2026-10-09 10:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 10:50 UTC
DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide. The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct government contracts. The tools were used to scan, and in […]
P0
2026-10-09 08:36 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-09 08:50 UTC
Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure. The post US Disrupts Chinese State-Sponsored Hacking Tools appeared first on SecurityWeek.
P0
2026-10-08 21:42 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-08 21:45 UTC
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide. [...]
P0
2026-10-08 18:01 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-08 18:10 UTC
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
P0
2026-10-08 10:01 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joey Chen · indexed 2026-10-08 10:30 UTC
Cisco Talos identified an APT spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions.
P0
2026-10-05 15:52 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-10-05 16:15 UTC
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
P0
2026-10-05 13:55 UTC
Security Journalism
The Record · indexed 2026-10-05 14:15 UTC
Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.
P0
2026-10-04 07:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-04 07:45 UTC
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations. The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a
P0
2026-10-03 14:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on September 30, 2026, MI5 said the "primary purpose of the China General Technology Research Institute (CGTRI) 中国通用技术研究院 is to fund research that
P0
2026-10-03 09:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-03 10:00 UTC
Cisco Talos details UAT-11587, a China-linked group using the Antino backdoor and Microsoft 365 as cover to spy on Asian governments. Cisco Talos has been tracking a cluster of espionage activity since September 2025 that it calls UAT-11587, and by July 2026 the group had hit at least 16 government and policy organizations across eight […]
P0
2026-10-02 17:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
P0
2026-10-01 13:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-10-01 13:00 UTC
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
P15
2026-09-30 15:02 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-30 15:10 UTC
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
P0
2026-09-30 10:59 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-30 11:10 UTC
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks appeared first on SecurityWeek.
P0
2026-09-24 09:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 11:05 UTC
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read
P0
2026-09-22 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-23 07:50 UTC
DarkMe, an APT-linked VB6 RAT known for using zero day exploits, turned up in two Huntress incidents stripped down to a plain .pif infostealer malware.
P0
2026-09-18 15:24 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 15:55 UTC
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
P0
2026-09-17 19:15 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-17 19:50 UTC
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
P0
2026-09-17 10:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
P0
2026-09-17 09:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-17 09:15 UTC
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]
P0
2026-09-17 08:50 UTC
Other
ESET · indexed 2026-09-18 07:30 UTC
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
P0
2026-09-16 15:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
P15
2026-09-16 01:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-16 01:00 UTC
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
P0
2026-09-15 10:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-15 11:30 UTC
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several […]
P25
2026-09-14 14:40 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 15:35 UTC
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of
P0
2026-09-13 17:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-13 17:50 UTC
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]
P0
2026-09-13 14:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-13 14:45 UTC
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
P15
2026-09-12 11:10 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-12 11:10 UTC
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
P25
2026-09-11 20:19 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-11 20:20 UTC
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
P0
2026-09-11 14:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 15:30 UTC
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial
P0