Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days post, februari 3, 2026februari 4, 2026 In the latest illustration of how quickly attackers can exploit newly disclosed flaws, Russia’s notorious APT28 cyber-espionage group has begun abusing a recently patched Microsoft vulnerability to steal emails and deploy malicious payloads against organizations in Central and Eastern Europe. CVE-2026-21509 is a security feature bypass vulnerability in Microsoft Office… Continue Reading
How the KGB Discovered Computer Viruses post, februari 2, 2026februari 4, 2026 A 1989 internal memo warned the Soviet security apparatus about a new threat: malicious software that was spreading among users across the USSR and even within the KGB itself. In this post I will review an archival KGB document on computer viruses available through the Lithuanian Genocide and Resistance Research… Continue Reading
Russia-linked APT28 attackers already abusing new Microsoft Office zero-day post, februari 2, 2026februari 4, 2026 Russia-linked attackers are already exploiting Microsoft’s latest Office zero-day, with Ukraine’s national cyber defense team warning that the same bug is being used to target government agencies inside the country and organizations across the EU. In an alert published on Sunday, CERT-UA says the activity is being driven by UAC-0001, better… Continue Reading
Sandworm hackers linked to failed wiper attack on Poland’s energy systems post, januari 24, 2026januari 26, 2026 A cyberattack targeting Poland’s power grid in late December 2025 has been linked to the Russian state-sponsored hacking group Sandworm, which attempted to deploy a new destructive data-wiping malware dubbed DynoWiper during the attack.. Sandworm (also tracked as UAC-0113, APT44, and Seashell Blizzard) is a Russian nation-state hacking group that… Continue Reading
Amazon Exposes Years-Long GRU Cyber Campaign Targeting Energy and Cloud Infrastructure post, december 16, 2025december 17, 2025 Amazon’s threat intelligence team has disclosed details of a “years-long” Russian state-sponsored campaign that targeted Western critical infrastructure between 2021 and 2025. Targets of the campaign included energy sector organizations across Western nations, critical infrastructure providers in North America and Europe, and entities with cloud-hosted network infrastructure. The activity has been attributed… Continue Reading
Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics post, oktober 29, 2025oktober 31, 2025 Organizations in Ukraine have been targeted by threat actors of Russian origin with an aim to siphon sensitive data and maintain persistent access to compromised networks. The activity, according to a new report from the Symantec and Carbon Black Threat Hunter Team, targeted a large business services organization for two months and… Continue Reading
Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign post, september 6, 2025september 8, 2025 A threat actor possibly of Russian origin has been attributed to a new set of attacks targeting the energy sector in Kazakhstan. The activity, codenamed Operation BarrelFire, is tied to a new threat group tracked by Seqrite Labs as Noisy Bear. The threat actor has been active since at least… Continue Reading
Russian APT28 Deploys “NotDoor” Outlook Backdoor Against Companies in NATO Countries post, september 4, 2025september 5, 2025 The Russian state-sponsored hacking group tracked as APT28 has been attributed to a new Microsoft Outlook backdoor called NotDoor in attacks targeting multiple companies from different sectors in NATO member countries. NotDoor “is a VBA macro for Outlook designed to monitor incoming emails for a specific trigger word,” S2 Grupo’s LAB52 threat intelligence team said…. Continue Reading
The Scale of Russian Sabotage Operations Against Europe’s Critical Infrastructure post, augustus 22, 2025augustus 25, 2025 Russia is waging an unconventional war on Europe. Through its campaign of sabotage, vandalism, espionage and covert action, Russia’s aim has been to destabilise European governments, undermine public support for Ukraine by imposing social and economic costs on Europe, and weaken the collective ability of NATO and the European Union… Continue Reading
Russian hackers took control of Norwegian dam, police chief says post, augustus 13, 2025september 1, 2025 The Norwegian Police Security Service suspects pro-Russian hackers sabotaged a dam in southwestern Norway in April. Norwegian daily newspaper VG reported that the hackers breached the dam’s control system, opening valves for four hours, sending large amounts of water gushing forth until the valves could be shut. Continue Reading