Skip to content
Flash Briefing high CommunicationsCNI

Dysphoria IoT Botnet Adopts Blockchain C2 After Law Enforcement Disruption

The Dysphoria IoT botnet has re-architected its command-and-control infrastructure using Ethereum and Solana blockchain name services and victim-relay mesh networks, directly responding to the March 2026 JackSkid disruption. Researchers report over 200,000 active bots sustaining near-daily DDoS campaigns against ISPs and communications infrastructure.

Adversary Wire · · 3 min read Read more →
All briefings →
high Communications

Dysphoria IoT Botnet Adopts Blockchain C2 After Law Enforcement Disruption

The Dysphoria IoT botnet has re-architected its command-and-control infrastructure using Ethereum and Solana blockchain name services and victim-relay mesh networks, directly responding to the March 2026 JackSkid disruption. Researchers report over 200,000 active bots sustaining near-daily DDoS campaigns against ISPs and communications infrastructure.

high Finance

PolinRider: North Korea Floods npm, Go and Chrome With 108 Malicious Packages

A North Korean supply chain campaign tracked as PolinRider has distributed 162 malicious release artifacts across 108 packages in npm, Packagist, Go modules, and Chrome extensions, using VS Code auto-run tasks and blockchain-based command-and-control to deliver credential-stealing malware.

high OT / ICS

CISA Updates Iranian PLC Advisory: Scope Expands to Schneider and Siemens

CISA advisory AA26-097a, updated July 22, now confirms Iranian-affiliated actors are targeting PLCs from Schneider Electric and Siemens alongside Rockwell Automation across US water, energy, and government sectors.

high Healthcare

Craneware Breach: Hackers Steal Data from UK Billing Software Firm Serving Thousands of US Hospitals

UK healthcare billing software company Craneware has confirmed attackers exfiltrated a 'significant volume' of data including employee records, customer data, and partner information. Craneware's software is used by thousands of clinics, hospitals, and pharmacies across the United States.

All analysis →
FinanceHealthcare high

GodDamn / Hyadina -- The Beast Rebrand That Ships With a Microsoft-Signed EDR Killer

The threat actor Symantec tracks as Hyadina has run three successive ransomware families since 2022. The latest, GodDamn, arrives paired with PoisonX -- a kernel driver that carries a valid Microsoft signature and kills endpoint defences before encryption starts. This is not a BYOVD attack. The driver was built for this purpose, and then it got a legitimate certificate.

· 10 min read

Governmentcivil-society high

Star Blizzard: The FSB's Spearphishing Arm Targeting Civil Society and Government

Star Blizzard — also known as Callisto Group, COLDRIVER, and TA446 — is the FSB's persistent long-term access operation against politicians, journalists, academics, and NGOs. A deep dive into their TTPs, target profile, infrastructure, and defensive implications.

· 12 min read

telecommunicationsGovernment critical

Linen Typhoon: APT27's SharePoint Zero-Days and the Return to North American Networks

Microsoft tracks APT27 as Linen Typhoon. In July 2026, the group is exploiting two SharePoint vulnerabilities — CVE-2025-49706 and CVE-2025-49704 — against North American telecommunications and government targets. Active since 2010, this group's tools, patience, and institutional knowledge make it one of the most capable Chinese-attributed actors operating against Western targets.

· 12 min read

All commentary →
FinanceCNI

Twenty-Two Seconds: What M-Trends 2026 Says About Attacker Speed and Defender Reality

Mandiant's M-Trends 2026 report, grounded in over 500,000 hours of incident investigations, contains several findings that should recalibrate how security teams think about detection windows, initial access economics, and the real mechanics of ransomware recovery denial. The headline statistic — 22 seconds from initial access to secondary threat group handoff — isn't the most important one.

· 7 min read

technologyFinance

The Agentic Attack Surface: Your AI Assistant Is the New Endpoint

Enterprise AI assistants now hold privileged access to code repositories, cloud credentials, internal APIs, and production systems. Security teams are not monitoring them. This is a structural blind spot with material consequences — and it's arriving faster than most organisations realise.

· 8 min read

CNICommunications

The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting

Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.

· 8 min read