Reminder: China-backed crews compromised ‘multiple’ US telcos in ‘significant cyber espionage campaign’ post, november 14, 2024 The US government has confirmed there was “a broad and significant cyber espionage campaign” conducted by China-linked snoops against “multiple” American telecommunications providers’ networks. In a joint statement issued on Wednesday by the FBI and US Cybersecurity and Infrastructure Security Agency (CISA), the two government bodies said the previously-reported digital assaults resulted… Continue Reading
North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks post, oktober 3, 2024juli 3, 2025 Threat actors with ties to North Korea have been observed delivering a previously undocumented backdoor and remote access trojan (RAT) called VeilShell as part of a campaign targeting Cambodia and likely other Southeast Asian countries. The activity, dubbed SHROUDED#SLEEP by Securonix, is believed to be the handiwork of APT37, which is also known… Continue Reading
Three Iranian Hackers Charged for Influencing Trump Election Campaign post, september 30, 2024 The U.S. Department of Justice has unsealed an indictment against three Iranian nationals linked to the Islamic Revolutionary Guard Corps (IRGC) for their alleged involvement in a “hack-and-leak” operation aimed at influencing the 2024 U.S. presidential election. The accused, Masoud Jalili, Seyyed Ali Aghamiri, and Yaser Balaghi, are charged with a… Continue Reading
Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign post, september 26, 2024september 26, 2024 Nation-state threat actors backed by Beijing broke into a “handful” of U.S. internet service providers (ISPs) as part of a cyber espionage campaign orchestrated to glean sensitive information, The Wall Street Journal reported Wednesday. The activity has been attributed to a threat actor that Microsoft tracks as Salt Typhoon, which is also… Continue Reading
Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware post, september 23, 2024 A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools. “They used advanced techniques like GeoServer exploitation, spear-phishing, and customized malware (Cobalt Strike and… Continue Reading
White House seizes 32 domains, issues criminal charges in massive election-meddling crackdown post, september 5, 2024 The Biden administration on Wednesday seized 32 websites and charged two employees of a state-owned media outlet connected to a $10 million scheme to distribute pro-Kremlin propaganda, and claimed the actions were necessary to counter Russia’s attempts to influence the upcoming US presidential election. This is all part of the… Continue Reading
Notorious Iranian Hackers Have Been Targeting the Space Industry With a New Backdoor post, augustus 28, 2024juli 3, 2025 The Iranian government-backed hacking group known as APT 33 has been active for more than 10 years, conducting aggressive espionage operations against a diverse array of public and private sector victims around the world, including critical infrastructure targets. And while the group is particularly known for strategic but technically simple attacks like “password spraying,” it has… Continue Reading
Iranian hackers target WhatsApp accounts of Biden and Trump administration associates, Meta says post, augustus 24, 2024augustus 26, 2024 An Iranian hacker group targeted the WhatsApp accounts of individuals associated with the administrations of President Joe Biden and former President Donald Trump, Meta announced Friday. “This malicious activity originated in Iran and attempted to target individuals in Israel, Palestine, Iran, the United States and the UK,” the social media giant said in… Continue Reading
Japanese space agency spotted zero-day attacks while cleaning up attack on M365 post, juli 11, 2024juli 12, 2024 The Japanese Space Exploration Agency (JAXA) discovered it was under attack using zero-day exploits while working with Microsoft to probe a 2023 cyberattack on its systems. But the space org’s statement also revealed the discovery of malware found and removed by an actor other than Microsoft. And then there’s the… Continue Reading
State-Sponsored Russian Media LeveragesMeliorator Software for Foreign MalignInfluence Activity post, juli 9, 2024juni 13, 2025 The U.S. Federal Bureau of Investigation (FBI) and Cyber National Mission Force (CNMF), in partnershipwith the Netherlands General Intelligence and Security Service (AIVD), Netherlands Military Intelligence and Security Service (MIVD), the Netherlands Police (DNP), and the Canadian Centre for Cyber Security (CCCS), (hereinafter referred to as the authoring organizations) are… Continue Reading