of encrypted files and ransom notes in its wake. This malicious software, written in C++, is marked by its telltale .encrypted file extension and !!!README_FIRST!!!.txt ransom notes.

North Korean Spies Deploy Local AI Tools to Bolster Cyber Operations
North Korean spies are taking their cyber operations to the next level by deploying local AI tools, marking a significant shift from experimentation to integration. This development enables them to enhance malware development, data analysis, and attack techniques, posing a more sophisticated threat.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure
North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

TrueConf Server Flaws Targeted to Deploy PhantomCore Backdoor
Security researchers at Kaspersky have uncovered a sneaky plot by threat actor Head Mare to exploit unpatched TrueConf servers and deploy the PhantomCore backdoor to unsuspecting users. The attack relies on a two-stage vulnerability chain that allows attackers to run malicious commands with high-level privileges.

Go-Based Malware Targets macOS Crypto Wallets
Beware of a sneaky new scam targeting macOS crypto wallets: a fake CAPTCHA prompt tricks you into copying and pasting a malicious command that can download malware and compromise your wallet. One wrong click is all it takes to put your crypto at risk.

US Targets Shelbit in $6bn Crypto Sanctions Crackdown
The US Treasury Department has cracked down on crypto sanctions, targeting Shelbit, a shadowy crypto conduit, and its founder Siavash Kayvanpour in a $6bn blow to Iran's financial apparatus. This move underscores the Treasury's determination to disrupt Tehran's reliance on digital assets and secret banking networks.