A China-linked threat actor is exploiting a vulnerability in Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. This campaign specifically targets academic researchers to gather intelligence.
The Chinese APT actor UAT-7810 is enhancing its ORB network via a new LONGLEASH malware targeting internet-facing networking devices, according to Cisco Talos. This campaign builds on the previously identified LapDogs ORB infrastructure active since mid-2025.
An Iran-linked hacker group associated with MOIS has started using a new modular command-and-control framework called Cavern to target Israeli IT providers and government organizations. This activity has been tracked by Check Point Research and highlights evolving state-sponsored cyber threats.
The FBI and CISA warn of a phishing campaign by Russian intelligence targeting Signal users to steal backup recovery keys, giving attackers access to historical messages. This represents a significant escalation in targeting secure communications.