Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection post, september 11, 2026september 15, 2026 Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group),… Continue Reading
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis post, september 1, 2026september 4, 2026 Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that’s been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model’s… Continue Reading
Russische ransomwaregroep zegt Shell en Philips te hebben gehackt post, augustus 13, 2026augustus 17, 2026 De Russische hackersgroep Clop claimt Shell en Philips te hebben gehackt. Het is nog onduidelijk wat de impact is. Shell zegt tegen de NOS “op de hoogte te zijn van een mogelijk incident”. Volgens een woordvoerder onderzoekt een team van beveiligingsexperts nog wat er precies is gebeurd. Continue Reading
Russische ransomwaregroep claimt Shell en Philips te hebben gehackt post, augustus 13, 2026augustus 17, 2026 De Russische hackersgroep Clop claimt een hack te hebben uitgevoerd bij Shell en Philips. De groep zegt 89 gigabyte aan informatie in handen te hebben van het olieconcern. Van Philips zou 13,5 gigabyte buitgemaakt zijn. Shell en Philips bevestigen tegenover BNR dat er een incident wordt onderzocht. Het is onduidelijk… Continue Reading
Sandworm hackers target IT pros with trojanized WireGuard VPN client post, augustus 11, 2026augustus 17, 2026 Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of… Continue Reading
Hackers breached a small Polish energy plant via private APN last year post, augustus 10, 2026augustus 17, 2026 Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland’s energy sector last year. The second target was a small combined heat-and-power (CHP) plant that supplies heat to around 50,000 residents, resulting in the steam turbine and the water treatment system being shut… Continue Reading
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data post, augustus 7, 2026augustus 17, 2026 A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees… Continue Reading
Russia State-Sponsored Hackers Turn Hotel and Conference Wi-Fi Networks Into Malware Delivery Systems post, augustus 4, 2026augustus 17, 2026 Russian state backed hackers are compromising public Wi-Fi infrastructure at hotels, conference centres and other shared venues to intercept travellers’ internet traffic, distribute remote-access malware and steal access to corporate cloud accounts, according to new research from Microsoft. The campaign, which Microsoft calls CaptiveCrunch, has been attributed to Storm-2945, an… Continue Reading
New DOUBLECUP ClickFix service hides malware in browser cache images post, augustus 3, 2026augustus 17, 2026 A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June… Continue Reading
Russian State-Backed Threat Actor Exploits Zimbra Zero-Day To Steal Emails & Authentication Data post, juli 24, 2026juli 27, 2026 A Russian state-supported hacking group has been exploiting a previously unknown vulnerability in Zimbra Collaboration Suite to silently steal emails, passwords, two-factor authentication codes and corporate address books from government and commercial organizations across Western countries. The campaign, attributed to a threat group primarily known as Laundry Bear, has been… Continue Reading