{"generated":"2026-07-21T03:41:44.347Z","lookbackDays":90,"feeds":27,"okFeeds":27,"count":34,"feedsStatus":[{"name":"ACSC (Australia)","ok":true,"items":4,"kept":0},{"name":"BleepingComputer","ok":true,"items":15,"kept":1},{"name":"CERT-EU","ok":true,"items":10,"kept":0},{"name":"Check Point Research","ok":true,"items":15,"kept":1},{"name":"CISA Advisories","ok":true,"items":30,"kept":2},{"name":"Cisco Talos","ok":true,"items":15,"kept":1},{"name":"CrowdStrike Blog","ok":true,"items":10,"kept":0},{"name":"CyberScoop","ok":true,"items":10,"kept":0},{"name":"Dark Reading","ok":true,"items":50,"kept":1},{"name":"ESET WeLiveSecurity","ok":true,"items":100,"kept":3},{"name":"Fortinet Threat Research","ok":true,"items":10,"kept":0},{"name":"Help Net Security","ok":true,"items":10,"kept":1},{"name":"JPCERT/CC","ok":true,"items":23,"kept":0},{"name":"Kaspersky Securelist","ok":true,"items":10,"kept":1},{"name":"Krebs on Security","ok":true,"items":10,"kept":1},{"name":"Microsoft Security Blog","ok":true,"items":10,"kept":0},{"name":"NCSC UK","ok":true,"items":20,"kept":4},{"name":"Palo Alto Unit 42","ok":true,"items":15,"kept":0},{"name":"Proofpoint Threat Insight","ok":true,"items":10,"kept":7},{"name":"SANS Internet Storm Center","ok":true,"items":10,"kept":0},{"name":"SecurityWeek","ok":true,"items":10,"kept":0},{"name":"SentinelOne Blog","ok":true,"items":10,"kept":0},{"name":"The Hacker News","ok":true,"items":50,"kept":7},{"name":"The Record (Recorded Future)","ok":true,"items":5,"kept":0},{"name":"The Register — Security","ok":true,"items":50,"kept":3},{"name":"Unit 42 — Threat Research","ok":true,"items":15,"kept":0},{"name":"WIRED — Security","ok":true,"items":20,"kept":2}],"items":[{"title":"Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service","url":"https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service","domain":"proofpoint.com","seendate":"20260720201028","sourceCountry":"Proofpoint Threat Insight","c":"CN","relationship":"sponsor","confidence":"medium","evidence":"nbsp; Between late April and early June 2026, Proofpoint observed&nbsp;four campaigns&nbsp;attributed to Chinese-speaking cybercrime actor&nbsp;TA4922&nbsp;using Cruciferra to ultimately deliver AsyncRAT. Campaigns in","activityType":"cybercrime","summary":"Key Findings&nbsp; Cruciferra is a sophisticated crypter service used by multiple unrelated cybercriminal threat clusters.&nbsp;&nbsp; It has been observed delivering a wide range of remote access trojans and infostealers.&nbsp; The malware employs extensive defense-evasion capabilities and over 90 variations of cryptographic functions to obfuscate its data and payloads.&nbsp; Proofpoint identified both production and apparent testing variants, indicating the service is under active development."},{"title":"HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel","url":"https://www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/","domain":"helpnetsecurity.com","seendate":"20260720172015","sourceCountry":"Help Net Security","c":"IR","relationship":"sponsor","confidence":"medium","evidence":"ide appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB calls HOLLOWGRAPH, is one component of a bigger toolkit t","activityType":"espionage","summary":"Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB calls HOLLOWGRAPH, is one component of a bigger toolkit the company links with high confidence to the Cavern backdoor framework, a modular espionage toolkit built from separate plugins that each handle a different task, prev"},{"title":"Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine","url":"https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html","domain":"thehackernews.com","seendate":"20260720121339","sourceCountry":"The Hacker News","c":"RU","relationship":"sponsor","confidence":"medium","evidence":"Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine. At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and U","activityType":"attributed-activity","summary":"At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence"},{"title":"Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs","url":"https://thehackernews.com/2026/07/russian-speaking-hacker-uses-google.html","domain":"thehackernews.com","seendate":"20260720090711","sourceCountry":"The Hacker News","c":"RU","relationship":"sponsor","confidence":"high","evidence":"Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs. A solo Russian-spea","activityType":"cyber-activity","summary":"A solo Russian-speaking threat actor known as \"bandcampro\" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential"},{"title":"Hackers abuse ViPNet software to target Russian govt agencies","url":"https://www.bleepingcomputer.com/news/security/hackers-abuse-vipnet-software-to-target-russian-govt-agencies/","domain":"bleepingcomputer.com","seendate":"20260719142346","sourceCountry":"BleepingComputer","c":"RU","relationship":"victim","confidence":"high","evidence":"Hackers abuse ViPNet software to target Russian govt agencies. An advanced threat actor is abusing the update mechanism for the ViPNet private networkin","activityType":"cyber-activity","summary":"An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]"},{"title":"UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware","url":"https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html","domain":"thehackernews.com","seendate":"20260719133055","sourceCountry":"The Hacker News","c":"RU","relationship":"sponsor","confidence":"medium","evidence":"y Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's","activityType":"cyber-activity","summary":"Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's"},{"title":"Your Period Tracker Is (Probably) Spying on You","url":"https://www.wired.com/story/security-news-this-week-your-period-tracker-is-probably-spying-on-you/","domain":"wired.com","seendate":"20260718103000","sourceCountry":"WIRED — Security","c":"RU","relationship":"sponsor","confidence":"medium","evidence":"Your Period Tracker Is (Probably) Spying on You. Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach ex","activityType":"cyber-activity","summary":"Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more."},{"title":"GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft","url":"https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html","domain":"thehackernews.com","seendate":"20260717163916","sourceCountry":"The Hacker News","c":"CN","relationship":"sponsor","confidence":"medium","evidence":"ribed the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using","activityType":"cyber-activity","summary":"Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using"},{"title":"Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images","url":"https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html","domain":"thehackernews.com","seendate":"20260717134856","sourceCountry":"The Hacker News","c":"KP","relationship":"sponsor","confidence":"medium","evidence":"Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images. North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in","activityType":"cyber-activity","summary":"North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. \"Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser credential and crypto wallet stealer, a file stealer, a"},{"title":"Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man","url":"https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html","domain":"thehackernews.com","seendate":"20260717105331","sourceCountry":"The Hacker News","c":"RU","relationship":"criminal","confidence":"medium","evidence":"Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man. Armenia has held a Russian tourist name","activityType":"cybercrime","summary":"Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov. His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan's Zvartnots airport, held up a phone with a photo of him off his VKontakte page, and walked him into a side"},{"title":"Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor","url":"https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html","domain":"thehackernews.com","seendate":"20260716111723","sourceCountry":"The Hacker News","c":"CN","relationship":"sponsor","confidence":"medium","evidence":"ces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor. An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along","activityType":"cyber-activity","summary":"An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm, along with a previously unreported backdoor dubbed Stupig. Daxin (\"srt64.sys\"), as the kernel-mode rootkit is referred to, was first documented by Broadcom-owned Symantec in March 2022, with evidence indicating its use in targeted attacks aimed"},{"title":"UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign","url":"https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/","domain":"blog.talosintelligence.com","seendate":"20260716100001","sourceCountry":"Cisco Talos","c":"RU","relationship":"criminal","confidence":"medium","evidence":"WLDR C2 implant in financially motivated campaign. Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users","activityType":"cybercrime","summary":"Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025."},{"title":"'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes","url":"https://www.theregister.com/research/2026/07/14/the-bots-are-alive-jailbroken-gemini-spun-up-new-c2-server-for-russian-fraudster-in-just-6-minutes/5270131","domain":"theregister.com","seendate":"20260714121500","sourceCountry":"The Register — Security","c":"RU","relationship":"criminal","confidence":"medium","evidence":"'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes. Human did 10% of the job, AI did 90%","activityType":"cyber-activity","summary":"Human did 10% of the job, AI did 90%"},{"title":"Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a","domain":"cisa.gov","seendate":"20260713120000","sourceCountry":"CISA Advisories","c":"CN","relationship":"sponsor","confidence":"medium","evidence":"-0171 CVE-2008-4128 13 Many of these TTPs overlap with activity by other malicious cyber actors, such as Salt Typhoon . Even though this CSA focuses on Russian FSB Center 16 cyber activity, the mitigations below should det","activityType":"exploitation","summary":"Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Pub"},{"title":"Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting","url":"https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a","domain":"cisa.gov","seendate":"20260713120000","sourceCountry":"CISA Advisories","c":"RU","relationship":"sponsor","confidence":"high","evidence":"Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting. Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerabl","activityType":"exploitation","summary":"Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Pub"},{"title":"UK and Allies urge critical sectors to improve defences against Russian intelligence targeting","url":"https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting","domain":"ncsc.gov.uk","seendate":"20260713120000","sourceCountry":"NCSC UK","c":"RU","relationship":"victim","confidence":"high","evidence":"UK and Allies urge critical sectors to improve defences against Russian intelligence targeting. New advisory highlights Russian state cyber actors’ global exploitation of poorl","activityType":"cyber-activity","summary":"New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers"},{"title":"Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure","url":"https://www.darkreading.com/cyber-risk/iran-cyber-crosshairs-beyond-critical-infrastructure","domain":"darkreading.com","seendate":"20260709203200","sourceCountry":"Dark Reading","c":"IR","relationship":"context","confidence":"low","evidence":"Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure. Obscurity isn't a defense. If your company has","activityType":"exploitation","summary":"Obscurity isn't a defense. If your company has any Internet-facing vulnerability, you're at risk from multiple threats."},{"title":"China tells devs to ditch Claude Code over 'backdoor code' fears","url":"https://www.theregister.com/security/2026/07/08/china-ditch-older-claude-versions-with-backdoor-code/5268371","domain":"theregister.com","seendate":"20260708135807","sourceCountry":"The Register — Security","c":"CN","relationship":"criminal","confidence":"medium","evidence":"China tells devs to ditch Claude Code over 'backdoor code' fears. National vulnerability database claims monit","activityType":"exploitation","summary":"National vulnerability database claims monitoring mechanism can forward Chinese users' data to remote servers"},{"title":"What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out","url":"https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/","domain":"wired.com","seendate":"20260708100000","sourceCountry":"WIRED — Security","c":"CN","relationship":"sponsor","confidence":"medium","evidence":"spitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario.","activityType":"cyber-activity","summary":"Burst water mains. Evacuated hospitals. In a closed-door simulation, insurers played out their response to a mass disruption by China’s Volt Typhoon hackers—and found a nightmare scenario."},{"title":"One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation","url":"https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation","domain":"proofpoint.com","seendate":"20260707154712","sourceCountry":"Proofpoint Threat Insight","c":"CN","relationship":"sponsor","confidence":"medium","evidence":"al TA designation. Key Findings Since May 2026, Proofpoint Threat Research has been tracking a suspected China-aligned threat cluster named UNK_MassTraction exploiting Roundcube mailservers belonging to the physics","activityType":"espionage","summary":"Analyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. Key Findings Since May 2026, Proofpoint Threat Research has been tracking a suspected China-aligned threat cluster named UNK_MassTraction exploiting Roundcube mailservers belonging to the physics and engineering departments of US and Canadian universities. The campaigns exploit multiple n-day vulnerabilities i"},{"title":"Spain collars alleged pro-Russia hacktivist after FBI tip-off","url":"https://www.theregister.com/security/2026/07/07/alleged-pro-russia-hacktivist-arrested-in-palencia/5267569","domain":"theregister.com","seendate":"20260707103050","sourceCountry":"The Register — Security","c":"RU","relationship":"sponsor","confidence":"high","evidence":"Spain collars alleged pro-Russia hacktivist after FBI tip-off. Palencia man suspected of links to CARR, Z-Pentest, and NoName057(16), plu","activityType":"cyber-activity","summary":"Palencia man suspected of links to CARR, Z-Pentest, and NoName057(16), plus helping a Ukrainian hacker flee to Russia"},{"title":"Cavern Manticore: Exposing Iran-Linked Modular C2 Framework","url":"https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/","domain":"research.checkpoint.com","seendate":"20260706122502","sourceCountry":"Check Point Research","c":"IR","relationship":"sponsor","confidence":"high","evidence":"Cavern Manticore: Exposing Iran-Linked Modular C2 Framework. Key Points Introduction Since early 2026, Check Point Research (CPR) has tr","activityType":"cyber-activity","summary":"Key Points Introduction Since early 2026, Check Point Research (CPR) has tracked a new modular command-and-control framework used by Cavern Manticore, an Iran-nexus APT group primarily targeting Israeli organizations, with a focus on IT providers, and government sectors. Cavern Manticore is an Iran MOIS (Ministry of Intelligence and Security)-linked actor, with links to the OilRig […] The post Cavern Manticore: Exposing Iran-Linked Modular C2 Framework appeared first on Check Point Research ."},{"title":"Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign","url":"https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/","domain":"securelist.com","seendate":"20260703100033","sourceCountry":"Kaspersky Securelist","c":"RU","relationship":"victim","confidence":"medium","evidence":"ishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.","activityType":"cyber-activity","summary":"An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil."},{"title":"Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances","url":"https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/","domain":"welivesecurity.com","seendate":"20260625084500","sourceCountry":"ESET WeLiveSecurity","c":"RU","relationship":"sponsor","confidence":"high","evidence":"Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances. ESET Research analyzes Gamaredon’s","activityType":"attributed-activity","summary":"ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data"},{"title":"Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation","url":"https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation","domain":"proofpoint.com","seendate":"20260617175958","sourceCountry":"Proofpoint Threat Insight","c":"RU","relationship":"criminal","confidence":"medium","evidence":"Public reporting&nbsp;has&nbsp;associated&nbsp;TA569 /&nbsp;SocGholish&nbsp;with Evil Corp, a notorious Russian cybercriminal group whose members have been&nbsp;sanctioned&nbsp;for cyber-enabled criminal activity&nbs","activityType":"cybercrime","summary":"Key Findings&nbsp; Global law enforcement and private sector partners worked to disrupt activity related to TA569, as part of Operation Endgame.&nbsp; TA569 is one of the most prominent&nbsp;cybercriminal&nbsp;threat groups in Proofpoint threat data, which our researchers have tracked since 2018.&nbsp;&nbsp; TA569’s&nbsp;SocGholish&nbsp;inject activity has been linked to major ransomware families and criminal syndicates.&nbsp; The&nbsp;law enforcement&nbsp;actions included disrupting their serve"},{"title":"Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency","url":"https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal","domain":"proofpoint.com","seendate":"20260608151153","sourceCountry":"Proofpoint Threat Insight","c":"KP","relationship":"sponsor","confidence":"medium","evidence":"reat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor conducting phishing campaigns using developer role recruitment or code review themes to tar","activityType":"espionage","summary":"By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor conducting phishing campaigns using developer role recruitment or code review themes to targets in close to 100 organizations in finance, cryptocurrency, education, technology, and several other sectors. Proofpoint clusters this activity under the name UNK_DeadDrop. The infection chain begins with emails containing"},{"title":"TA4922: The Suspected Chinese Crime Group is Going Global","url":"https://www.proofpoint.com/us/blog/threat-insight/ta4922-suspected-chinese-crime-group-going-global","domain":"proofpoint.com","seendate":"20260603170632","sourceCountry":"Proofpoint Threat Insight","c":"CN","relationship":"sponsor","confidence":"high","evidence":"TA4922: The Suspected Chinese Crime Group is Going Global. Key Findings:&nbsp; TA4922 is a highly sophisticated threat actor&nbsp;demo","activityType":"cybercrime","summary":"Key Findings:&nbsp; TA4922 is a highly sophisticated threat actor&nbsp;demonstrating&nbsp;a rapid operational tempo and continually evolving malware arsenal.&nbsp; The group has been&nbsp;observed&nbsp;using multiple malware families including Atlas RAT,&nbsp;RomulusLoader,&nbsp;SilentRunLoader, and&nbsp;ValleyRAT&nbsp;(Winos4.0), among others.&nbsp; TA4922 relies on localized lures often themed around HR, payroll, tax, and invoicing to convince targets across multiple regions. In recent months,"},{"title":"More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild","url":"https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild","domain":"proofpoint.com","seendate":"20260527150000","sourceCountry":"Proofpoint Threat Insight","c":"RU","relationship":"sponsor","confidence":"medium","evidence":"OLE document processing. Within 24 hours of public disclosure in January 2026, Russia-linked&nbsp;TA422 (APT28)&nbsp;weaponized the flaw in malicious RTF files targeting Ukrainian government agencies and European de","activityType":"cybercrime","summary":"Executive Summary The CVE Landscape Has Changed. The Threat Actors Haven't.&nbsp; Proofpoint's dual telemetry streams — targeted&nbsp;attack&nbsp;visibility covering hundreds of millions of messages daily, and a global network sensor array that generated over 3 million alerts&nbsp;and&nbsp;identified&nbsp;four undisclosed CVEs&nbsp;in 2026 to date — present a consistent picture:&nbsp;attackers are opportunistic. They grab newly published CVEs when public proof-of-concept code appears, chain them"},{"title":"More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild","url":"https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild","domain":"proofpoint.com","seendate":"20260527150000","sourceCountry":"Proofpoint Threat Insight","c":"KP","relationship":"sponsor","confidence":"medium","evidence":"hanism Failure&nbsp; In two separate campaigns&nbsp;observed&nbsp;by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack","activityType":"cybercrime","summary":"Executive Summary The CVE Landscape Has Changed. The Threat Actors Haven't.&nbsp; Proofpoint's dual telemetry streams — targeted&nbsp;attack&nbsp;visibility covering hundreds of millions of messages daily, and a global network sensor array that generated over 3 million alerts&nbsp;and&nbsp;identified&nbsp;four undisclosed CVEs&nbsp;in 2026 to date — present a consistent picture:&nbsp;attackers are opportunistic. They grab newly published CVEs when public proof-of-concept code appears, chain them"},{"title":"Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks","url":"https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/","domain":"krebsonsecurity.com","seendate":"20260525132149","sourceCountry":"Krebs on Security","c":"RU","relationship":"criminal","confidence":"medium","evidence":"arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union.","activityType":"information-operation","summary":"Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequ"},{"title":"This month in security with Tony Anscombe – April 2026 edition","url":"https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-april-2026/","domain":"welivesecurity.com","seendate":"20260430090000","sourceCountry":"ESET WeLiveSecurity","c":"IR","relationship":"sponsor","confidence":"medium","evidence":"nth in security with Tony Anscombe – April 2026 edition. Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some","activityType":"cyber-activity","summary":"Warnings about helpdesk impersonation scams and Iran-linked hackers targeting critical sectors in the US, plus the most damaging scams of 2025 - here's some of what made the headlines this month"},{"title":"Executive Summary: Defending against China-nexus covert networks of compromised devices","url":"https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices","domain":"ncsc.gov.uk","seendate":"20260423120000","sourceCountry":"NCSC UK","c":"CN","relationship":"victim","confidence":"high","evidence":"Executive Summary: Defending against China-nexus covert networks of compromised devices. Organisations should map and baseline their edge device tr","activityType":"cyber-activity","summary":"Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators."},{"title":"International cyber agencies share fresh advice to defend against China-linked covert networks","url":"https://www.ncsc.gov.uk/news/international-cyber-agencies-fresh-advice-defend-against-china-linked-covert-networks","domain":"ncsc.gov.uk","seendate":"20260423120000","sourceCountry":"NCSC UK","c":"CN","relationship":"victim","confidence":"high","evidence":"International cyber agencies share fresh advice to defend against China-linked covert networks. New advisory highlights how to defend against attacker tactics believed to be us","activityType":"cyber-activity","summary":"New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity."},{"title":"GopherWhisper: A burrow full of malware","url":"https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/","domain":"welivesecurity.com","seendate":"20260423085918","sourceCountry":"ESET WeLiveSecurity","c":"CN","relationship":"sponsor","confidence":"medium","evidence":"GopherWhisper: A burrow full of malware. ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions","activityType":"cyber-activity","summary":"ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions"}]}
