Nation-State Threats
20 articles RSS
Rust Security Team Warns of Targeted Social-Engineering Campaign Against Prominent Developers
The Rust security response working group and crates.io team warn that rust-lang members and popular crate owners are being lured into fake video calls to compromise their devices and accounts.
Lazarus Group Exploited Windows Kernel Zero-Day via Fake Job Offers Before Microsoft's August Patch Tuesday Fix
Check Point traced CVE-2026-68820, a WinSock kernel flaw, to a North Korean campaign deploying the FudModule rootkit against defense contractors before Microsoft patched it.
Hunt.io Finds Attacker Ran Nous Research's Hermes AI Agent Unattended Against Thailand's Finance Ministry
Researchers say a threat actor ran the open-source Hermes AI agent in unattended "YOLO" mode to probe Thailand's Ministry of Finance, deploying a web shell and staging a custom Go implant.
CISA, FBI, and NSA Warn Iran-Linked Hackers Are Breaching US Water and Energy Providers Through Exposed Industrial Controllers
A joint US advisory says Iran-linked hackers are exploiting exposed industrial controllers at water and energy providers, and disabled shutdown alarms at one breached facility.
Kaspersky Uncovers GoSerpent, a Go-Based Backdoor Spying on Southeast Asian Governments Since Late 2025
Kaspersky's GReAT team found a new Go-language RAT and toolkit hitting government and diplomatic targets in Southeast Asia, with a possible link to the TetrisPhantom espionage actor.
Iranian APT MuddyWater Deployed Chaos Ransomware as a False Flag to Disguise State-Sponsored Espionage
Rapid7 links a Chaos ransomware intrusion in early 2026 to Iranian state-linked MuddyWater, finding no encryption deployed — only credential theft and data exfiltration under ransomware cover.
Google GTIG Confirms First Criminal AI-Built Zero-Day: A 2FA Bypass That Would Have Enabled Mass Exploitation
Google's Threat Intelligence Group says a cybercrime group built a zero-day exploit using AI, marking the first confirmed case of adversaries weaponizing an LLM to discover and exploit a previously unknown vulnerability.
APT28 Hijacked 18,000 Routers Worldwide While Deploying PRISMEX Malware Against Ukraine and NATO Allies
APT28 compromised 18,000 routers across 120 countries for credential theft while deploying PRISMEX malware against Ukraine and NATO logistics targets.
Unit 42 Exposes Shadow Campaigns, a State-Aligned Espionage Operation That Breached 70 Government Organizations Across 37 Countries
Palo Alto Networks researchers reveal TGR-STA-1030, an Asia-based threat group that compromised law enforcement agencies, finance ministries, and telecoms across 37 countries while scanning government infrastructure in 155 nations.
Iran-Linked Handala Hackers Breach FBI Director Kash Patel's Personal Email as Retaliation Escalates Between Washington and Tehran
Pro-Iranian hacking group Handala published over 300 emails and personal photos from FBI Director Kash Patel's Gmail account, claiming retaliation after the DOJ seized four of the group's domains.
Suspected Chinese Hackers Breach FBI Wiretap Network Through Supply Chain Backdoor as FISA Reauthorization Debate Intensifies
U.S. investigators believe China-affiliated hackers penetrated the FBI's Digital Collection System Network, which manages FISA warrants and wiretap surveillance, by exploiting a commercial ISP vendor relationship.
FBI and CISA Warn Russian Intelligence Is Hijacking Signal and WhatsApp Accounts in Global Phishing Campaign
A joint FBI-CISA advisory says Russian-linked actors have compromised thousands of Signal and WhatsApp accounts belonging to government officials, military personnel, and journalists across multiple countries.