Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Categorie: geopolitics

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

post, augustus 26, 2026september 4, 2026

The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei…

Continue Reading

Iraanse hackers legden Britse energiecentrale 4 dagen plat

post, augustus 23, 2026augustus 24, 2026

Iraanse hackers hebben vorige maand een energiecentrale in het Verenigd Koninkrijk vier dagen platgelegd met een cyberaanval. Dat meldt de Britse krant The Telegraph. Volgens de krant is het de eerste keer dat hackers die gelinkt worden aan het Iraanse regime een energiefaciliteit in het VK wisten te raken. Om welke energiecentrale…

Continue Reading

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

post, augustus 12, 2026augustus 17, 2026

Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews. During that investigation,…

Continue Reading

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

post, juli 23, 2026juli 27, 2026

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it…

Continue Reading

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

post, juli 22, 2026juli 27, 2026

The authoring agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control…

Continue Reading

Golden Dome: When Data Becomes Ammunition

post, april 29, 2026mei 1, 2026

When we think of Golden Dome and what success looks like, we naturally talk about sensors, interceptors, and systems but the reality is much simpler: if the data they rely on doesn’t move, at speed, and securely, then nothing else matters. Data is now the driver of operational advantage. In today’s multi-domain, mission-critical environments, speed isn’t measured in minutes or seconds but in milliseconds. Data…

Continue Reading

US warns of Iranian hackers targeting critical infrastructure

post, april 7, 2026april 9, 2026

Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations. The warning came earlier today in the form of a joint advisory authored by the FBI, CISA, NSA, the Environmental Protection Agency (EPA), Department of Energy (DOE), and the United States Cyber…

Continue Reading

FBI confirms hack of Director Patel’s personal email inbox

post, maart 29, 2026maart 30, 2026

The Handala hackers associated with Iran have breached the personal email account of FBI Director Kash Patel and published photos and documents. The FBI has confirmed the compromise, saying that the stolen data was not recent and did not include any government data. ​On Friday, the Handala threat actor announced…

Continue Reading

Why Stryker’s Outage Is a Disaster Recovery Wake-Up Call

post, maart 12, 2026maart 18, 2026

A cyberattack that appears to have knocked tens of thousands of systems offline at medical technology company Stryker this week is a sobering reminder of the importance for organizations to have robust and tested business continuity and disaster recovery plans. Iranian threat group Handala claimed responsibility for the attack, calling it…

Continue Reading

Iran intelligence backdoored US bank, airport, software outfit networks

post, maart 5, 2026maart 9, 2026

An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies’ networks – including a bank, software firm, and airport, among others – since the beginning of February, with more activity in the days following the US…

Continue Reading
  • 1
  • 2
  • …
  • 8
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes