Anthropic says a Russia-linked group used Claude AI to automate cyberattacks against Ukrainian and European targets, run disinformation campaigns in Africa and Moldova, and develop autonomous kamikaze drone software; the company blocked the misuse, strengthened its security, and shared findings with governments and industry partners.
Proofpoint links a new Chrome/Windows exploit kit, BlueMoon, to a wave of espionage campaigns by four groups—primarily China-aligned—using two Chrome V8 flaws (CVE-2026-85046 and CVE-2026-85880) and a Windows ALPC privilege escalation to run payloads after a phishing lure; multiple variants target NGOs, aerospace, Vietnamese manufacturing, and government/financial sectors, with DLL sideloading, Cloudflare infrastructure, and in-memory payloads observed. CISA added the Chrome flaw to Known Exploited Vulnerabilities; patching browsers may not remove implants. Indicators include process chains (chrome.exe → cmd.exe → curl.exe → msgbox.exe), ChromeUpdate.exe/msgbox.exe in %TEMP%, specific scheduled tasks (EdgeCore_AutoUpdate, MicrosoftEdgeUpdatesTaskMachine, Avpcheckup, GeForceService), a registry key, and related DLL artifacts; detection rules 2071919–2071924 published.
Sygnia researchers say Fire Ant has shifted from targeting VMware to compromising Cisco IOS XR routers, TACACS servers, and Linux management hosts, deploying a persistent malware that creates a fake systemd service, suppresses logs, and uses a GRE tunnel to route traffic to a Linux staging server for reconnaissance. The attackers capture router traffic as PCAPs, upload them to external FTP servers, and probe connected high-value networks; they also uncovered BridgeAgent, a backdoor masquerading as a Zabbix agent that supports TLS reverse shells and additional payload execution. The operation overlaps with UNC3886 but features distinct artifacts, and investigators warn to validate logs and IoCs to detect the actors’ activity.
The EU has blacklisted members of Russia’s FSB-led Turla cyber espionage group for years of hacking and spying across Europe and Ukraine, targeting governments and critical infrastructure; the sanctions include travel bans and asset freezes on individuals and entities such as AST and NPP Gamma, with the UK also imposing penalties.
The DarkSpectre threat actor, linked to China, has exposed a series of malicious browser extensions across Chrome, Edge, and Firefox, affecting over 8.8 million users worldwide. These extensions, including ShadyPanda, GhostPoster, and The Zoom Stealer, are designed for data theft, corporate espionage, and meeting information harvesting, often masquerading as legitimate tools for video conferencing and utilities. The campaigns have been active for over seven years, with some extensions still in the trust-building phase, posing significant risks to user privacy and corporate security.
China's Ministry of State Security has become a major cyber power, conducting sophisticated operations like the Salt Typhoon intrusion, which stole data from numerous countries, highlighting its strategic cyber capabilities and the leadership's focus on technological and cyber espionage advancements under Xi Jinping.
The FBI has issued a warning that a Chinese hacking campaign has expanded its reach to 80 countries, highlighting a significant global cybersecurity threat and ongoing cyber espionage activities.
North Korea's APT37 group is using sophisticated malware embedded in JPEG images and leveraging steganography to evade detection and attack Windows systems, primarily in South Korea. The malware employs multi-stage shellcode injection, fileless techniques, and cloud API abuse for command and control, highlighting the need for advanced behavioral detection and proactive security measures.
Microsoft announced that a cyber-espionage group called Storm-2603 is exploiting vulnerabilities in SharePoint server software to deploy ransomware, leading to at least 400 known victims including U.S. government agencies, marking a significant escalation in the campaign.
Microsoft knew of a critical SharePoint security flaw identified in May but released a patch that failed to fully fix it, leading to a global cyber espionage operation targeting around 100 organizations, with Chinese hacking groups exploiting the vulnerability despite Microsoft's efforts to patch it.
The article discusses the emerging risks associated with advancing quantum technology, highlighting potential threats to cybersecurity and the possibility of a 'cyber doomsday' scenario as these technologies become more prevalent.
Chinese state-sponsored group APT41 exploited Google Calendar for malware C2 operations, using a sophisticated multi-stage malware to target government entities and organizations worldwide, with Google taking measures to neutralize the campaign.
A Chinese hacking group known as "Salt Typhoon" has stolen a significant amount of Americans' metadata in a cyber-espionage campaign, according to a senior US official. The hackers targeted multiple telecommunications companies, including Verizon, AT&T, and T-Mobile, although some companies reported no customer data compromise. The stolen metadata, which includes call records but not content, can reveal detailed personal information. The US government, prioritizing the issue, has briefed President Biden and held a classified briefing for senators on the matter.
A Russian hacking group, identified as "RomCom," has exploited two zero-day vulnerabilities to target Firefox and Tor browser users on Windows PCs, primarily in Europe and North America. The attacks, which began in October, involve a malicious web page that installs a backdoor on victims' PCs without user interaction. The vulnerabilities, CVE-2024-9680 and CVE-2024-49039, have been patched by Mozilla, Tor, and Microsoft. However, users who haven't updated remain at risk. ESET links these attacks to RomCom's previous exploits.
Chinese hackers are reportedly embedding themselves in U.S. critical infrastructure to gain an advantage in potential conflicts, according to Morgan Adamski of U.S. Cyber Command. This follows a significant cyberespionage operation, "Salt Typhoon," which targeted U.S. telecommunications, compromising call records and communications of key officials. The Chinese government denies involvement, and the Chinese Embassy has not commented on the allegations.