Artificial Intelligence (AI)
Hermes Autonomous Agent in "YOLO Mode" Named in Thai Ministry of Finance Espionage
Now with a name and a mode — the Thai Finance Ministry attribution lands this week.
Coverage of nation-state cyber threats, including government-backed hackers, cyber espionage campaigns, and geopolitical cyberattacks targeting critical infrastructure and global organizations.
Artificial Intelligence (AI)
Now with a name and a mode — the Thai Finance Ministry attribution lands this week.
Nation-State Cyber Threats
New backdoor, familiar actor — the Iran-linked group tracked as Nimbus Manticore has a fresh toolset, and Kaspersky's write-up of NightLedger lands this week.
Artificial Intelligence (AI)
Ten days after Hugging Face — the second autonomous-agent cyber event lands this week.
Nation-State Cyber Threats
A year-long Russian state-supported zero-click Zimbra campaign, exposed this week by NCSC UK and partners across some 16 nations — a defender review for any organization still running unpatched Zimbra.
Data Breaches
A nine-month South Korean foreign-ministry breach — allied foreign-ministry defender posture review this week.
Nation-State Cyber Threats
A Dutch intelligence advisory raises the stakes on Russian camera-hijacking activity — critical-infrastructure defender teams review IP-camera posture this week.
Nation-State Cyber Threats
CERT-UA names UAC-0145 as the Sandworm sub-cluster behind the ClickFix CAPTCHA activity against Ukrainian devices - a GRU-affiliated crew, and defender awareness for Ukraine-adjacent teams this weekend.
Supply Chain Attack
A code-signing-integrity attribution against a Chinese cybercrime subgroup — and a prompt for supply-chain defenders to review how much trust their pipelines place in a valid signature.
Nation-State Cyber Threats
Another Southeast-Asia-focused espionage cluster documented by Kaspersky — a defender research review this week for government and diplomatic entities in the region.
Nation-State Cyber Threats
ClickFix migrates from financially motivated crime to nation-state activity, according to Ars Technica's report on Russia's Sandworm cluster - a defender-awareness read for this week.
Nation-State Cyber Threats
Another Contagious Interview variant with a novel SVG delivery angle — a defender-oriented research review of how North Korea-linked actors hid an OtterCookie-aligned payload inside flag images sent through fake coding challenges.
Nation-State Cyber Threats
A dormant China-linked kernel rootkit surfaces again in Taiwan with a new backdoor companion — defender research review this week.