Transport Threat Intelligence
Cyber threats facing aviation, rail, maritime logistics, freight, and transport infrastructure operators.
Flash Briefings
Gunra Ransomware Actors Hit Healthcare, Finance, and Critical Infrastructure Across Five Continents
CISA, the FBI, NSA, and South Korean authorities have issued a joint advisory on Gunra, a Conti-derived ransomware-as-a-service operation that has compromised organisations across healthcare, financial services, manufacturing, transportation, and government sectors globally.
CVE-2026-59310: VMware vCenter Exploited Globally Five Days After Disclosure
A critical directory-traversal vulnerability in VMware vCenter was patched July 29 and exploited within five days -- an APT actor has compromised 361 servers across 47 countries, deploying reverse shell infrastructure via a malicious cron job.
Lazarus Burned a Windows Kernel Zero-Day for Six Weeks Targeting Defence and Aerospace
CVE-2026-68820, a use-after-free in Windows AFD.sys patched on August 11 Patch Tuesday, was actively exploited by North Korea's Lazarus Group since early July in a fresh Operation Dream Job wave targeting defence, aerospace, aviation, and UAV firms across Europe and India. The attack chain drops the FudModule rootkit and a newly identified modular backdoor named Troy.
CrowdStrike Threat Hunting 2026: AI Embedded in Adversary Operations as Exploitation Window Narrows
CrowdStrike's 2026 Threat Hunting Report, published August 3, documents a structural shift in adversarial tradecraft: AI is now a core operational capability for threat actors, China-nexus groups are exploiting critical CVEs within 24 hours of disclosure, and North Korean actors have poisoned 131 AI framework packages in the npm ecosystem.
Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.
A medium-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect is being actively exploited across enterprise networks, with CISA's KEV remediation deadline falling on 1 June 2026.
Iranian IRGC-affiliated APT Nimbus Manticore has resumed aggressive campaigns against aviation, telecommunications, and critical infrastructure in Europe and the US, deploying an undocumented AI-assisted backdoor and adopting new delivery techniques since the outbreak of the US-Iran conflict.
Cl0p Exploiting File Transfer Vulnerabilities Across Transport and Logistics Sector
The Cl0p ransomware group is mass-exploiting a newly disclosed vulnerability in a widely used managed file transfer platform. Several European freight and logistics operators have been impacted, with customs and supply chain data exfiltrated.
Deep Analysis
Kaspersky has upgraded pro-Ukraine hacktivist group Head Mare to APT status after documenting a July 2026 campaign that chained two unpatched TrueConf videoconferencing flaws into SYSTEM-level compromise, trojanised client installers, and a Microsoft OneDrive-based command channel against Russian critical infrastructure.
Pioneer Kitten: How Iran's IRGC Became an Access Broker for Ransomware Gangs
Pioneer Kitten — tracked as Fox Kitten, Lemon Sandstorm, and UNC757 — is an Iranian state-sponsored group that exploits network perimeter devices to establish persistent access, then sells that access to criminal ransomware affiliates. This deep dive examines the group's dual mandate, tradecraft, and what a compromise looks like in practice.
Mustang Panda (Twill Typhoon): China's Most Prolific Espionage APT
Mustang Panda is one of the most operationally active Chinese APT groups, running continuous espionage operations since at least 2012. Known for PlugX, DLL sideloading, and a rapidly evolving implant arsenal, the group has compromised government ministries, NGOs, telecoms, and religious organisations across Southeast Asia, Europe, and beyond.
Silk Typhoon: China's IT Supply Chain Pivot and the Downstream Threat to Every Sector
Silk Typhoon — the Chinese state actor behind the 2021 Exchange ProxyLogon campaign and the 2024 US Treasury breach — has fundamentally changed how it operates. A deep dive into the group's shift to IT supply chain targeting and what it means for every organisation that relies on a managed service provider.
Sandworm: Inside Russia's Most Destructive Cyber Weapon
Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.
Launched in mid-2025 by a disgruntled Qilin affiliate, The Gentlemen ransomware-as-a-service operation reached third place globally in Q1 2026 through pre-stockpiled FortiGate access, a 90% affiliate commission, and a deliberate strategy to target non-US markets that most groups neglect.
AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally
AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.
Volt Typhoon: The Long Game in Western Critical Infrastructure
A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.
Commentary
The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting
Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.
The Real Cost of a Critical Infrastructure Attack: Beyond the Ransom
When a critical infrastructure operator is hit, the ransom payment is usually the smallest line on the eventual damage assessment. The true costs -- operational, regulatory, reputational, and systemic -- are far larger and far longer-lasting.