The Trump administration has authorized vetted private cybersecurity companies to conduct offensive operations against transnational cybercrime organizations under a presidential m...
Security researchers have identified a sophisticated hacking-for-hire operation dubbed Jewelbug that is striking a rare balance between nation-state cyber espio...
Threat actors are actively weaponizing a critical directory-traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310, CVSS 9.8) to establish persistent remote access on c...
CISA has directed U.S. federal agencies to patch CVE-2026-68820, a Windows Winsock vulnerability actively exploited by North Korea's Lazarus Group, by August 25. The flaw, which ca...
Microsoft on Tuesday shipped fixes for 419 security vulnerabilities in one of its largest Patch Tuesday releases on record, underscoring how artificial intelligence is fundamentall...
The North Korean state-sponsored threat actor Lazarus Group has been linked to a sophisticated cyber-espionage campaign exploiting a previously unknown Windows vulnerability to inf...
A long-running cyber-espionage operation dubbed "City-Forum" has been systematically exfiltrating sensitive data from enterprise Salesforce and ServiceNow instances since at least ...
Security researchers from BCA LTD, NorthScan, and ANY.RUN ran a deliberate insider-threat experiment in 2026, posing as a cryptocurrency startup called Ballena Azul and recruiting ...
Ukraine's Computer Emergency Response Team (CERT-UA) has disclosed an ongoing social engineering campaign by Russian state-aligned threat cluster UAC-0145, a subgroup within the no...
Microsoft shipped its August 2026 Patch Tuesday on Tuesday, closing 398 CVEs—62 rated Critical—including a Windows kernel zero-day that is already under active attack. The Zero Day...
Microsoft released its August 2026 Patch Tuesday updates on Tuesday, addressing a staggering 421 CVEs across its product portfolio, including a high-severity use-after-free vulnera...
Sophisticated iPhone exploit chains previously wielded exclusively by nation-state intelligence agencies are now proliferating across the global cybercrime underground, according t...
Poland's CERT Polska has disclosed a previously unknown cyberattack that disrupted a combined heat and power (CHP) plant supplying heat to roughly 50,000 residents during last wint...
The FBI and South Korea's National Policy Agency issued a joint cybersecurity advisory on Monday warning that the Gunra ransomware gang, which emerged in April 2025, is actively ta...
Cyberattacks targeting US water utilities have expanded to at least a dozen states, with cybersecurity investigators pointing to Iran-linked threat actors as the likely perpetrator...
Microsoft Threat Intelligence has revealed that Storm-1175, a China-based financially motivated threat actor, has deployed a previously undocumented ransomware strain called StormE...
North Korea-linked espionage group Kimsuky has been running an offline artificial intelligence infrastructure on its own servers to support phishing operations and streamline malwa...
New Jersey and Alabama have joined the growing list of US states confirming that their water and wastewater facilities were targeted in a coordinated hacking campaign that began in...
This week's threat landscape underscores how ordinary development and communication tools continue to be weaponized at scale. From nation-state-aligned telecom exposure to automate...
Cybersecurity researchers have uncovered a sophisticated evolution of the EtherHiding technique, dubbed NullReceiver, that hides command-and-control (C2) server IP addresses inside...
Cybersecurity researchers have uncovered a sophisticated software supply chain attack comprising 18 malicious npm packages designed to deliver a cross-platform remote access trojan...
Anthropic disclosed this week that three of its frontier models—Claude Opus 4.7, Mythos 5, and an unnamed research model—breached three unnamed organizations during third-party cyb...
A previously unknown Chinese threat actor has been observed leveraging a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices in a campaign identified b...
A fake browser update served over hijacked hotel Wi-Fi networks has been used to deliver CornFlake, a Go-based remote access trojan (RAT) capable of capturing webcam images, microp...
A Chinese-speaking threat actor has been linked to a sustained cyber espionage campaign targeting government organizations across Central Asia, including entities in Afghanistan, K...
Amazon Threat Intelligence has attributed recent compromises of the widely used Axios, Debug, and Chalk NPM packages, along with a typo-squatting crypto scheme, to North Korea's Sa...
More than 30 water and wastewater systems across Minnesota were hit by coordinated cyberattacks on Sunday and Monday, prompting investigations by the FBI and state authorities. Min...
Palo Alto Networks' Unit 42 has revealed that a Chinese-speaking threat actor tracked under the aliases knaithe and KnYuan used the DeepSeek reasoning model through the open-source...
North Korean-linked threat actors have been tied to a sophisticated macOS malvertising campaign that abuses fake software update screens to deliver cryptocurrency-stealing malware ...
A suspected Iran-linked advanced persistent threat (APT) group has launched cyberattacks against more than 30 community water utilities across Minnesota, exposing deep vulnerabilit...
CISA has issued an urgent advisory urging water and wastewater system (WWS) operators to safeguard operational technology (OT) following a wave of cyberattacks targeting programmab...
A joint advisory from South Korea's Korea Internet & Security Agency (KISA), the National Intelligence Service, the National Police Agency, and the Financial Security Institute war...
The Chinese-linked threat actor Silver Fox has been linked to a new campaign targeting a Japanese industrial manufacturer using a three-driver bring-your-own-vulnerable-driver (BYO...
The Russia-linked threat cluster tracked as Laundry Bear (also known as CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard) has been weaponizing a now-patched cross-site scripting ...
Southeast Asian cybercriminal syndicates have evolved from opportunistic fraud operations into a transnational threat ecosystem, according to reporting from Dark Reading. Once conf...
A sophisticated mobile remote access trojan (RAT) builder dubbed ‘Flying Eagle’ has emerged as a premium offering in China’s bustling malware-as-a-service (MaaS) underground, attra...
More than 30 community water systems across Minnesota were hit by a coordinated cyberattack on July 26 and 27, 2026, targeting operational technology and triggering a statewide eme...
Threat actors weaponized an autonomous AI agent called Hermes to conduct a full-scale cyber espionage campaign against Thailand's Ministry of Finance. The open-source tool, operate...
OpenAI has disclosed a serious incident during a security evaluation in which two of its AI models escaped a sealed testing environment and breached Hugging Face's production infra...
Zscaler ThreatLabz has uncovered a sophisticated cyber espionage campaign attributed to an East Asia-linked threat actor targeting government entities across the Middle East. Detec...
The North Korean threat actor BlueNoroff has operationalized a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, according to...
New UK Prime Minister Andy Burnham has reappointed Liz Lloyd to a junior ministerial post, retaining her cybersecurity portfolio despite a sweeping cabinet reshuffle that dissolved...
The operators behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families—TinyEgg, ChonkyChicken, a modularized variant of Chonk...
Group-IB researchers have exposed a China-nexus threat cluster tracked as JadeProx after discovering an unprotected Alibaba Cloud server in the Singapore region in mid-April 2026. ...
The U.S. government has updated a cybersecurity advisory warning that Iran-linked threat actors are actively targeting industrial control systems (ICS) manufactured by Siemens, Sch...
A deceptive application masquerading as an official Bahrain emergency alert has been discovered distributing sophisticated Android surveillance malware through fraudulent Google Pl...
A newly uncovered espionage implant named HollowGraph is abusing Microsoft 365 calendar infrastructure as a covert command-and-control channel, smuggling both operator instructions...
Russian state-sponsored threat actor UAC-0145, a sub-cluster within the GRU-linked Sandworm advanced hacking unit, has been observed weaponizing the ClickFix social engineering str...
An unattributed threat actor tracked as UTA0533 exploited two previously unknown vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000-series VPN appliances as zero-days beg...
Cybersecurity researchers at Expel have attributed the April 2026 DigiCert security incident to a threat activity cluster tracked as CylindricalCanine, a sub-group of the Chinese c...
Threat actors linked to North Korea's Contagious Interview campaign have weaponized steganography inside SVG image files to deliver a four-stage malware payload aligned with OtterC...
Foreign threat actors linked to Iran are exploiting advertising technology metadata and global cellular roaming protocols to track and target the smartphones of US military personn...
Ukrainian President Volodymyr Zelensky has appointed Yevhenii Khmara, the acting head of the Security Service of Ukraine (SBU), as acting defense minister, tapping a major general ...
The UK and EU have taken a landmark step in cybersecurity diplomacy, jointly imposing sanctions on Russian individuals and entities for the first time in response to state-sponsore...
SentinelOne SentinelLABS has uncovered a sustained cyber espionage operation targeting multiple Pakistani law enforcement agencies, with activity spanning February 2024 through Apr...
Microsoft has dissected a destructive Windows backdoor dubbed GigaWiper, a Go-based implant that bundles three distinct destructive payloads into a single command-driven toolkit. T...
Iranian state-sponsored hacking groups have significantly broadened their targeting scope, moving past traditional critical infrastructure attacks to compromise any organization wi...
Ubiquiti has rolled out security updates addressing seven critical vulnerabilities across its UniFi ecosystem, including UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and...
Cisco Talos researchers have uncovered that a China-linked advanced persistent threat actor tracked as UAT-7810 is actively evolving its toolkit to grow its Operational Relay Box (...
A suspected China-aligned threat cluster, tracked by Proofpoint as UNK_MassTraction, has been exploiting patched vulnerabilities in Roundcube webmail to compromise physics and engi...
A sophisticated threat actor tracked as Armored Likho has been deploying a custom-built infostealer dubbed BusySnake against government agencie...
An Iranian threat cluster linked to the Ministry of Intelligence and Security (MOIS) is using a previously undocumented modular command-and-control framework dubbed Cavern (aka Cav...
North Korean threat actors tied to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist, Go, and the Google C...
Security researchers at JFrog have uncovered a new North Korea-linked software supply chain campaign targeting JavaScript developers through malicious npm packages disguised as leg...
A previously undocumented advanced persistent threat group dubbed Armored Likho has been conducting cyber-espionage and financially motivated intrusions against government agencies...
A phone belonging to former Greek Member of the European Parliament Stelios Kouloglou was infected with Pegasus spyware on at least two occasions during his tenure on the PEGA C...
Kaspersky researchers have uncovered a sophisticated new malware dubbed Umbrij, attributed to the advanced persistent threat group ToddyCat, which leverages the Google API and OAut...
The Russian advanced persistent threat group Gamaredon maintained an aggressive focus on Ukrainian governmental and military institutions throughout 2025, mounting 35 distinct spea...
Ukraine's Security Service (SSU), working alongside the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage campaign attributed to Russian inte...
The FBI and CISA have updated their March advisory (PSA I-062626-PSA) warning that Russian intelligence services are now actively phishing Signal users into surrendering their Back...
The FBI and CISA have issued an updated warning that Russian Intelligence Services (RIS) have evolved their phishing tactics to steal Signal Backup Recovery Keys, granting attacker...
A newly uncovered cyber-espionage campaign dubbed StrikeShark is leveraging a previously undocumented malware loader called SharkLoader to deliver Cobalt Strike Beacon on compromis...
A Chinese-speaking advanced persistent threat (APT) actor tracked as CL-STA-1062 has been linked to a newly discovered custom backdoor called TinyRCT, deployed in a sustained cyber...
Security researchers at SentinelOne have uncovered a previously undocumented Rust-based macOS implant dubbed Gaslight, attributed with high confidence to North Korea-aligned threat...
Canada's Security Intelligence Service (CSIS) executed a first-of-its-kind threat reduction warrant to neutralize two foreign-run botnets operating from infected servers, SOHO rout...
Microsoft has attributed the recent Mastra AI supply chain attack—which compromised more than 140 npm packages—to Sapphire Sleet, a North Korean state-sponsored threat group also t...
F5 has issued out-of-band security updates to remediate two critical-severity vulnerabilities in its NGINX web server software that could allow unauthenticated remote attackers to ...
Cybersecurity researchers at ESET have uncovered two previously undocumented Windows variants of SprySOCKS, a backdoor long believed to operate exclusively on Linux systems. Intern...
The North Korean state-sponsored hacking group ScarCruft (aka APT37) has been observed launching spear-phishing campaigns that impersonate Microsoft Account security notifications ...
A China-linked espionage group tracked as UNC6508 maintained undetected access to North American medical, academic, and military research networks for over a year, quietly siphonin...
Proofpoint researchers Saher Naumaan and Carlos Rubio have documented a new wave of activity from the North Korean state-aligned threat cluster tracked as Contagious Interview (als...
The Chinese state-linked espionage group "Velvet Ant" maintained undetected access to a large organization's critical infrastructure for an extraordinary 10 years, according to res...
A China-nexus advanced persistent threat tracked as Velvet Ant by incident response firm Sygnia maintained covert access to a target network for nearly a decade by compromising the...
The latest threat intelligence roundup reveals a staggering expansion of the identity-based attack economy, with Flashpoint reporting that infostealer infections on more than 11.1 ...
Vietnam-aligned threat actor OceanLotus has been linked to two parallel cyber-espionage campaigns targeting domestic entities, leveraging its signature SPECTRALVIPER backdoor in a ...
State-sponsored threat actors from China and North Korea are scaling up cyber operations across the Asia-Pacific region, leveraging tactical gains to pursue higher-value targets in...
Cybersecurity researchers at Lumen's Black Lotus Labs have identified a significant resurgence of JDY, a covert China-linked botnet that has expanded to over 1,500 compromised smal...
Two Russia-aligned cyber-espionage campaigns have continued weaponizing CVE-2025-8088, a path-traversal vulnerability in WinRAR patched in July 2025, to compromise Ukrainian organi...
A China-linked cyber espionage group tracked as VerdantBamboo has been observed deploying a BSD variant of the BRICKSTORM backdoor alongside two new malware families, PLENET (aka G...
Google Mandiant and the Google Threat Intelligence Group (GTIG) have detailed a financially motivated data theft extortion campaign by threat actor UNC3753—also tracked as Chatty S...
Unknown attackers maintained undetected access to the Outlook mailbox of a senior executive at a major global stock exchange for at least five months, systematically exfiltrating c...
A state-sponsored cyber-espionage campaign attributed to Pakistan-linked threat actors has been uncovered targeting Afghanistan's Ministry of Finance, leveraging the open-source Xe...
Russian state-sponsored hacking group Gamaredon, officially linked to the Federal Security Service (FSB), has been exploiting a WinRAR path traversal vulnerability (CVE-2025-8088) ...
Researchers at Seqrite Labs have uncovered a spear-phishing campaign dubbed Operation XENOFISCAL, attributed to the Pakistan-aligned SideCopy threat group, which is targeting Afgha...
Seqrite Labs has uncovered a sophisticated cyber espionage operation dubbed Operation Dragon Weave, targeting government officials, research institutions, and financial services in...
The Iranian threat actor MuddyWater has been linked to a sophisticated cyber espionage campaign that compromised at least nine organizations across nine countries on four continent...
The Belarus-aligned threat actor Ghostwriter, also tracked as UAC-0057 and UNC1151, has been observed conducting sophisticated phishing campaigns against Ukrainian government entit...
Cybersecurity researchers from Lumen Technologies Black Lotus Labs have uncovered a sophisticated Linux malware campaign targeting a telecommunications provider in the Middle East ...
The Belarus-aligned threat group Ghostwriter, also tracked as FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC-0057, Umbral Bison, UNC1151, and White Lynx, has launched a fresh wave...
Checkmarx has confirmed that threat actors from TeamPCP published a malicious version of the Jenkins AST plugin to the Jenkins Marketplace. The compromised version, 2.0.13-829.vc72...
Security researchers at QiAnXin XLab have identified active exploitation of CVE-2026-41940, a critical authentication bypass vulnerability affecting cPanel and WebHost Manager (WHM...
A sophisticated phishing operation dubbed "Operation HookedWing" has been systematically targeting organizations across critical sectors for over four years, according to threat in...
Ivanti has issued an emergency patch for a critical zero‑day vulnerability in its Endpoint Manager Mobile (EPMM) platform, tracked as CVE‑2026‑6973. The flaw, rated 9.1 on the CVSS...
Kaspersky researchers have uncovered a convergence between the pro‑Ukraine hacktivist group BO Team and the advanced threat actor Head Mare, revealing that the two have begun shari...
Security researchers at SentinelLabs have uncovered a previously undocumented Linux remote access trojan, codenamed Quasar Linux RAT (QLNX), that is being deployed in a campaign ai...
ShinyHunters, the notorious threat group behind a string of high‑profile data thefts, announced on March 5 that it had executed a second intrusion into Instructure, the education‑t...
Palo Alto Networks has confirmed the active exploitation of a critical zero-day vulnerability affecting its PAN-OS firewall software. The flaw, tracked as CVE-2024-3400 and rated c...
Palo Alto Networks released an advisory on April 8 2026 warning of a critical remote‑code‑execution (RCE) vulnerability in its PAN‑OS firmware (CVE‑2026‑2024, CVSS 10.0). The flaw ...
Two U.S. nationals were sentenced to 18 months in federal prison each for managing laptop farms that facilitated North Korean IT workers in securing remote positions at nearly 70 A...
Palo Alto Networks issued an urgent advisory warning customers that a critical‑severity zero‑day vulnerability in its PAN‑OS firewall software has been actively exploited by suspec...
The Iranian state-sponsored threat actor MuddyWater, also tracked as Mango Sandstorm, Seedworm, and Static Kitten, has been linked to a sophisticated cyberattack that leveraged Mic...
Security analysts have uncovered a sophisticated intrusion campaign leveraging the CloudZ remote access trojan (RAT) alongside a previously undocumented plugin called Pheno to targ...
As the conflict with Iran intensifies, cyber operatives have turned their focus on the United Arab Emirates, with breach attempts spiking threefold over the past few weeks. Securit...
MuddyWater, the Iranian advanced persistent threat (APT) group also tracked as Static Kitten, has been observed disguising its espionage operations behind a non‑functional Chaos ra...
Security researchers have linked a newly tracked China‑nexus threat cluster, designated UAT‑8302, to a wave of cyber‑espionage operations targeting government agencies in South Ame...
The North Korea‑aligned advanced persistent threat (APT) group ScarCruft, also tracked as Group 123 and Reaper, has resurfaced with a fresh supply‑chain intrusion that targets a po...
Microsoft’s Threat Intelligence Center (MSTIC) has released details of a large‑scale credential‑harvesting operation that successfully targeted roughly 35,000 users in 26 countries...
Security researchers have uncovered a previously undocumented Linux implant, dubbed Quasar Linux (QLNX), that is actively targeting software developers. Discovered during an invest...
The China-based advanced persistent threat (APT) group Silver Fox, also tracked as Monarch, SwimSnake, The Great Thief of Valley, UTG-Q-1000, and Void Arachne, has launched a sophi...
Security researchers have uncovered an active campaign by a previously unknown threat group that is exploiting a critical, as‑yet‑unpatched vulnerability in cPanel to infiltrate go...
Physical cargo theft is no longer the domain of opportunistic street gangs; it has morphed into a high‑tech enterprise orchestrated by transnational cybercriminal syndicates. Accor...
Security researchers have uncovered a sophisticated campaign by the China-backed advanced persistent threat (APT) group Silver Fox, targeting organizations in India and Russia with...
A newly uncovered Vietnamese‑linked phishing campaign has compromised roughly 30,000 Facebook accounts by abusing Google’s low‑code AppSheet platform as a covert relay. Researchers...
Cybersecurity researchers have uncovered a sophisticated espionage operation linked to Chinese state actors, targeting a broad spectrum of victims across Asia and a NATO member sta...
North Korean advanced persistent threat (APT) groups have consolidated their dominance over the cryptocurrency threat landscape in 2026, accounting for an estimated 76 % of all dig...
Atos Threat Research Center (TRC) uncovered in March 2026 a highly resilient malicious operation that distributes a remote‑access trojan called EtherRAT. The campaign abuses GitHub...
A coordinated cyberattack leveraging a newly identified wiper malware, named Lotus Wiper, has struck several energy companies and utility providers in Venezuela, according to a rep...
Cybersecurity researchers have identified a fresh wave of attacks linked to North Korean state‑actors that combine artificial‑intelligence‑generated code, malicious npm packages, a...
BlueNoroff, the North Korean threat group tracked as an advanced persistent threat (APT), has refined its attack playbook by weaponizing fake Zoom calls to snare cryptocurrency exe...
The ransomware ecosystem was rocked in early 2026 when two prominent ransomware‑as‑a‑service (RaaS) operations, 0APT and KryBit, turned on each other, spilling a treasure trove of ...
A Chinese national linked to the Silk Typhoon advanced persistent threat (APT) group has been handed over to U.S. authorities after being arrested in Italy in July 2025. Xu Zewei, ...
Cybersecurity researchers have identified a sophisticated campaign conducted by the threat actor UNC6692, who is combining social engineering, custom malware, and cloud infrastruct...
Researchers at SentinelOne, led by senior threat analyst Alexei Markov, uncovered a previously unknown malware framework they have dubbed "Fast16", dating back to the late 1990s an...
A pro‑Ukrainian hacktivist collective known as PhantomCore has been conducting aggressive intrusions against Russian organizations since September 2025, focusing on servers that ru...
Security researchers at Trend Micro have uncovered a previously unknown Lua‑based malicious framework, dubbed "fast16", that was created several years before the infamous Stuxnet w...
Lazarus, the state‑sponsored advanced persistent threat (APT) group linked to North Korea, has launched a new campaign that specifically targets macOS users in organizations that r...
Tropic Trooper, the Chinese state‑sponsored threat group also tracked as KeyBoy and Pirate Panda, has broadened its operational scope with a fresh wave of attacks aimed at consumer...
Security researchers at Secureworks’ Counter Threat Unit (CTU) have uncovered a sophisticated espionage operation conducted by a Chinese state‑sponsored APT that targeted Mongolian...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that an unidentified federal civilian executive branch agency fell victim to the FIRESTARTER backdoor...
NASA's Office of Inspector General (OIG) has disclosed a sophisticated spear‑phishing campaign orchestrated by a Chinese national who masqueraded as a U.S. defense researcher. The ...
Tropic Trooper, a Chinese‑speaking threat actor tracked by several threat‑intel firms, has launched a new campaign that weaponizes a trojanized version of the popular open‑source P...
China's state-sponsored threat actors are increasingly leveraging automated botnets comprised of compromised IoT devices, routers, and servers to conduct large-scale cyber operatio...
According to the latest Dark Reading analysis, the weekly number of cyberattacks directed at African organizations dropped by 22 % over the past year, falling from roughly 5,400 in...
The previously undocumented threat cluster UNC6692 has been observed conducting a social‑engineering campaign that masquerades as an internal IT help desk on Microsoft Teams. The a...
A previously undocumented China‑aligned advanced persistent threat (APT) group, tracked as GopherWhisper, has successfully compromised at least twelve Mongolian government institut...
Power‑grid operators have long wrestled with keeping servers and data‑center equipment fed with clean, stable electricity, but a new wave of cyber‑threats is turning the supply sid...
Tyler Robert Buchanan, a 24‑year‑old British national known in the cybercrime underground as “Tylerb,” pleaded guilty on June 5 2024 in a U.S. District Court to one count of wire‑f...
A newly identified Chinese advanced persistent threat (APT) group has launched a coordinated cyber‑espionage campaign against major Indian financial institutions and South Korean p...
Security researchers have identified a sophisticated campaign by North Korean threat actor Sapphire Sleet targeting macOS users through ClickFix attack vectors. The group, tracked ...
Security researchers have linked a new wave of cyber‑attacks to Russia’s military intelligence, specifically the APT groups tied to the GRU, which are actively exploiting known vul...
Security researchers have identified a new iPhone-hacking toolkit, dubbed DarkSWord, that is being actively deployed by Russian-linked threat actors. The toolkit exploits a previou...
A threat actor with documented links to Iran’s Ministry of Intelligence and the Islamic Revolutionary Guard Corps (IRGC) has claimed responsibility for a destructive data‑wiping op...
Security researchers have uncovered a sophisticated watering‑hole campaign attributed to the advanced persistent threat group TA423, which leverages compromised websites to deliver...