threat-intel US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks The US government has disrupted a Chinese hacking platform and botnet, QTFY, used by Chinese threat actors to target military and critical infrastructure systems in the United States. The disruption targeted QScan and QTRouter, effectively rendering the platform inoperable after seizing associated domains. QTFY has bee… SecurityWeek · 3d ago High CHhackingcyberespionagebotnet
threat-intel Russian snoops add OAuth abuse to targeted phishing campaigns Google has identified three distinct groups of Russian cyber-spies – UNC6293, UNC7005, and UNC5976 – that are aggressively targeting individuals in academia, defense, government, and think tanks across Europe and the US.… The Register · Aug 21, 2026 High RUUKWEphishingoathsocial engineering
threat-intel Hackers target Ukrainian agency managing assets seized from sanctioned Russians Ukraine’s Asset Recovery and Management Agency (ARMA), responsible for seizing assets from sanctioned Russians, has been targeted by a cyberattack as it prepares to select a manager for IDS Ukraine, a major bottled water… The Record · Aug 18, 2026 High UKRUcyberattackrussiasanctions
threat-intel North Korean spies are running local LLMs to cause AI mischief North Korean intelligence operatives are leveraging locally hosted Large Language Models (LLMs) to conduct sophisticated disinformation campaigns and potentially cause broader AI-related mischief. This indicates a growin… The Register · Aug 10, 2026 Medium NOaillmcyberespionage
threat-intel Semiconductor chip titan Analog Devices reports data breach Analog Devices, a major semiconductor manufacturer, experienced a data breach resulting in the potential exfiltration of customer data. The company detected unauthorized access and is investigating, while also addressing… The Record · Jul 30, 2026 Medium semiconductorcybersecurityransomware
threat-intel Hackers used autonomous AI agent to spy on Thailand's finance ministry Hackers used an autonomous AI agent, Hermes developed by Nous Research, to conduct a cyber-espionage campaign targeting Thailand's Ministry of Finance. The agent independently explored the ministry's network, gathering i… The Record · Jul 27, 2026 High CNaicyberespionageautonomous agent
threat-intel Russian Global Webmail Espionage A persistent cyberespionage campaign, tracked as CL-STA-1114, originating from Russian threat actors (Void Blizzard and LAUNDRY BEAR) is targeting Zimbra webmail instances across various sectors, including governments, d… Palo Alto Unit 42 · Jul 23, 2026 High CVE-2025-66376NAUKCIcyberespionagephishingvulnerability
threat-intel China, India-Linked Hackers Both Targeted Same Pakistani Police Force Chinese and Indian cyber espionage groups have been quietly targeting Pakistani law enforcement networks for over two years, with a particular focus on the Balochistan Police. The intrusions aimed to access sensitive dat… SecurityWeek · Jul 10, 2026 High CHINPAcyberespionagebelt and roadgeopolitics
threat-intel In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs This week’s cybersecurity news includes a Russian government operation utilizing Cellebrite software to target an opposition activist, a Scattered Spider group breach of Transport for London, and a significant data leak… SecurityWeek · Jun 26, 2026 High RUUKINaicyberespionagesupply chain
apt Turla group adds more malware to Russia’s espionage efforts against Ukraine The Turla group, a long-standing Russian cyber-espionage team, has expanded its operations against Ukraine by deploying a new malware strain called StockStay. This malware, developed since December 2022, targets Ukrainia… The Record · Jun 26, 2026 High UKITNEcyberespionagerussiaukraine
threat-intel Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances In 2025, the Russian-aligned threat actor Gamaredon significantly ramped up its cyberespionage operations targeting Ukraine, utilizing a sophisticated and evolving toolkit. The group, linked to the FSB, employed a combin… WeLiveSecurity · Jun 25, 2026 HighCVSS 8.8 CVE-2025-8088RUcyberespionagerussiaspearphishing
threat-intel Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs Russian threat actors, including Shadow-Earth-066 (UAC-0226) and Earth Dahu (Primitive Bear, Shuckworm), are continuing to exploit a long-standing vulnerability (CVE-2025-8088) in WinRAR to conduct data theft and cyber e… Dark Reading · Jun 9, 2026 High CVE-2025-8088CVE-2023-38831RUUAwinrarvulnerabilitycyberespionage
apt Pakistan Spies on Afghan Finance Ministry With Xeno RAT A Pakistani advanced persistent threat (APT) group, identified as SideCopy and linked to the Transparent Tribe (APT 36), has been conducting espionage against Afghanistan's finance ministry since at least May 2025. The g… Dark Reading · Jun 4, 2026 High AFPKspear-phishingremote-accesspashto
threat-intel As Global Powers Explore Humanoid Robots, Cyber-Risk Looms This article discusses the emerging cybersecurity risks associated with the rapid development and deployment of embodied AI, particularly humanoid robots. The core concern is that these systems, currently being developed… Dark Reading · May 28, 2026 High CHRUCAembodied aicyberespionagerobotics
threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
threat-intel FrostyNeighbor: Fresh mischief and digital shenanigans FrostyNeighbor, a long-running cyberespionage group allegedly linked to Belarus, is continuing its operations targeting governmental organizations in Ukraine and other Eastern European countries. The latest activity invo… WeLiveSecurity · May 14, 2026 High BYPLLTcyberespionagecobalt strikepicassoloader