<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Nation State</title><description>Cybersecurity articles tagged #Nation State on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI-Driven Cyberattack Targets APAC Government Agencies</title><link>https://runtimerebel.com/blog/ai-driven-cyberattack-targets-apac-government-agencies</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-cyberattack-targets-apac-government-agencies</guid><description>A China-linked actor reportedly deployed a near-autonomous AI framework to compromise government agencies in the APAC region, signaling a new threat landscape.</description><pubDate>Wed, 19 Aug 2026 08:27:30 GMT</pubDate><category>AI</category><category>Cyber Espionage</category><category>Nation State</category><category>APT</category><category>Asia Pacific</category></item><item><title>AI Overwhelms Patching: Rapid7 Warns of Exposure Crisis</title><link>https://runtimerebel.com/blog/ai-overwhelms-patching-rapid7-warns-of-exposure-crisis</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-overwhelms-patching-rapid7-warns-of-exposure-crisis</guid><description>Rapid7 analysis reveals an AI-driven surge in vulnerabilities is overwhelming traditional patching, requiring a shift to exposure management.</description><pubDate>Wed, 19 Aug 2026 00:41:09 GMT</pubDate><category>AI</category><category>Vulnerability Management</category><category>Patching</category><category>Ransomware</category><category>Nation State</category></item><item><title>Iran-Backed Cyberattacks Target Minnesota Water Utilities</title><link>https://runtimerebel.com/blog/iran-backed-cyberattacks-target-minnesota-water-utilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-backed-cyberattacks-target-minnesota-water-utilities</guid><description>Iran-backed threat actors targeted over 30 Minnesota water utilities, highlighting critical infrastructure vulnerabilities. Learn about TTPs and mitigation strategies.</description><pubDate>Fri, 31 Jul 2026 02:56:58 GMT</pubDate><category>Iran</category><category>Water Utilities</category><category>Critical Infrastructure</category><category>ICS OT Security</category><category>Minnesota</category><category>Nation State</category></item><item><title>Parallel APT Cyber Espionage Targets Balochistan Police</title><link>https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</link><guid isPermaLink="true">https://runtimerebel.com/blog/parallel-apt-cyber-espionage-targets-balochistan-police</guid><description>Analysis of parallel cyber espionage campaigns by China and India-linked APTs against Pakistan&apos;s Balochistan Police, detailed by SentinelOne.</description><pubDate>Fri, 10 Jul 2026 14:32:36 GMT</pubDate><category>China</category><category>India</category><category>Pakistan</category><category>Balochistan Police</category><category>APT</category><category>Cyber Espionage</category><category>SentinelOne</category><category>Nation State</category></item><item><title>Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities</title><link>https://runtimerebel.com/blog/iran-cyber-focus-expands-securing-internet-facing-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-cyber-focus-expands-securing-internet-facing-vulnerabilities</guid><description>Iranian state-sponsored cyber operations are broadening targets beyond critical infrastructure. All organizations must secure Internet-facing systems.</description><pubDate>Fri, 10 Jul 2026 03:33:44 GMT</pubDate><category>Iran</category><category>Nation State</category><category>Cyber Espionage</category><category>Vulnerability Management</category><category>Internet Facing Vulnerabilities</category></item><item><title>China&apos;s Dual-Method Cyberattack Targets Czech, Taiwan Orgs with Azureveil</title><link>https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-s-dual-method-cyberattack-targets-czech-taiwan-orgs-with-azureveil</guid><description>Nation-state actors linked to China employ dual-method spear-phishing with Azureveil malware to target Czech and Taiwan organizations for data theft.</description><pubDate>Tue, 02 Jun 2026 21:12:29 GMT</pubDate><category>China</category><category>Azureveil</category><category>Spear Phishing</category><category>Data Theft</category><category>Czech Republic</category><category>Taiwan</category><category>Nation State</category></item><item><title>GCHQ Warning: Russian Gray Zone Tactics and AI-Driven Cyber Threats</title><link>https://runtimerebel.com/blog/gchq-warning-russian-gray-zone-tactics-and-ai-driven-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/gchq-warning-russian-gray-zone-tactics-and-ai-driven-cyber-threats</guid><description>GCHQ Director Anne Keast-Butler warns that AI is an unstoppable force that Russian state-sponsored actors are leveraging for gray zone cyber operations.</description><pubDate>Wed, 27 May 2026 20:48:14 GMT</pubDate><category>GCHQ</category><category>Russia</category><category>Artificial Intelligence</category><category>Gray Zone</category><category>Nation State</category></item><item><title>FrostyNeighbor APT Targets Poland/Ukraine Gov with Spear-Phishing</title><link>https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/frostyneighbor-apt-targets-poland-ukraine-gov-with-spear-phishing</guid><description>Belarussian APT &apos;FrostyNeighbor&apos; is deploying spear-phishing campaigns against Polish and Ukrainian government entities after unique victim fingerprinting, aiming for…</description><pubDate>Thu, 14 May 2026 20:38:13 GMT</pubDate><category>FrostyNeighbor</category><category>APT</category><category>Belarus</category><category>Poland</category><category>Ukraine</category><category>Espionage</category><category>Spear Phishing</category><category>Government</category><category>Nation State</category></item><item><title>Alleged Silk Typhoon Hacker Extradited: Cyberespionage Threat</title><link>https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/alleged-silk-typhoon-hacker-extradited-cyberespionage-threat</guid><description>An alleged Silk Typhoon hacker, associated with Chinese intelligence, has been extradited to the US, highlighting persistent nation-state cyberespionage threats.</description><pubDate>Mon, 27 Apr 2026 20:30:07 GMT</pubDate><category>Silk Typhoon</category><category>Volt Typhoon</category><category>Cyber Espionage</category><category>Nation State</category><category>China</category><category>Extradition</category><category>APT</category></item><item><title>UK Cyber Chief: Russia, Iran, China Drive Top Cyber Threats</title><link>https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-cyber-chief-russia-iran-china-drive-top-cyber-threats</guid><description>NCSC warns British businesses of escalating cyber threats from state-sponsored groups in Russia, Iran, and China, urging preparedness for potential large-scale attacks.</description><pubDate>Wed, 22 Apr 2026 20:26:36 GMT</pubDate><category>UK</category><category>NCSC</category><category>Russia</category><category>Iran</category><category>China</category><category>Nation State</category><category>Cyber Warfare</category><category>Critical Infrastructure</category></item><item><title>Iran Geopolitical Tensions: Cyber Implications &amp; Preparedness</title><link>https://runtimerebel.com/blog/iran-geopolitical-tensions-cyber-implications-preparedness</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-geopolitical-tensions-cyber-implications-preparedness</guid><description>Examine the potential cybersecurity implications of escalating geopolitical tensions involving Iran, focusing on nation-state TTPs and organizational preparedness…</description><pubDate>Tue, 14 Apr 2026 20:28:00 GMT</pubDate><category>Iran</category><category>Nation State</category><category>Geopolitical Threat</category><category>Cyber Warfare</category><category>Critical Infrastructure</category><category>APT</category><category>Threat Intelligence</category></item><item><title>APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns</title><link>https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-analysis-mitigation-strategies-against-fancy-bear-campaigns</guid><description>A technical analysis of APT28&apos;s global operations, highlighting the necessity of Zero Trust and rapid patching to counter Fancy Bear threat activity.</description><pubDate>Fri, 10 Apr 2026 08:40:01 GMT</pubDate><category>APT28</category><category>Fancy Bear</category><category>Russia</category><category>Nation State</category><category>Zero Trust</category></item><item><title>APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers</title><link>https://runtimerebel.com/blog/apt28-forest-blizzard-dns-manipulation-targets-soho-routers</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-forest-blizzard-dns-manipulation-targets-soho-routers</guid><description>Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…</description><pubDate>Thu, 09 Apr 2026 04:53:01 GMT</pubDate><category>APT28</category><category>Forest Blizzard</category><category>SOHO Routers</category><category>DNS Manipulation</category><category>Credential Theft</category><category>Cyber Espionage</category><category>Nation State</category></item><item><title>Russian Hackers Exploit Routers to Steal Microsoft Office Tokens</title><link>https://runtimerebel.com/blog/russian-hackers-exploit-routers-to-steal-microsoft-office-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-hackers-exploit-routers-to-steal-microsoft-office-tokens</guid><description>Russian military intelligence-linked hackers exploited known router flaws to harvest Microsoft Office authentication tokens from over 18,000 networks, posing a…</description><pubDate>Tue, 07 Apr 2026 20:19:57 GMT</pubDate><category>Russia</category><category>Military Intelligence</category><category>Router Security</category><category>Microsoft Office</category><category>Authentication Tokens</category><category>Nation State</category><category>Espionage</category></item><item><title>AI-Enabled Cyber Attacks: Adapting Defenses for Agentic Speed</title><link>https://runtimerebel.com/blog/ai-enabled-cyber-attacks-adapting-defenses-for-agentic-speed</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-enabled-cyber-attacks-adapting-defenses-for-agentic-speed</guid><description>AI is accelerating cyber attack speed, demanding architectural shifts in defense. Understand nation-state threats and strategize for agentic attack response.</description><pubDate>Tue, 07 Apr 2026 20:19:32 GMT</pubDate><category>AI</category><category>Nation State</category><category>Cyber Warfare</category><category>Autonomous Agents</category><category>Threat Intelligence</category><category>Cybersecurity Strategy</category></item><item><title>Geopolitical Cyber Warfare: The Rise of Multipolar Tech Power</title><link>https://runtimerebel.com/blog/geopolitical-cyber-warfare-the-rise-of-multipolar-tech-power</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-cyber-warfare-the-rise-of-multipolar-tech-power</guid><description>An analysis of how rising geopolitical tensions drive state-sponsored cyber operations and the strategic fragmentation of global technology infrastructure.</description><pubDate>Fri, 27 Mar 2026 12:21:41 GMT</pubDate><category>Cyber Warfare</category><category>Geopolitics</category><category>Nation State</category><category>Strategic Intelligence</category></item><item><title>Weaponized Surveillance: How Israel Hijacked Iran&apos;s Camera Network</title><link>https://runtimerebel.com/blog/weaponized-surveillance-how-israel-hijacked-iran-s-camera-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/weaponized-surveillance-how-israel-hijacked-iran-s-camera-network</guid><description>Analysis of the compromise of Iran&apos;s surveillance infrastructure by Israel to facilitate kinetic targeting and high-value intelligence operations.</description><pubDate>Tue, 24 Mar 2026 12:24:55 GMT</pubDate><category>Iran</category><category>Israel</category><category>CCTV Security</category><category>Nation State</category><category>Surveillance Weaponization</category></item><item><title>DarkSword iPhone Exploit Kit: Zero-Day Attacks on iOS Users</title><link>https://runtimerebel.com/blog/darksword-iphone-exploit-kit-zero-day-attacks-on-ios-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/darksword-iphone-exploit-kit-zero-day-attacks-on-ios-users</guid><description>DarkSword, an advanced iPhone exploit kit, leverages multiple zero-day vulnerabilities to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine for espionage and…</description><pubDate>Thu, 19 Mar 2026 00:37:39 GMT</pubDate><category>DarkSword</category><category>iOS</category><category>iPhone</category><category>Zero-Day</category><category>Exploit Kit</category><category>Nation State</category><category>Cybercrime</category><category>Espionage</category><category>Turkey</category><category>Saudi Arabia</category><category>Malaysia</category><category>Ukraine</category></item><item><title>Iranian MOIS Collusion with Cybercriminals: Evolving Hybrid Threat</title><link>https://runtimerebel.com/blog/iranian-mois-collusion-with-cybercriminals-evolving-hybrid-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/iranian-mois-collusion-with-cybercriminals-evolving-hybrid-threat</guid><description>Iranian state-sponsored APTs, linked to MOIS, are now directly collaborating with cybercriminal organizations, escalating hybrid cyber operations. Defenders must adapt.</description><pubDate>Fri, 13 Mar 2026 00:35:19 GMT</pubDate><category>Iran</category><category>MOIS</category><category>Nation State</category><category>Cybercrime</category><category>APT</category><category>Hybrid Warfare</category><category>Threat Intelligence</category></item><item><title>Sednit/APT28 Resurfaces: Advanced Toolkit Threat Analysis</title><link>https://runtimerebel.com/blog/sednit-apt28-resurfaces-advanced-toolkit-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/sednit-apt28-resurfaces-advanced-toolkit-threat-analysis</guid><description>Russian-affiliated APT Sednit (APT28) has returned with sophisticated new malware, shifting from simple implants. Understand their updated TTPs and mitigation strategies.</description><pubDate>Tue, 10 Mar 2026 20:14:43 GMT</pubDate><category>Sednit</category><category>APT28</category><category>Russia</category><category>Nation State</category><category>Malware</category><category>Toolkit</category></item><item><title>APT36 Leverages AI for Mass-Produced Malware: Overwhelming Defenses</title><link>https://runtimerebel.com/blog/apt36-leverages-ai-for-mass-produced-malware-overwhelming-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt36-leverages-ai-for-mass-produced-malware-overwhelming-defenses</guid><description>APT36, a Pakistan-linked threat actor, is using AI &apos;vibe-coding&apos; to generate malware at scale, posing a significant challenge to conventional defenses.</description><pubDate>Fri, 06 Mar 2026 00:39:47 GMT</pubDate><category>APT36</category><category>AI Generated Malware</category><category>Vibe Coding</category><category>Nation State</category><category>Malware</category><category>Pakistan</category></item><item><title>Iran-US/Israel Cyber Conflict: Geopolitical &amp; Cyber Threat Analysis</title><link>https://runtimerebel.com/blog/iran-us-israel-cyber-conflict-geopolitical-cyber-threat-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/iran-us-israel-cyber-conflict-geopolitical-cyber-threat-analysis</guid><description>Analysis of the ongoing US-Israeli strikes on Iran, covering cyber, physical, and geopolitical dimensions.</description><pubDate>Thu, 05 Mar 2026 00:36:15 GMT</pubDate><category>Iran</category><category>US</category><category>Israel</category><category>Geopolitical Conflict</category><category>Nation State</category><category>Cyber Warfare</category></item><item><title>Geopolitical Cyber Threat: Iran Conflict Implications for Defenders</title><link>https://runtimerebel.com/blog/geopolitical-cyber-threat-iran-conflict-implications-for-defenders</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-cyber-threat-iran-conflict-implications-for-defenders</guid><description>An analysis of the ongoing cyber, physical, and geopolitical components of the US-Israeli strikes on Iran and its implications for cybersecurity professionals.</description><pubDate>Tue, 03 Mar 2026 00:37:34 GMT</pubDate><category>Iran</category><category>Geopolitics</category><category>Nation State</category><category>Cyber Conflict</category><category>Threat Intelligence</category></item><item><title>Chinese Police Use ChatGPT in Influence Operations Against Japan</title><link>https://runtimerebel.com/blog/chinese-police-use-chatgpt-in-influence-operations-against-japan</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-police-use-chatgpt-in-influence-operations-against-japan</guid><description>Chinese police reportedly used ChatGPT for politically motivated influence operations to smear Japan&apos;s PM Takaichi, highlighting AI&apos;s role in disinformation campaigns.</description><pubDate>Thu, 26 Feb 2026 00:33:49 GMT</pubDate><category>ChatGPT</category><category>Influence Operations</category><category>Disinformation</category><category>Nation State</category><category>China</category><category>Japan</category><category>AI</category><category>Cyber Espionage</category></item></channel></rss>