Tag: nation state
994 articles

Ex-NSA Chief Warns of Water System Cyber Risks
Retired General and ex-NSA chief Paul Nakasone warns that water systems are vulnerable to cyber threats, urging stricter defenses and cautioning that PLCs should be kept offline. He calls for higher standards and new partnerships to protect critical infrastructure.

Ransomware Attacks Surge 20% as New Gangs Target Finance, Healthcare
Ransomware attacks are on the rise, surging 20% in July with a staggering 799 incidents reported, with finance, healthcare, and tech industries becoming prime targets for new gangs. The alarming increase marks the second-busiest month of the year so far, with the US leading the list of targeted countries.

Microsoft 365 Phishing Campaign Hijacks Accounts to Gather Payroll, Finance Emails
Beware of a sneaky Microsoft 365 phishing campaign that's hijacking accounts to get its hands on sensitive payroll and finance emails. Hundreds of organizations across healthcare, education, and more have already been targeted in this financially driven attack.

Phisher Breaches US Defense Supplier's Microsoft 365 Account
A phishing scam led to a breach of a US defense supplier's Microsoft 365 account, exposing sensitive data including customer communications, engineering docs, and potentially export-controlled tech info. The intruder gained access to mailbox contents, but the company found no evidence that the data was copied or exfiltrated.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access
Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

TeamPCP Exploits Redis in Years-Long Supply Chain Campaign
Researchers have uncovered a clever and patient hacking group, TeamPCP, that exploited Redis servers in a years-long supply chain campaign, with roots tracing back to 2020. This group's sophisticated tactics involved compromising internet-facing infrastructure and deploying malware, showcasing a highly evolved operational tradecraft.

Houthis Launch Large-Scale Attack On Saudi-Aligned Forces In Yemen
The Houthi forces have unleashed a massive assault on Saudi-aligned troops in Yemen, launching a barrage of ballistic missiles and drones in a bold operation that targeted key enemy strongholds. Hundreds of mercenaries are reportedly dead or injured, with numerous camps and mobilizations destroyed or burned to the ground.

Australia's New Defence Chief Charts Course on Deterrence, Integration
Admiral Mark Hammond is shaking things up as the new head of the Australian Defence Force, starting with a bold move to restore "command" to the ADF's nomenclature, signaling a sharper focus on operations and warfighting readiness. This change sets the tone for what promises to be a transformative four-year tenure.

Thousands of U.S. Water System Controllers Remain Exposed Online
A recent scan revealed over 4,000 vulnerable water system controllers exposed to the public internet, including 22 in cities that have already faced cyberattacks on their water and wastewater systems. This alarming discovery highlights the urgent need for increased security measures to protect these critical systems.

PLA's Mountain Cat ATV Evolves with Expanded Doctrine
Meet the CS/VP4 "Mountain Cat" ATV, a game-changing mobility aid that's been defying expectations since 2008 with its lightweight, amphibious design and impressive capabilities. From humble beginnings as a simple, airdroppable vehicle to its current evolved form, the Mountain Cat has consistently proven itself to be "better-than-walking".

FBI, EPA Warn Water Sector of Rising Cyberattacks
Water and wastewater utilities in at least seven states have come under cyberattack, with internet-facing programmable logic controllers (PLCs) compromised, causing operations disruptions, pressure loss, and flooding. The FBI and EPA have sounded the alarm, warning of the growing threat to the water sector.

Rockwell PLCs Exposed in Water Utilities Hit by Cyberattacks
A recent scan revealed 4,407 Rockwell Automation programmable logic controllers (PLCs) exposed to the public internet, including 2,844 in the United States, leaving critical water utilities vulnerable to cyberattacks. Many of these exposed PLCs are concentrated in areas that have already reported recent cyber incidents, raising serious security concerns.

AI Assistants Expose to Recommendation Poisoning via 'Ask AI' Buttons
Beware of the sneaky "Ask AI" buttons - they can be exploited through a technique called recommendation poisoning, allowing attackers to manipulate AI assistants and turn them into persistent memory threats. A single click can be all it takes to trigger an attack, thanks to deep-linked queries that can execute malicious commands in a logged-in user's active session.

Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access
Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java into a powerful post-exploitation tool.

Zbtlink Routers Expose Unauthenticated Root Shells via Factory-Shipped Backdoor
Meet ENDLESSDOORS, a sneaky backdoor embedded in over 20 Zbtlink router models that lets hackers tap into an unauthenticated root shell, allowing them to remotely control your device. This hidden threat masquerades as a harmless Linux kernel thread, but in reality, it's a powerful tool that can phone home to Chinese command-and-control infrastructure every 35 seconds.

US Air Forces Central Gets New Commander Amid Iran War Escalation
As Lt. Gen. Daniel Lasica takes the reins of US Air Forces Central, the US military is facing a critical juncture, having already depleted nearly 80% of its THAAD interceptors and half of its Patriot missiles. With tensions escalating, Lasica assumes command at a pivotal moment.

North Korea Escalates Ballistic Missile Support for Russia Amid Ukraine Crisis
Ukraine's air defenses scored a major win against drones, downing 98 out of 115, but were left vulnerable to ballistic missiles, which slipped through completely unscathed. Meanwhile, a North Korean missile unit may soon join forces with Russia in the Voronezh region, potentially bringing 120 short-range ballistic missiles into the fray.

Senate Intel Chair Urges Treasury to Bolster OT Security with Tax Code Tweaks
The US is under attack, with recent breaches hitting community water systems in Minnesota and Iran-backed threats targeting critical infrastructure, prompting Sen. Tom Cotton to urge the Treasury Department to take action. He’s calling on Treasury Secretary Scott Bessent to use tax code tweaks to boost investment in operational technology security.

Pakistan Navy Bolsters A2/AD with Uncrewed Systems, High-Speed Missiles
The Pakistan Navy is ramping up its anti-access and area-denial capabilities with uncrewed systems and high-speed missiles, leveraging hard-won battle lessons and a surge in domestic defence production. By combining combat-proven tech with homegrown innovation, Pakistan is poised to significantly bolster its A2/AD posture.

Snowflake hacker pleads guilty to massive data extortion scheme
In a major win for justice, Connor Moucka, a Canadian national, has pleaded guilty to masterminding a massive data extortion scheme targeting Snowflake customer environments, a case that could put him behind bars for up to 32 years. The guilty plea marks a significant milestone in one of the most expansive data-theft-and-extortion campaigns of 2024.

Australia Urged to Embrace Semi-Autonomous Systems to Counter China
Imagine being able to develop and deploy game-changing products on the battlefield in just a matter of weeks - that's the power of speed, scale, and continuous adaptation that Ukraine's unique ecosystem has harnessed, and which Australia is being urged to adopt. By embracing semi-autonomous systems, Australia could revolutionize its defence capabilities and stay ahead of emerging threats.

Drone Found with Explosives Near Ukrainian Cargo Jet in Germany
German Interior Minister Armin Schuster raised the alarm after a chilling discovery: a drone loaded with explosives was found near a Ukrainian cargo jet at Leipzig/Halle Airport, marking a disturbing escalation in drone-related threats. The incident was just one of two drone-related events that occurred on the same night, leaving authorities on high alert.

Ransom Cartel Creator Sentenced to 16 Years for Global Cyberattacks
Meet Maksim Silnikau, the mastermind behind the notorious Ransom Cartel, who's now facing 16 years behind bars for masterminding a global cyberattack spree that targeted at least 18 companies and raked in millions for him. The US Department of Justice brought him to justice, sentencing him for conspiracy, wire fraud, and identity theft.

Hackers Embed khunt Toolkit in Oracle Database via SQL Injection
Security researchers have uncovered a rare and stealthy attack where hackers embedded the Khunt toolkit in an Oracle database using a SQL injection technique, highlighting a seldom-documented threat in the wild. The attack started with a simple vulnerability in an autocomplete search feature that allowed malicious input to slip through.