North Korean hackers behind the Contagious Interview campaign compromised over 30,000 devices worldwide, targeting crypto specialists and web designers to steal $10.7 million from more than 7,000 cryptocurrency wallets.
The North Korean group WaterPlum compromised over 30,000 devices worldwide, stealing more than $10.7 million in cryptocurrency between December 2025 and July 2026.
The Pakistan-aligned threat group Transparent Tribe (APT36) has launched cyber attacks using new Rust-based backdoors and private GitHub command and control, targeting government and defense sectors in India and Afghanistan.
Iranian state-linked hackers are using the CHOSEN BRICK Windows malware to conduct surveillance on activists, dissidents, and journalists worldwide, enabling persistent spying and data collection.
US, UK, and Dutch agencies report Iran's intelligence uses Windows malware controlled via Telegram to spy on dissidents and journalists globally, targeting sensitive communications and recordings.
A mass-scanning campaign targets internet-exposed Vite development servers to steal cloud credentials linked to AWS and Azure environments.
The state-sponsored threat actor Red Heron exploited a remote code execution vulnerability in Gitea to compromise 13 organizations across six countries in a rapid, targeted campaign.
Microsoft disclosed campaigns where attackers exploited third-party email systems for large-scale financial scam phishing and used passkey-themed social engineering techniques to compromise cloud accounts.
Anthropic has disrupted a Russian state-sponsored threat actor's campaign that used AI to accelerate malware redevelopment and evade detection, marking an evolution in cyber espionage.
The China-linked threat group UNC3569 exploited a vulnerability in Sogou Input Method on Windows to deploy the GRAYRABBIT backdoor, allowing attackers full control of the affected user's machine.
A Russian-speaking threat actor used hundreds of AI agents to exploit vulnerabilities in PaperCut NG/MF servers, compromising 395 organizations worldwide and highlighting the operational risks of AI-driven cyberattacks.
Four espionage-linked threat groups use the BlueMoon exploit kit to chain Chrome and Windows vulnerabilities, with initial in-the-wild activity linked to APT31.
Attackers exploit passkey-themed social engineering to bypass MFA and leverage Microsoft Graph for access to SharePoint, OneDrive, and email data, impacting cloud and identity security.
Threat actors use invisible Unicode characters in phishing emails to evade detection by security filters, complicating phishing identification.
A Russian national has been indicted in the US for a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware, representing significant cybercrime against remote workers.
The Iranian group Nimbus Manticore uses recruiter-themed coding tests to distribute Node.js and JavaScript remote access Trojans on Linux and macOS platforms, as reported by Kaspersky.
The China-linked Fire Ant group has compromised Cisco IOS XR routers, TACACS servers, and Linux hosts to steal credentials and disable security logs, targeting critical network infrastructure.
Australian authorities arrested two men linked to the TeamPCP group known for extensive developer supply chain attacks, disrupting a significant threat actor.
The FBI disrupted two hacking platforms, QScan and QTRouter, linked to the Chinese state-sponsored group QTFY targeting critical U.S. infrastructure.
Researchers identified new malware and infrastructure linked to the Iranian state-sponsored group Nimbus Manticore, increasing cyber espionage risks.
The US Department of the Treasury imposed sanctions on Iranian cyber actors involved in attacks targeting critical infrastructure to disrupt their financial networks.
The Chinese-speaking cybercrime group UAT-10147 leverages AI to launch scaled attacks on Windows and Linux web servers worldwide and deploys advanced tools including the SPECTRE EDR bypass and Linux rootkit.
Three Russian cyber espionage clusters abuse Google OAuth flows and WhatsApp linking to hijack accounts in high-value sectors across Europe and the U.S.
SilkParasite, a newly uncovered cyber espionage campaign, targets Central Asian government bodies using seven remote access tools, five of which are previously undocumented, highlighting evolving advanced threats in the region.
Cybercriminals exploited a service provider vulnerability to steal over €30 million from Commerzbank customers, leading to arrests in Brazil and Europe.
The Jewelbug hacker group has breached government and military webmail accounts while simultaneously conducting cryptocurrency fraud, illustrating a dual-threat approach involving cyber espionage and financial crime.
North Korea's Lazarus Group exploited a recently patched Windows zero-day to deploy a new backdoor targeting defense and aerospace firms as part of Operation Dream Job.
CERT-UA reports Sandworm subgroup UAC-0145 targets Ukrainian IT workers with fake job interviews to deploy malware via a malicious VPN tool.
North Korea’s APT group Kimsuky has implemented an offline AI infrastructure that advances their phishing tactics and automates malware development by integrating AI with internal document search and malware creation tools.
Data extortion group UNC6671 is using vishing attacks to impersonate IT help desk staff and steal SaaS credentials from employees' personal phones in financial and professional services sectors.
A widespread phishing campaign uses adversary-in-the-middle techniques to compromise Microsoft 365 accounts and target payroll and finance emails.
A suspected Chinese-speaking threat actor has targeted Central Asian government organizations with OctLurk and SilkLurk malware since January 2025, impacting healthcare, research, and government sectors.
The Russian threat group Midnight Blizzard's Storm-2945 sub-cluster has compromised hospitality sign-in portals worldwide since May 2026, delivering malware and stealing traveler credentials.
Amazon attributes multiple supply chain attacks on the Debug and Chalk npm packages to North Korean state-sponsored hackers, exposing risks to open-source software security.
North Korean threat actors have launched a sophisticated macOS malvertising campaign using fake update prompts to deliver crypto-stealing malware as part of the ongoing Contagious Interview operation.
A coordinated cyberattack targeted operational technology at over 30 Minnesota community water systems in late July, causing outages and communication disruptions.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
Cl0p ransomware affiliates exploit unauthenticated remote code execution vulnerabilities in internet-facing PTC Windchill and FlexPLM systems to conduct data extortion campaigns.
North Korean group BlueNoroff uses a phishing kit impersonating Zoom and Microsoft Teams to profile cryptocurrency wallets and deliver malware via social engineering.
Attackers manipulate DNS settings on hotel and conference center Wi-Fi to redirect users to fraudulent Microsoft 365 login pages, targeting credential theft from business travelers.
CISA warns that Russian state-sponsored group Laundry Bear is exploiting a patched Zimbra zero-click vulnerability combined with phishing to steal emails from enterprise Zimbra Collaboration servers.
Russian intelligence services compromise internet-connected security cameras across Europe and Ukraine to gather military logistics intelligence, as reported by the Netherlands' AIVD and MIVD.
An advanced threat actor exploits the update mechanism of ViPNet private networking software to attack Russian government agencies, illustrating ongoing espionage.
North Korean threat actors linked to the Contagious Interview campaign employ steganography within SVG flag images in fake coding challenges to deliver multi-stage OTTERCOOKIE-aligned malware.
US prosecutors charged three Russian nationals for operating a bulletproof hosting service that enabled ransomware gangs causing over $62 million in damages globally.
Spanish Police arrested four individuals and dismantled a cybercrime network responsible for €140 million in losses through investment fraud and business email compromise attacks.
The EU and UK have imposed joint sanctions on Russian individuals and entities linked to the GRU for orchestrating widespread cyberattacks across Europe, marking the first coordinated cyber sanction package targeting Russian state-sponsored hackers.
Russian state-sponsored hackers from FSB Center 16 are exploiting poorly configured routers in critical infrastructure worldwide, heightening operational risks.
Microsoft Threat Intelligence uncovered ShinyHunters abusing OAuth in SaaS applications through vishing, supply chain attacks, and guest access misconfigurations, exposing new SaaS security risks.
Researchers reveal cyber espionage targeting Pakistani law enforcement by suspected China- and India-aligned groups between 2024 and 2026, compromising police servers with critical data.
Datadog Security Labs warns of campaigns using dormant GitHub accounts and compromised OAuth tokens to scrape corporate GitHub organizations and user data through the GitHub API. Attackers automate scraping with custom or legitimate-sounding user agents to blend in and avoid detection.
A threat actor known as O-UNC-066 is using a phishing kit to exploit Microsoft 365 users via fake Entra passkey enrollment requests, aiming at data extortion. This tactic spans multiple industry sectors and involves voice-based social engineering.
A China-linked threat actor is exploiting a vulnerability in Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. This campaign specifically targets academic researchers to gather intelligence.
The Chinese APT actor UAT-7810 is enhancing its ORB network via a new LONGLEASH malware targeting internet-facing networking devices, according to Cisco Talos. This campaign builds on the previously identified LapDogs ORB infrastructure active since mid-2025.
A China-nexus threat group is targeting Indian taxpayers and finance teams with spear-phishing emails impersonating the Income Tax Department to deploy DcRAT, a remote access trojan. This multi-stage campaign aims to steal sensitive data from compromised systems.
An Iran-linked hacker group associated with MOIS has started using a new modular command-and-control framework called Cavern to target Israeli IT providers and government organizations. This activity has been tracked by Check Point Research and highlights evolving state-sponsored cyber threats.
North Korean hackers linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across multiple platforms as part of their ongoing PolinRider operation. These malicious artifacts are being actively distributed via compromised maintainer accounts on npm, Packagist, Go, and Chrome Web Store.
The China-aligned Mustang Panda group has launched campaigns targeting Indian government networks and hydropower infrastructure using new malware and Zoho WorkDrive as a command channel. Acronis researchers detected active compromises including high-level administrative systems.
The FBI and CISA warn of a phishing campaign by Russian intelligence targeting Signal users to steal backup recovery keys, giving attackers access to historical messages. This represents a significant escalation in targeting secure communications.
Ukraine and the FBI uncovered a Russian intelligence campaign targeting messaging accounts of officials and activists across Ukraine, Europe, and the U.S. The operation involved fake support texts aimed at stealing sensitive credentials.
Microsoft has attributed the recent Mastra AI supply chain attack, compromising over 140 npm packages, to the North Korean group Sapphire Sleet, aka BlueNoroff. This highlights ongoing state-sponsored supply chain risks affecting open source ecosystems.