Threat Intelligence
Kaspersky Details Umbrij, a New ToddyCat Tool Targeting Corporate Gmail via OAuth Tokens
An APT-tooling disclosure with corporate-Gmail implications — defender teams review OAuth-token hygiene this week.
Coverage of nation-state cyber threats, including government-backed hackers, cyber espionage campaigns, and geopolitical cyberattacks targeting critical infrastructure and global organizations.
Threat Intelligence
An APT-tooling disclosure with corporate-Gmail implications — defender teams review OAuth-token hygiene this week.
Artificial Intelligence (AI)
A senior US-intelligence framing lands mid-cycle — how AI-cyber policy hardens in focus this week.
Cybercrime
A coordinated US law-enforcement push against a Russian-intelligence messaging-app campaign pairs a Rewards for Justice bounty with an FBI advisory on Signal backup-recovery-key theft.
Data Breaches
Fresh reporting around the Jaguar Land Rover cyber incident pegs the toll near $2.5 billion and points to Russian-linked actors — a scale-significant automotive-manufacturing disclosure whose figure source and attribution both warrant careful reading.
Nation-State Cyber Threats
A Russian-intelligence campaign against messaging-app credentials, documented by Ukraine, uses fake support texts to coax Signal and WhatsApp users into surrendering the codes that unlock their accounts.
Nation-State Cyber Threats
Another Russia-linked backdoor lands on defenders' desks for review. Google Threat Intelligence Group and Mandiant have detailed STOCKSTAY, a .NET implant Turla has deployed against Ukrainian government and military networks since at least 2022.
Mobile Security
Cellebrite's stated sales-restriction practice gets fresh scrutiny via human-rights documentation, after researchers tied its forensic tooling to a jailed Russian activist's iPhone months after the company said it had pulled out.
Nation-State Cyber Threats
Australian government and intelligence officials disclosed nation-state activity against the country's critical infrastructure that, they assessed, could enable disruption at a time of the actor's choosing — landing amid a wave of Five-Eyes warnings.
Artificial Intelligence (AI)
A multilateral statement raises the temperature on AI's cybersecurity implications, with the Five Eyes agencies warning leaders that frontier models are compressing the timeline for both offensive and defensive cyber change.
Supply Chain Attack
Microsoft's attribution analysis ties the JavaScript-ecosystem compromise to a North-Korea-linked cluster, assessing with high confidence that the actor it tracks as Sapphire Sleet published poisoned Mastra packages to reach developers and crypto wallets.
Nation-State Cyber Threats
NCSC UK's CEO puts a number on hostile-state activity — three-quarters of attacks on UK critical systems. The figure, drawn from a year of incident response, reframes the threat as a sustained contest.
Nation-State Cyber Threats
Another published-research disclosure for defenders to review for indicator relevance: researchers at Genians named NarwhalRAT, a remote access trojan they attribute to a North Korean-linked cluster, and published indicators worth checking against your own telemetry.