Tag: Cyber Espionage

Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.

Mustang Panda Uses Zoho WorkDrive To Target Indian Government And Hydropower Networks

Acronis has uncovered two cyber espionage campaigns by Mustang Panda targeting Indian government and hydropower organizations using new malware and Zoho WorkDrive as a command and control channel.

Ukraine And FBI Expose Russian Intelligence Campaign Targeting Messaging App Accounts

Ukraine's SSU and FBI have uncovered a long running Russian intelligence phishing campaign targeting messaging app users, including government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States.

Chinese Speaking APT Deploys TinyRCT Backdoor In Southeast Asia Government And Critical Infrastructure Attacks

Palo Alto Networks Unit 42 has uncovered the TinyRCT backdoor used by Chinese speaking threat actor CL STA 1062 to target government organizations and critical infrastructure across Southeast Asia.

Chinese Hackers Exploited Google Workspace Rules To Steal Research And Defense Emails

Google uncovers a China linked cyber espionage campaign that abused Google Workspace rules to steal sensitive research and defense emails from organizations across United States and Canada.

China Linked SprySOCKS Backdoor Expands To Windows With Advanced Driver Based Stealth Features

Cybersecurity researchers uncover new Windows variants of China linked SprySOCKS malware featuring driver based stealth, TCP traffic diversion, and targeting organizations across multiple countries including Pakistan.

New OP-512 Threat Cluster Targets Microsoft IIS Servers With Custom Web Shell Framework

Cybersecurity researchers have uncovered OP-512, a newly identified espionage focused threat cluster targeting Microsoft IIS servers using a custom web shell framework linked with moderate to high confidence to China.

Gamaredon Exploits WinRAR Vulnerability To Deploy GammaWorm And GammaSteel Malware Against Ukraine

Russian linked hacking group Gamaredon has exploited a WinRAR vulnerability to deploy GammaWorm and GammaSteel malware targeting Ukraine, according to cybersecurity firm Sekoia.

Kimsuky Expands Cyber Arsenal With HTTPSpy, HelloDoor, And VS Code Tunnels

North Korean threat actor Kimsuky has intensified cyberattacks targeting South Korean military and corporate organizations, deploying HTTPSpy malware, HelloDoor, and abusing VS Code tunneling for covert access.

Showboat Linux Malware Targets Middle East Telecom Sector With SOCKS5 Proxy Backdoor

Cybersecurity researchers have uncovered Showboat, a Linux malware targeting a Middle East telecom provider, featuring SOCKS5 proxy capabilities and links to China affiliated threat activity clusters.

PAN OS CVE-2026-0300 Exploited In Active Attacks Enables Root Level Remote Code Execution

Palo Alto Networks reports active exploitation of PAN OS CVE-2026-0300 allowing root level RCE, with espionage activity linked to suspected state sponsored threat cluster CL STA 1132.

Chinese Silk Typhoon Hacker Xu Zewei Sacked And Extradited To United States Over COVID Research Cyberattacks

Chinese national Xu Zewei linked to Silk Typhoon hacking group has been sacked and extradited from Italy to United States over cyberattacks targeting COVID research systems and Microsoft Exchange vulnerabilities.

Lotus Wiper Malware Discovered Targeting Venezuelan Energy And Utility Systems

Researchers have identified Lotus Wiper, a destructive malware targeting Venezuela’s energy sector, capable of wiping systems, deleting recovery mechanisms, and disabling infrastructure through multi stage batch scripts and disk overwriting techniques.

Recent articles

spot_img