Communications Threat Intelligence
Threats to telecommunications carriers, ISPs, and the networks that underpin connected society.
Flash Briefings
Critical Gitea RCE Added to CISA KEV After Active Exploitation Deploys Miner Payloads
CISA added CVE-2026-60004, a critical unauthenticated-to-authenticated remote code execution flaw in self-hosted Gitea instances, to its Known Exploited Vulnerabilities catalog on August 25 after attackers were observed using it to drop cryptomining-style payloads.
Emperador Extortion Group Claims Breach of Vietnam's Largest Power Utility
A newly surfaced extortion group calling itself Emperador claims to have breached EVNHANOI, part of Vietnam Electricity, exposing over 300GB of customer and account data. The claim is unconfirmed by EVN or Vietnamese authorities.
Critical GitLab Flaw Under Active Exploitation Two Days After Disclosure
An unauthenticated, CVSS 9.4 GraphQL code-injection vulnerability in self-managed GitLab (CVE-2026-19478) is being actively exploited to delete or rewrite public repositories, with watchTowr confirming attacks within days of the emergency patch.
Microsoft Discloses Maximum-Severity CVSS 10.0 Entra ID Remote Code Execution Flaw
CVE-2026-69836, a deserialization bug in Microsoft's cloud identity platform, carried a perfect CVSS score — but Microsoft says it was never exploited and has already been fixed on its side, with no customer action required.
CISA Adds SharePoint JWT Auth Bypass CVE-2026-55040 to KEV Catalog Amid Active Exploitation
A critical authentication bypass in on-premises SharePoint Server is being actively exploited days after a public proof-of-concept, letting unauthenticated attackers impersonate any user, including administrators.
Cavern C2 Evolves: Iranian MOIS Group Adds Google Apps Script and M365 Calendar Channels
Kaspersky and Group-IB analysis reveals Iranian MOIS-linked Cavern Manticore has extended its C2 framework with DNS-directed Google Apps Script relays and a new HOLLOWGRAPH module abusing Microsoft 365 calendar events — while APT42 separately targets the nuclear energy sector with AI-accelerated TAMECAT implants.
APT36 Campaign Deploys Three-Malware Cluster Against Afghan Telecom and South Asian Infrastructure
Acronis TRU has documented three previously undisclosed malware families — PATCHCORD, SHEETCORD, and a GitHub-based C2 agent — targeting Afghan telecom providers and Indian critical infrastructure in an espionage campaign active since March 2026.
LoadMaster Under Active Exploitation: CISA Adds CVE-2026-8037 to KEV
A critical unauthenticated command injection flaw in Progress Kemp LoadMaster has been added to CISA's Known Exploited Vulnerabilities catalog after 792 confirmed exploit attempts across 41 days. With over 100,000 deployments — including at the U.S. Air Force and 80% of Fortune 500 companies — unpatched appliances represent significant exposure across finance, healthcare, and communications infrastructure.
N-able N-central Zero-Day: Unauthenticated RMM Takeover Now on CISA KEV
CVE-2026-18577 in N-able N-central gives unauthenticated attackers full administrative access to RMM consoles and every endpoint they manage. CISA has confirmed active exploitation with over half of cloud instances still unpatched.
CrowdStrike Threat Hunting 2026: AI Embedded in Adversary Operations as Exploitation Window Narrows
CrowdStrike's 2026 Threat Hunting Report, published August 3, documents a structural shift in adversarial tradecraft: AI is now a core operational capability for threat actors, China-nexus groups are exploiting critical CVEs within 24 hours of disclosure, and North Korean actors have poisoned 131 AI framework packages in the npm ecosystem.
CaptiveCrunch: Midnight Blizzard Targets Corporate Travellers via Hotel Wi-Fi
Russian threat actor Storm-2945, linked to Midnight Blizzard, has been compromising hotel and conference Wi-Fi captive portals since May 2026 to harvest Microsoft 365 credentials from corporate travellers using custom malware families CornFlake and ChocoShell.
N-able N-central Authentication Bypass: MSP Infrastructure Under Active Attack
Threat actors are actively exploiting authentication bypass vulnerabilities in N-able N-central, a remote monitoring and management platform used by managed service providers. Post-exploitation involves Cloudflare Tunnel implants for persistent access to downstream client environments.
Threat Actors Exploit N-able N-central to Mass-Pivot Across Managed Endpoints
Unknown threat actors have been exploiting an authentication bypass in N-able N-central since July 31, using the platform's own Take Control feature to deploy persistent Cloudflare tunnels across every endpoint under management.
Dysphoria IoT Botnet Adopts Blockchain C2 After Law Enforcement Disruption
The Dysphoria IoT botnet has re-architected its command-and-control infrastructure using Ethereum and Solana blockchain name services and victim-relay mesh networks, directly responding to the March 2026 JackSkid disruption. Researchers report over 200,000 active bots sustaining near-daily DDoS campaigns against ISPs and communications infrastructure.
Qilin Ransomware Actively Exploiting Palo Alto PAN-OS Authentication Bypass
Qilin affiliates are exploiting CVE-2026-0257, an authentication bypass in Palo Alto GlobalProtect, enabling rapid domain-wide ransomware encryption. Arctic Wolf confirmed multiple intrusions across enterprise sectors in June and July 2026.
PolinRider: North Korea Floods npm, Go and Chrome With 108 Malicious Packages
A North Korean supply chain campaign tracked as PolinRider has distributed 162 malicious release artifacts across 108 packages in npm, Packagist, Go modules, and Chrome extensions, using VS Code auto-run tasks and blockchain-based command-and-control to deliver credential-stealing malware.
LAUNDRY BEAR: Russia-Linked APT Exploits Zimbra for Zero-Click Email Collection
A joint NCSC and Five Eyes advisory has exposed LAUNDRY BEAR, a Russian state-supported threat actor exploiting a Zimbra Collaboration Suite XSS vulnerability to silently harvest 90 days of email from targeted accounts without any victim interaction.
SharePoint Zero-Day CVE-2026-58644 Exploited in Multi-CVE RCE Chain
A critical SharePoint deserialization zero-day (CVSS 9.8) was exploited in the wild before Microsoft's July 14 Patch Tuesday fixed it. CISA added it to the KEV catalog on July 16 alongside three companion CVEs forming an active RCE and persistence chain.
A 19-agency joint advisory from 13 countries details how FSB Center 16 has been harvesting router configurations and credentials from critical infrastructure networks globally by exploiting default SNMP community strings and unpatched Cisco Smart Install deployments.
CISA added three critical OS command injection vulnerabilities in Fortinet FortiSandbox to the KEV catalog on July 16, 2026, citing active exploitation. Federal agencies face a July 19 patch deadline; enterprise defenders running FortiSandbox on-premises, cloud, or PaaS must act immediately.
Five Eyes Alert: Russian FSB Router Campaign Targets Critical Sectors Globally
CISA, NSA, FBI, and 15 international partners have issued a joint advisory warning that Russian FSB Center 16 actors are systematically exploiting poorly configured networking devices across energy, communications, healthcare, and financial services.
Two SonicWall SMA1000 zero-days — an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) chained with post-auth code injection (CVE-2026-15410, CVSS 7.2) — are confirmed exploited in the wild. CISA added both plus two Microsoft zero-days to the KEV catalogue on July 14 with a July 17 federal patch deadline.
FSB Center 16 Named in Poland Grid Attack as UK and EU Issue First Joint Cyber Sanctions
The UK and EU have formally attributed a December 2025 cyberattack on Poland's energy grid — which came close to causing a blackout for half a million people — to Russia's FSB Center 16, imposing a landmark coordinated sanctions package targeting Moscow's broader cyber ecosystem.
GigaWiper: Iran-Nexus Destructive Backdoor Combines Wiper, Fake Ransomware, and Spyware
Microsoft and Binary Defense have separately documented GigaWiper, a modular Go-based Windows backdoor attributed to an Iran-nexus group that has been targeting Israeli organisations since October 2025. The implant combines irreversible disk wiping, fake ransomware with no recoverable key, and live spyware capabilities in a single deployable payload.
SharePoint RCE CVE-2026-45659 Exploited Despite Microsoft's 'Less Likely' Rating
CISA added CVE-2026-45659 to its KEV catalog on July 1, overriding Microsoft's own 'Exploitation Less Likely' assessment. Any authenticated SharePoint user with Site Member permissions can achieve remote code execution across SharePoint Server 2016, 2019, and Subscription Edition.
Progress Orders ShareFile Storage Zone Controllers Offline Over Active Security Threat
Progress Software has directed all ShareFile Storage Zone Controller customers to take their on-premises file-transfer infrastructure offline following a credible external security threat. No patch exists; shutdown is the only available mitigation.
GhostLock: 15-Year Linux Kernel Flaw Opens Root and Container Escape
A 15-year-old Linux kernel use-after-free vulnerability tracked as CVE-2026-43499 allows any logged-in user to gain root access on unpatched systems. Public exploit code is available and the flaw enables container escape, making patching of cloud, server, and multi-tenant Linux infrastructure an immediate priority.
Januscape (CVE-2026-53359): 16-Year-Old KVM Flaw Allows VM Escape to Host
A critical use-after-free in the Linux KVM shadow MMU lets a guest VM with root privileges escape to the host, threatening multi-tenant cloud and virtualised enterprise environments. A public PoC has been released.
CVE-2026-46242 'Bad Epoll': Linux Kernel LPE Demands Patch Urgency Across Server Fleets
A race-condition use-after-free in the Linux kernel's epoll subsystem gives any unprivileged local user a reliable path to root. A working exploit exists, kernel versions 6.4 and later are affected, and many distributions have not yet shipped the backport.
Group-IB tracked MuddyWater's Operation Olalampo campaign from January 2026, uncovering four previously undocumented malware families including CHAR — a Rust backdoor using Telegram for C2 with evidence of AI-assisted development. Targets span government, energy, and telecoms across the MENA region.
FBI and Google Dismantle NetNut: 2 Million-Device Botnet Used by Spy Groups and Ransomware Gangs
A coordinated FBI and Google-led operation has seized hundreds of domains tied to NetNut, a residential proxy network secretly built on 2 million compromised home devices. GTIG observed 316 distinct threat actor clusters using the network in a single June week — spanning state-sponsored espionage groups and ransomware operators.
SimpleHelp CVSS 10.0 Auth Bypass Exploited: Djinn Stealer Targets Cloud, AI, and Dev Credentials
Attackers are actively exploiting CVE-2026-48558, a perfect-CVSS authentication bypass in SimpleHelp RMM, to deploy a new cross-platform infostealer harvesting cloud platform credentials, AI API keys, developer tokens, and cryptocurrency wallets across Windows, macOS, and Linux.
CVE-2026-55200: Public PoC for Critical libssh2 Flaw Exposes Enterprise Infrastructure
A public proof-of-concept has been released for a CVSS 9.2 client-side flaw in libssh2 that enables zero-authentication remote code execution when connecting to a malicious or compromised SSH server. No official patched release exists yet.
CISA KEV: Lantronix EDS5000 and Ubiquiti UniFi Under Active Attack
CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on June 23, 2026, including a CVSS 9.8 code injection flaw in Lantronix EDS5000 serial device servers widely used in OT environments, and three maximum-severity flaws in Ubiquiti UniFi OS.
Squidbleed: 29-Year-Old Squid Proxy Bug Exposes Enterprise Credentials
Researchers disclosed a heap over-read in Squid proxy's FTP parser on June 23, 2026 that can silently leak cleartext HTTP requests, credentials, and session tokens from other users on the same proxy instance. The bug has existed since 1997.
DragonForce Hides C2 in Microsoft Teams: Backdoor.Turn Evades Detection for Two Months
DragonForce ransomware operators deployed a custom Go-based backdoor that tunnels command-and-control traffic through legitimate Microsoft Teams relay infrastructure, rendering traditional network monitoring ineffective.
Icarus Compromises Klue to Steal CRM Data from Salesforce Customers
A new extortion group called Icarus abused a legacy integration credential to steal OAuth tokens from Klue's integration infrastructure, enabling automated bulk extraction of Salesforce CRM data from dozens of enterprise customers — with Huntress among those confirming impact as of June 19, 2026.
NCSC Warning: Citrix NetScaler ADC and Gateway Critical Vulnerabilities Under Active Exploitation
NCSC has issued an urgent advisory on two vulnerabilities in Citrix NetScaler ADC and Gateway — CVE-2026-3055 (CVSS 9.3, unauthenticated memory exfiltration) and CVE-2026-4368 — urging UK organisations to patch immediately. Both flaws affect versions widely deployed across enterprise, healthcare, and finance environments.
Velvet Ant's Operation Highland: China-Nexus APT Backdoored Linux Auth Stack for Nearly a Decade
Sygnia's disclosure of Operation Highland reveals a China-linked threat actor that modified PAM and OpenSSH components to maintain persistent, credential-harvesting access inside isolated networks from 2016 to at least 2026.
Ivanti Sentry MDM Gateways Backdoored Within 48 Hours of Patch: CVSS 10.0 Pre-Auth RCE
A CVSS 10.0 pre-authentication OS command injection in Ivanti Sentry allows unauthenticated root-level code execution on MDM gateway appliances. Production instances were backdoored within 48 hours of the advisory. CISA has set a 14 June 2026 remediation deadline.
The researcher behind the Nightmare-Eclipse exploit series has released a seventh zero-day — RoguePlanet — exploiting a race condition in Microsoft Defender to deliver SYSTEM privileges on fully patched Windows 10 and 11, hours after June Patch Tuesday closed the previous six.
A Qilin ransomware affiliate is systematically exploiting authentication bypass vulnerabilities across Check Point, Palo Alto Networks, Fortinet, and F5 VPN infrastructure simultaneously — with a month-long zero-day window on the Check Point flaw before any patch existed.
Miasma Worm Hits 73 Microsoft GitHub Repositories, Including Core Azure SDKs
The Miasma supply chain worm -- a variant of the Mini Shai-Hulud campaign -- has compromised 73 repositories across Microsoft's GitHub organisations today, including Azure Functions, Durable Task, and several developer tooling packages. GitHub has disabled access to affected repos; credentials from the May compromise appear not to have been fully rotated.
Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.
Palo Alto Networks Unit 42 has published new research detailing how Iran-nexus APT Screening Serpens deployed six previously undocumented RAT variants against US, Israeli, and UAE targets in aerospace, defence manufacturing, and telecommunications between February and April 2026.
Android Zero-Day Exploitation Confirmed: June 2026 Bulletin Signals Commercial Spyware Activity
Google's June 2026 Android Security Bulletin confirms active exploitation of CVE-2025-48595, a local privilege escalation requiring no user interaction. CISA's simultaneous KEV addition with a three-day federal deadline points to targeted commercial surveillance tool deployment against high-value individuals.
Seqrite researchers have attributed a targeted espionage campaign against government, financial, and research organisations in the Czech Republic and Taiwan to a China-aligned threat actor using Azure Blob Storage as a covert C2 channel.
A medium-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect is being actively exploited across enterprise networks, with CISA's KEV remediation deadline falling on 1 June 2026.
ShinyHunters Publishes Charter Communications Customer Data After Vishing Compromise
ShinyHunters extortion group has published data from Charter Communications after a vishing attack compromised a Microsoft Entra account and enabled access to Charter's Salesforce environment. At least 4.9 million customer records confirmed; the group claims 42 million.
The Mini Shai-Hulud npm worm has expanded well beyond the initial TanStack compromise to breach GitHub's internal infrastructure, compromise devices at OpenAI and Mistral AI, and poison 600+ packages across 16 million weekly downloads -- before its authors open-sourced it on BreachForums.
Dutch Authorities Seize 800 Servers Tied to Russian Cyber-Attack Infrastructure
Dutch financial crime investigators arrested two suspects and seized 800 servers connected to Stark Industries, a hosting network linked to NoName057(16) DDoS campaigns against European governments and critical infrastructure.
Nightmare-Eclipse: Six Windows Zero-Days Released in Six Weeks, Three Now Weaponised in Live Attacks
A rogue researcher has published six working Windows exploit drops since April 2026. Three are confirmed active in attacks linked to Russian infrastructure, with more exploits -- including RCE -- threatened for June Patch Tuesday.
Iranian IRGC-affiliated APT Nimbus Manticore has resumed aggressive campaigns against aviation, telecommunications, and critical infrastructure in Europe and the US, deploying an undocumented AI-assisted backdoor and adopting new delivery techniques since the outbreak of the US-Iran conflict.
CISA's May 21 KEV additions confirm active exploitation of Trend Micro Apex One's directory traversal flaw -- which allows attackers to push malicious code through the defender's own endpoint management -- alongside a Langflow AI workflow vulnerability tied to MuddyWater intrusions.
An attacker who obtained push access to the Laravel-Lang GitHub organisation rewrote over 230 package versions in under 90 minutes on 22–23 May, injecting a sophisticated cloud credential stealer into one of PHP's most widely used localisation library sets.
Iranian APT MuddyWater Deploys Chaos Ransomware as False Flag to Mask Espionage
Rapid7 researchers have attributed a series of intrusions using Chaos ransomware branding to MuddyWater -- an Iranian state-sponsored group -- in a deliberate false flag operation designed to obscure intelligence collection behind the appearance of criminal extortion.
First Confirmed AI-Built Zero-Day: Google Thwarts Mass Exploitation Campaign
A threat actor used a large language model to write a working 2FA bypass exploit for a widely deployed open-source admin tool. Google's threat intelligence team detected the planned mass exploitation campaign before it launched. The code left distinctive LLM fingerprints.
Salt Typhoon Access Persists in European Telecoms More Than a Year After Initial Disclosure
Fourteen months after the US disclosed Salt Typhoon's compromise of major American carriers, intelligence assessments confirm the same group retains access inside at least two major European telecommunications networks.
Deep Analysis
UNC6671: Inside the Vishing Crew Behind BlackFile, Redact, Pink, Helix, and Falcon
A single financially motivated intrusion group has spent 2026 impersonating IT helpdesks to bypass MFA at scale, quietly cycling through five extortion brands -- and this summer set its sights on Wall Street's largest hedge funds.
Kaspersky has upgraded pro-Ukraine hacktivist group Head Mare to APT status after documenting a July 2026 campaign that chained two unpatched TrueConf videoconferencing flaws into SYSTEM-level compromise, trojanised client installers, and a Microsoft OneDrive-based command channel against Russian critical infrastructure.
Jewelbug: The China-Linked Hack-for-Hire Crew Running Espionage and Crypto Fraud From One Panel
Broadcom researchers have exposed Jewelbug, a China-based threat actor that breached 15 government webmail tenants in a single Middle Eastern intrusion while operating a parallel million-dollar cryptocurrency fraud scheme from the same control infrastructure.
OilRig (APT34): Iran's Most Persistent Cyber Espionage Operation
OilRig has maintained one of the longest continuous cyber espionage campaigns of any state-aligned threat actor, targeting energy, telecoms, government, and financial sectors across the Middle East and beyond for over a decade. A full profile of TTPs, malware ecosystem, and 2026 campaign activity.
APT34 / OilRig / Hazel Sandstorm: Inside Iran's Premier Cyber Espionage Group
APT34 has operated persistently since at least 2014, targeting energy, government, financial, and telecoms sectors across the Middle East and beyond. Known for DNS-based command-and-control, a continuously evolving malware arsenal, and deep operational persistence, the group represents Iran's most capable and consistently active espionage platform. This deep-dive covers APT34's organisational profile, TTPs, malware families, and 2025-2026 activity.
Infoblox and The Hacker News disclosed in July 2026 that Lurking Lizard, a China-based financially motivated threat group, operates an industrial-scale residential proxy business sustained by trojaned installers for legitimate software. The network has processed hundreds of millions of proxy requests and is actively rented to criminal and espionage-linked operators.
Microsoft disclosed Storm-2755 in April 2026 — a financially motivated threat actor conducting adversary-in-the-middle phishing campaigns against Canadian employees to redirect payroll deposits to attacker-controlled bank accounts. The group operates without traditional malware, using stolen session tokens to bypass MFA and modify direct deposit settings in HR portals.
DPRK IT Worker Networks: North Korea's Industrial-Scale Employment Fraud Operation
North Korea is running an industrial-scale programme in which thousands of operatives pose as freelance software developers and remote employees to generate revenue, conduct espionage, and extort companies they infiltrate. Tracked as UNC5267 and Nickel Tapestry, this threat has graduated from a revenue scheme to a direct enterprise security risk.
UAT-7810 and LapDogs: Inside China's Malware Factory for Covert Relay Infrastructure
Cisco Talos has published detailed research on UAT-7810's LapDogs campaign: a China-nexus operation building Operational Relay Box networks through compromised SOHO routers. New malware families LONGLEASH, DOGLEASH, and JARLEASH reveal how far this infrastructure-as-a-service model has matured.
Weaver Ant: The China-Nexus APT That Lived Inside a Telecom for Four Years
Sygnia's exposure of Weaver Ant reveals a China-aligned threat actor that maintained persistent access inside an Asian telecommunications provider for more than four years, using an AES-encrypted China Chopper variant, a novel in-memory web shell, and an ORB network built from compromised telco routers.
Qilin emerged in 2022 as Agenda ransomware and has evolved through a complete Rust rewrite, a defining attack on NHS blood supply services in 2024, a novel Chrome browser credential theft technique, and a 2026 VPN exploitation campaign hitting four major vendors simultaneously. This deep dive covers the full operational and technical profile.
Mustang Panda (Twill Typhoon): China's Most Prolific Espionage APT
Mustang Panda is one of the most operationally active Chinese APT groups, running continuous espionage operations since at least 2012. Known for PlugX, DLL sideloading, and a rapidly evolving implant arsenal, the group has compromised government ministries, NGOs, telecoms, and religious organisations across Southeast Asia, Europe, and beyond.
APT42: Iran's Elite Social Engineering Unit Targeting Western Officials and Research
APT42 is Iran's most operationally sophisticated espionage actor — an IRGC-IO-sponsored group that has compromised US presidential campaigns, nuclear researchers, journalists, and Western diplomats through highly targeted social engineering rather than technical exploitation.
Secret Blizzard: Inside Russia's Most Patient Cyber Espionage Operation
A deep dive into Secret Blizzard (Turla), the FSB-linked APT that has sustained global intelligence collection for over two decades — hijacking criminal infrastructure, deploying ISP-level interception against foreign embassies, and evolving the Kazuar backdoor into a resilient P2P botnet.
APT41 / Winnti / Double Dragon: China's Dual-Mandate Cyber Threat Group
APT41 operates simultaneously as a state-directed espionage actor targeting strategic industries for Beijing and a financially motivated cybercriminal enterprise — a combination unique among Chinese threat groups. A 2026 ELF cloud credential backdoor with zero VirusTotal detections is the latest evidence of the group's continued operational sophistication.
Gamaredon (Primitive Bear, Aqua Blizzard) — Russia's FSB-linked APT targeting Ukraine since 2014 — has deployed a newly modularised malware framework in 2026, using HTML smuggling and CVE-2025-8088 WinRAR exploitation for initial access. Sekoia's June 2026 analysis reveals a four-stage VBScript loader chain, Telegram-based dead drop resolvers, and five distinct payload families covering every phase of the kill chain.
MuddyWater: Iran's MOIS Cyber Arm and the Blurred Line Between Espionage and Disruption
MuddyWater — Seedworm, Static Kitten, Earth Vetala — is Iran's Ministry of Intelligence and Security cyber unit conducting sustained espionage across the Middle East, Europe, and Asia, increasingly deploying ransomware as a false flag to complicate attribution and provide cover for intelligence collection.
UNC1549: Iran's Persistent Aerospace and Defence Espionage Operation
UNC1549 — tracked as Screening Serpens and Nimbus Manticore by different intelligence vendors — is an IRGC-affiliated Iranian APT conducting sustained espionage against aerospace, defence, and telecommunications targets. Their recent expansion to European targeting, adoption of Azure and cloud C2 infrastructure, and novel AppDomainManager injection technique make them a growing concern beyond their traditional Middle East focus.
Harvester APT: South Asia Espionage Expands to Linux With Graph API Command-and-Control
The Harvester threat group — active since at least 2021 against government and telecommunications targets in South Asia — has extended its capabilities to Linux with a new GoGra backdoor variant that routes command-and-control traffic through Microsoft Outlook via the Graph API. The evolution reflects a broader shift toward cloud-service-based C2 that defeats traditional perimeter monitoring.
Silk Typhoon: China's IT Supply Chain Pivot and the Downstream Threat to Every Sector
Silk Typhoon — the Chinese state actor behind the 2021 Exchange ProxyLogon campaign and the 2024 US Treasury breach — has fundamentally changed how it operates. A deep dive into the group's shift to IT supply chain targeting and what it means for every organisation that relies on a managed service provider.
Lazarus Group / TraderTraitor: North Korea's Premier Financial Theft Operation
A comprehensive profile of Lazarus Group and its TraderTraitor subcluster -- the North Korean cyber apparatus responsible for over $6 billion in cryptocurrency theft, the largest single financial heist in history, and a growing campaign of developer-targeted supply chain intrusions.
Sandworm: Inside Russia's Most Destructive Cyber Weapon
Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.
Phantom Taurus: China's Surgical New APT Targeting Governments and Embassies Worldwide
Unit 42 researchers have unmasked Phantom Taurus, a previously undocumented Chinese state-aligned APT deploying the bespoke NET-STAR malware suite against ministries of foreign affairs, embassies, and telecoms across Africa, the Middle East, and Asia.
SHADOW-EARTH-053: Inside China's ShadowPad Espionage Campaign Against Asian Governments and NATO
A detailed examination of SHADOW-EARTH-053, a China-aligned cyberespionage cluster that has compromised government, defence, and critical infrastructure organisations across South, East, and Southeast Asia -- and at least one NATO member state -- since late 2024.
UNC3886: The China-Nexus Group That Breached All of Singapore's Major Telecoms
UNC3886, the China-linked APT responsible for zero-day exploitation of Fortinet, VMware, and Juniper systems, breached all four of Singapore's major telecommunications operators in a campaign that triggered the nation's largest ever coordinated cyber defence operation.
AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally
AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.
Volt Typhoon: The Long Game in Western Critical Infrastructure
A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.
Salt Typhoon: How China Compromised the West's Wiretap Infrastructure
The Salt Typhoon campaign against US and European telecommunications carriers was not a data breach in any conventional sense. It was a strategic intelligence operation targeting the systems governments use to conduct lawful surveillance.
Scattered Spider: When Social Engineering Becomes a Professional Discipline
The group behind the MGM Resorts and Caesars Entertainment attacks isn't a nation-state operation or a seasoned criminal enterprise. They're young, English-speaking, and they're better at manipulating people than most security teams are at stopping them.
Commentary
Banned in Name, Present in Network: What the House Salt Typhoon Probe Actually Found
The House Select Committee's August 2026 report on Salt Typhoon is not primarily about the hack. It is about how the regulatory framework meant to prevent it failed at the infrastructure level — and why rip-and-replace alone will not close the gap.
The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting
Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.
The AI Patch Wave Is Already Here -- and Defenders Are Already Behind
The NCSC warned in May that AI-accelerated vulnerability discovery would create a forced correction of technical debt. One month later, Anthropic's Project Glasswing has already found over 10,000 critical vulnerabilities in open source. The bottleneck is no longer finding bugs. It's fixing them.
A joint advisory from CISA, NCSC, and ten allied nations describes how China-linked threat actors have abandoned dedicated attack infrastructure in favour of networks of compromised home routers and IoT devices. The implication for defenders is worse than it sounds.
Nation-State Threats: What Business Leaders Get Wrong and Why It Matters
Most executives conflate nation-state cyber activity with the ransomware threat they're more familiar with. They are different in purpose, method, and the defences required. Getting this wrong shapes your entire risk posture.