securitybrief.com.au
Google disrupts China-linked cyber espionage on telecoms
Google says it has crippled a China-linked cyber espionage group accused of hacking telecoms and governments in at least 42 countries.
#CyberEspionage is an active hashtag on Bluesky. In the last 30 days, 13 people shared 33 posts with it — around 1 a day. Activity is down 71% versus the previous week, peaking on Jul 21 with 4 posts.
Tags most often used together with #CyberEspionage.
securitybrief.com.au
Google disrupts China-linked cyber espionage on telecoms
Google says it has crippled a China-linked cyber espionage group accused of hacking telecoms and governments in at least 42 countries.
industrialcyber.co
Finland’s National Security Overview 2026 flags Russian and Chinese cyber espionage targeting government, critical infrastructure - Industrial Cyber
Finland’s National Security Overview 2026 flags Russian and Chinese cyber espionage targeting government, critical infrastructure
osintdaily.blogspot.com
Inside the Silent Breach: How CIA Spies Steal Data Without Going Online
A blog about the 17 spy agencies comprising the US Intelligence Community
theins.ru
“World-class” Russian hacker wanted by FBI and arrested in Thailand is likely GRU officer Aleksey Lukashev
On Nov. 12, Thai cyber police announced the arrest of a 35-year-old Russian citizen on the island of Phuket, adding that the unnamed suspect stands wanted in the United States on charges of hacking go...
In diesen Tagen reden viele wieder vom sogenannten „Hybriden Krieg“. Kein neues Phänomen. Schon vor 10 Jahren hackte sich ein russischer Geheimdienst in den Bundestag - bis in die Computer von Angela Merkel. @hatr.bsky.social haben darüber einen Podcast gemacht: www.ardaudiothek.de/sendung/der-...
www.ardaudiothek.de
cyberintel.substack.com
DOGE Exposes Once-Secret Government Networks, Making Cyber-Espionage Easier than Ever
A new investigation shows nuclear secrets and government servers are dangerously exposed to nation-state hackers.
securityonline.info
CaptiveCrunch Malware Campaign Hijacks Hotel Wi-Fi Worldwide
At a glance Actor or group Storm-2945, assessed as an operational sub-cluster of Midnight Blizzard Activity type Traffic manipulation on captive portals, malware delivery, and credential theft Targets or victims Corporate travelers at hotels, conference centers, and shared venues worldwide Scale Widespread compromise of Wi-Fi networks at hospitality organizations in several countries; exact victim count not disclosed Jurisdiction or status…
Le #cyberespionnage joue un rôle très important. Chaque mois, l'équipe de recherche #APT voit des groupes de hackers liés à la #Chine cibler des industriels des semi-conducteurs (en particulier à #Taïwan 🇹🇼). Force est de constater qu’il s’agit d’un effort persistant, bien ciblé et intergroupe.
smpl.is
Cuckoo's Egg Book Review: A True Cyber Spy Story
This Cuckoo's Egg book review covers a true spy hunt that exposed the first major KGB hacker case.
securityonline.info
CaptiveCrunch Malware Campaign Hijacks Hotel Wi-Fi Worldwide
At a glance Actor or group Storm-2945, assessed as an operational sub-cluster of Midnight Blizzard Activity type Traffic manipulation on captive portals, malware delivery, and credential theft Targets or victims Corporate travelers at hotels, conference centers, and shared venues worldwide Scale Widespread compromise of Wi-Fi networks at hospitality organizations in several countries; exact victim count not disclosed Jurisdiction or status…
securityonline.info
OctLurk and SilkLurk Backdoors Hit Central Asian Government Networks
At a glance
meterpreter.org
SNOWLIGHT Malware Campaign Exposed by Open Directories
The operators behind a massive, globally coordinated hacking campaign committed a fatal operational security error. They inadvertently left directories entirely open on the centralized server utilized to prepare and execute their attacks. Consequently, SOCRadar researchers discovered comprehensive target lists, sophisticated exploits, and malicious payloads. Furthermore, they unearthed detailed command execution logs and specialized traffic obfuscation tools. These meticulously maintained records span six critical weeks.
securityonline.info
Mirage Kitten Deploys New Malware Against Middle East and Africa
At a glance Actor Mirage Kitten (also UNC1549, Smoke Sandstorm, Nimbus Manticore) Activity State-aligned cyber espionage and long-term network access Targets Aviation, defense, telecom, government, and financial sectors Scale Victims across at least six countries in the Middle East and Africa Attribution Assessed by multiple firms as an Iran-nexus, IRGC-linked group; no arrests reported Source Kaspersky Securelist TL;DR Kaspersky has uncovered new Mirage Kitten malware aimed at the Middle East and Africa.
www.helpnetsecurity.com
Laundry Bear's new Microsoft Exchange attack triggers on email open (CVE-2026-42897) - Help Net Security
Russia-affiliated spies are exploiting Microsoft Exchange flaw (CVE-2026-42897) to target government entities via email.
securelist.com
OctLurk and SilkLurk backdoors target Central Asia
cyber.netsecops.io
Russian APT28 Hijacks Routers in DNS Poisoning Campaign
A cyberespionage campaign named FrostArmada, linked to the Russian APT group Forest Blizzard (APT28), hijacked routers to steal Microsoft credentials.
securityonline.info
APT42 TAMECAT Malware Grows with AI-Assisted Phishing
At a glance Actor or group APT42 (Iran-linked; also tracked as TA453) Activity type AI-assisted spear-phishing, credential theft, TAMECAT backdoor delivery Targets or victims Defense and government figures, a US think tank, nuclear-energy sector contacts Scale Multiple hand-picked individuals; not mass phishing Jurisdiction or law-enforcement status
meterpreter.org
Iranian Cyber Threat Landscape: Espionage and Covert Access
The Strategic Value of Silent Persistence Iranian threat actors operate with significantly greater stealth than conventionally perceived. Rather than executing immediate, high-profile disruptive attacks, these adversaries meticulously maintain long-term, covert access within compromised networks. They strategically leverage these embedded footholds for prolonged espionage, psychological pressure, or targeted sabotage when geopolitical conditions dictate. This sobering conclusion stems from a comprehensive analysis conducted by…
dlvr.it
US Indicts Three Russian Nationals Over Bulletproof Hosting Network Linked to Global Cybercrime
The EU sanctioned nine Russian citizens and four entities for engaging in cyber-espionage campaigns and attacks against the EU, member states, Ukraine, and other countries. The sanctions were imposed by the Council of the European Union and coordinated with the UK as the first joint action under the cyber sanctions of the EU and the UK. According to the EU, the sanctioned entities and individuals are integral parts of Russia’s cyber ecosystem that have supported ransomware perpetrators, phishing campaigns, DDoS services, and attacks on enterprises and government infrastructure. Among the sanctioned entities are Media Land LLC, its owner Alexander Volosovik, and affiliated company ML.Cloud that have allegedly facilitated ransomware and phishing campaigns that have resulted in billions of dollars in damages to enterprises around Europe. The pro-Russian hacker group Z-Pentest was also sanctioned for targeting critical infrastructure such as Denmark’s water supply in the December 2024 attack. Along with Z-Pentest’s leader Yuliya Pankratova and the group’s chief hacker Denis Degtyarenko, the EU sanctioned the pro-Russian hacker collective Cyber Army of Russia Reborn (CARR). Cyber Army of Russia Reborn is accused of launching DDoS attacks on government resources worldwide in support of Russia’s war effort against Ukraine since 2022. The sanctioned individuals include Evgeniy Bashev, the owner of Impuls LLC, a Russian cyber security firm, and Maksim Voronin, Maksim Gordienko, and Vitaly Kovalov, four Russian hackers. They have been accused of facilitating the development and proliferation of hacking software, including the LummaC2 botnet, Trickbot, and Conti ransomware, which have been used in numerous cybercrime activities in Europe. Additionally, the EU sanctioned Ivan Kasyanenko, the deputy commander of Russia’s Main Intelligence Directorate 29155 for allegedly facilitating military and paramilitary activities in Europe and Afghanistan. He has been identified as the person responsible for coordinating cyber operations in Russia against the EU and Ukraine and supporting Wagner Group mercenaries in Africa. Kasyanenko is also accused of being involved in the poisoning of Sergei and Yulia Skripal in the UK in 2018. The EU is currently finalizing its 21st sanctions package against Russia, which will involve further economic and trade restrictions. According to the spokesperson, the coordination of cyber sanctions measures by the EU and UK sends a strong signal to Russia that the EU is willing to take more steps to weaken its cyber capacities and disrupt its espionage and disinformation activities in the EU, UK, and critical infrastructure in Europe.
Le #cyberespionnage joue un rôle très important. Chaque mois, l'équipe de recherche #APT voit des groupes de hackers liés à la #Chine cibler des industriels des semi-conducteurs (en particulier à #Taïwan 🇹🇼). Force est de constater qu’il s’agit d’un effort persistant, bien ciblé et intergroupe.
Posts are pulled live from Bluesky and cached briefly. Posts with content labels are hidden.