Advertisement
PurpleDelta: North Korean IT Workers Exploit Remote Hiring
Recorded Future exposes PurpleDelta, North Korean IT workers using sophisticated fraudulent employment, AI, and extensive vetting evasion to fund DPRK military programs.
Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations
Russian threat actors exploit a Microsoft Outlook Web Access (OWA) flaw to maintain persistent mailbox access even after passwords are changed or rotated.
Zimbra Zero-Day Exploited by Laundry Bear Against US & Ukraine
Russian state-sponsored group 'Laundry Bear' exploits a Zimbra zero-day via 'half-click' phishing, targeting US and Ukrainian entities for credential theft and backdoor…
Iran-Linked Hackers Deploy New Cavern C2 Against Israeli Targets
Iranian state-sponsored threat actors are using a novel modular C2 framework, Cavern (Cav3rn), to compromise Israeli IT and government entities.
China-Linked APT Targets Southeast Asia Critical Systems with New Backdoor
A China-linked APT group has compromised ten organizations, including state-owned entities in Southeast Asia, deploying a new backdoor.
US Targets Russian-Linked UNC5792, UNC4221 Hackers of Messaging Apps
US State Dept. offers $10M for info on Russian-linked UNC5792 & UNC4221 groups targeting WhatsApp, Signal users. Learn about nation-state threats.
Advertisement
JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices
China-linked JDY botnet now controls 1,500+ SOHO/IoT devices, actively expanding cyber reconnaissance for state-sponsored operations.
UAE Critical Infrastructure Faces Surge in Geopolitical Cyberattacks
Breach attempts against the UAE have tripled following regional tensions, specifically targeting critical infrastructure and government sectors.
DarkSword: Analyzing the GTIG iOS Full-Chain Zero-Day Exploit
Google Threat Intelligence Group uncovers DarkSword, a sophisticated iOS exploit chain leveraging multiple zero-days for state-sponsored surveillance.
Fast16 Malware: Analyzing the Precursor to Stuxnet Sabotage
Analysis of the Fast16 malware, a state-sponsored tool designed to sabotage high-precision mathematical simulations and physical computation processes.
Grinex Exchange Shuts Down After $13.74M State-Sponsored Hack
Sanctioned exchange Grinex halts operations following a $13.74M hack attributed to Western intelligence agencies. Analysis of TTPs and geopolitical impact.
Apple DarkSword Protection Expands: Mitigating CVE-2023-38604 Zero-Click Exploits
Apple expands DarkSword exploit protection to all users, enhancing defenses against state-sponsored and commercial zero-click attacks like CVE-2023-38604.
Coruna: Sophisticated iPhone Hacking Toolkit Bypasses iOS Defenses
Google researchers uncovered "Coruna," a powerful iOS exploit kit leveraging 23 vulnerabilities to silently install malware on iPhones, likely state-sponsored.
Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit
Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.
Iranian Hackers Target Kash Patel: US Offers $10M Bounty
The FBI confirms Iranian state-sponsored hackers compromised Kash Patel’s personal email, leading the U.S. to offer a $10M reward for information.
Iranian Cyber Infrastructure Hardening Ahead of Operation Epic Fury
Analysis of Iran's six-month buildup of US-based shell companies and resilient cyber infrastructure to survive kinetic strikes and maintain hacking operations.
Google Disrupts Chinese Espionage Actor UNC2814 Targeting Telecoms
Google and Mandiant disrupt UNC2814, a Chinese state-sponsored actor active since 2017, targeting 42 countries across telecom and government sectors.