Topic: state-sponsored attacks

  • State-Sponsored Cyber-Attacks: A Top Fear for Businesses

    State-Sponsored Cyber-Attacks: A Top Fear for Businesses

    State-sponsored cyber-attacks are a top fear for cybersecurity professionals, with many citing a lack of preparedness for such threats linked to geopolitical conflict as a primary concern. Over a third of surveyed professionals feel their governments provide insufficient support, and the risk ext...

    Read More »
  • Why Cyber Threats Demand a Statecraft Mindset

    Why Cyber Threats Demand a Statecraft Mindset

    Cybersecurity leaders must stop treating security as a purely technical problem and recognize that private firms are geopolitical actors, as demonstrated by breaches like the 2014 Sony Pictures attack and the 2022 Viasat incident. The Cyber Geopolitical Preparedness and Response (CGPR) framework ...

    Read More »
  • 10,000+ Zimbra servers exposed to active XSS attacks

    10,000+ Zimbra servers exposed to active XSS attacks

    Over 10,000 unpatched Zimbra Collaboration Suite servers remain vulnerable to active exploitation of a cross-site scripting flaw (CVE-2025-48700), which allows unauthenticated attackers to execute arbitrary JavaScript when a user views a specially crafted email in the Classic UI. The U.S. Cyberse...

    Read More »
  • EU Cyberattacks Increasingly Target Critical Infrastructure

    EU Cyberattacks Increasingly Target Critical Infrastructure

    The ENISA Threat Landscape 2025 report reveals a significant increase in cyberattacks targeting operational technology systems, which now account for 18.2% of all documented threats, driven by their growing interconnectedness and deliberate targeting by malicious actors. Pro-Russian hacker groups...

    Read More »
  • AI's dual threat: weapon and target, warns CrowdStrike

    AI's dual threat: weapon and target, warns CrowdStrike

    AI now serves as both a weapon for cybercriminals and a primary attack surface, with AI-driven attack signals outpacing human analysis by 2.5 times, making it harder for defenders to distinguish malicious activity from legitimate AI behavior. Threat actors are exploiting AI in documented campaign...

    Read More »
  • Notepad++ Supply Chain Attack Exposed: Patch Tuesday Outlook

    Notepad++ Supply Chain Attack Exposed: Patch Tuesday Outlook

    A sophisticated supply chain attack on Notepad++ by a Chinese state-sponsored group and the exploitation of a Microsoft Office flaw by Russian hackers highlight critical risks in software updates and patch management. Attackers are disabling modern security tools using a decade-old driver, while ...

    Read More »
  • AWS Accounts Hijacked by AiTM Phishing, HR Targeted in Year-Long Malware Campaign

    AWS Accounts Hijacked by AiTM Phishing, HR Targeted in Year-Long Malware Campaign

    Attackers are employing sophisticated, persistent methods like phishing kits that bypass multi-factor authentication and long-term malware campaigns targeting critical business functions such as HR departments. The cybersecurity industry faces significant human challenges, including a lack of div...

    Read More »
  • Critical Flaw Exposes 10K+ Fortinet Firewalls to 2FA Bypass

    Critical Flaw Exposes 10K+ Fortinet Firewalls to 2FA Bypass

    A critical five-year-old Fortinet firewall flaw (CVE-2020-12812) allows attackers to bypass two-factor authentication by altering a username's case, and over 10,000 vulnerable devices remain exposed online. Despite a patch being available since 2020, attackers are actively exploiting the vulnerab...

    Read More »
  • 2026 Cybersecurity Forecast: Key Trends to Watch

    2026 Cybersecurity Forecast: Key Trends to Watch

    Cybercriminals are increasingly targeting people over software vulnerabilities, using tactics like phishing and deceptive applications to breach networks, as seen in the 2025 Salesforce attack by Shiny Hunters. Artificial intelligence tools are creating more sophisticated threats, such as advance...

    Read More »
  • Google AI Detects Malware That Morphs During Attacks

    Google AI Detects Malware That Morphs During Attacks

    Google has identified a new generation of AI-powered malware that rewrites its own code during attacks, making it more resilient and harder to detect by dynamically altering behavior and evading security systems. Several malware families, such as FRUITSHELL, PROMPTFLUX, and PROMPTLOCK, are active...

    Read More »
  • Phishing Leads EU Cyber Intrusions, ENISA Reports

    Phishing Leads EU Cyber Intrusions, ENISA Reports

    Phishing was the leading initial attack method in the EU, responsible for 60% of intrusions, with outdated mobile and OT systems being prime targets. DDoS attacks comprised 77% of all incidents, largely driven by hacktivism, but only 2% caused service disruptions, with groups like NoName057(16) e...

    Read More »
  • Water Cyberattacks Expand to New Jersey, Alabama

    Water Cyberattacks Expand to New Jersey, Alabama

    Iranian state-linked hackers have expanded attacks on U.S. water treatment plants, with new intrusions confirmed in New Jersey and Alabama, bringing the total to at least a dozen states. The campaign targets industrial control systems (ICS) and SCADA systems, shifting focus from data theft to pot...

    Read More »
  • US Agencies Still Vulnerable to Critical Cisco Flaws

    US Agencies Still Vulnerable to Critical Cisco Flaws

    CISA issued an emergency directive for U.S. federal agencies to patch two actively exploited Cisco vulnerabilities (CVE-2025-20333 and CVE-2025-20362), as many devices were incorrectly reported as secure. These vulnerabilities enable remote code execution and privilege escalation, and are linked ...

    Read More »
  • The Economics Fueling Global Ransomware

    The Economics Fueling Global Ransomware

    Ransomware has evolved into a sophisticated criminal business model, projected to cause $10.5 trillion in global economic losses by 2025, driven by professional networks and Ransomware-as-a-Service (RaaS) that lower entry barriers for attackers. Attackers employ double and triple extortion tactic...

    Read More »
  • Chinese Hackers Exploiting VMware Zero-Day Since 2025

    Chinese Hackers Exploiting VMware Zero-Day Since 2025

    A critical privilege escalation vulnerability (CVE-2025-41244) in Broadcom's VMware software has been actively exploited since October 2024, allowing attackers to gain root-level control over affected virtual machines. The exploitation has been attributed to UNC5174, a Chinese state-sponsored thr...

    Read More »
  • Google Patches Critical Chrome Zero-Day Flaw (CVE-2025-10585)

    Google Patches Critical Chrome Zero-Day Flaw (CVE-2025-10585)

    Google has released an urgent security update for Chrome to fix a zero-day vulnerability (CVE-2025-10585) that is being actively exploited, particularly by state-sponsored threat actors. The flaw is a type confusion issue in Chrome's V8 JavaScript engine, marking the second such vulnerability pat...

    Read More »
  • Infosecurity Europe Urges Procurement Teams to Address Security Risks Now

    Infosecurity Europe Urges Procurement Teams to Address Security Risks Now

    Only 8% of SSH servers currently support post-quantum cryptography, and security experts warn organizations must begin PQC transitions now to prepare for cryptographically relevant quantum computers, not just the arrival of Q-day. The threat of "harvest-now-decrypt-later" attacks is already docum...

    Read More »
  • Google Finds Malware Using AI to Evade Detection

    Google Finds Malware Using AI to Evade Detection

    Malicious software is now actively using artificial intelligence to autonomously bypass security measures, with tools like QuietVault and PromptSteal already deployed in the wild to steal credentials and sensitive data. Google's threat intelligence report highlights that adversaries have moved be...

    Read More »
  • Cisco ASA Firewalls Remain Vulnerable to Zero-Day Attacks

    Cisco ASA Firewalls Remain Vulnerable to Zero-Day Attacks

    Approximately 48,000 Cisco ASA devices remain vulnerable to active zero-day attacks, posing ongoing risks globally, with the majority located in the U.S. and other key countries. Attackers have used advanced tactics, including disabling logging and intercepting commands, to exploit vulnerabilitie...

    Read More »
  • 2025's Most Devastating Cyberattacks Exposed

    2025's Most Devastating Cyberattacks Exposed

    The cyber threat landscape has shifted towards sophisticated supply chain attacks, where breaches of third-party vendors like Gainsight and Salesloft led to widespread data exposure at major corporations including Cloudflare, Verizon, and Cisco. The Clop ransomware group exploited a critical vuln...

    Read More »