A China nexus threat actor is using the Antino backdoor against Asian government and policy organizations with Microsoft 365 services for command and control.
Novacare Hospitals has appointed Shakeel Akhter as Chief Information Officer, bringing extensive technology and innovation experience from Indus Hospital.
Researchers have introduced TrojPix, a new data exfiltration technique that uses video cable electromagnetic emissions to transfer information from air gapped computers without requiring hardware modifications.
Researchers have uncovered Operation DragonReturn, a phishing campaign using fake Indian tax filing utilities to deploy DcRAT and steal sensitive data from taxpayers, finance teams, and tax professionals.
Acronis has uncovered two cyber espionage campaigns by Mustang Panda targeting Indian government and hydropower organizations using new malware and Zoho WorkDrive as a command and control channel.
Ukraine's SSU and FBI have uncovered a long running Russian intelligence phishing campaign targeting messaging app users, including government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States.
Palo Alto Networks Unit 42 has uncovered the TinyRCT backdoor used by Chinese speaking threat actor CL STA 1062 to target government organizations and critical infrastructure across Southeast Asia.
Google uncovers a China linked cyber espionage campaign that abused Google Workspace rules to steal sensitive research and defense emails from organizations across United States and Canada.
Cybersecurity researchers uncover new Windows variants of China linked SprySOCKS malware featuring driver based stealth, TCP traffic diversion, and targeting organizations across multiple countries including Pakistan.
Cybersecurity researchers have uncovered OP-512, a newly identified espionage focused threat cluster targeting Microsoft IIS servers using a custom web shell framework linked with moderate to high confidence to China.
Russian linked hacking group Gamaredon has exploited a WinRAR vulnerability to deploy GammaWorm and GammaSteel malware targeting Ukraine, according to cybersecurity firm Sekoia.
North Korean threat actor Kimsuky has intensified cyberattacks targeting South Korean military and corporate organizations, deploying HTTPSpy malware, HelloDoor, and abusing VS Code tunneling for covert access.
Cybersecurity researchers have uncovered Showboat, a Linux malware targeting a Middle East telecom provider, featuring SOCKS5 proxy capabilities and links to China affiliated threat activity clusters.
Palo Alto Networks reports active exploitation of PAN OS CVE-2026-0300 allowing root level RCE, with espionage activity linked to suspected state sponsored threat cluster CL STA 1132.