Supply Chain Compromise: Russian Backdoor Detected in NERO R-ONE Traffic Cameras
A sophisticated supply chain attack has targeted Slovakia's critical transport infrastructure through the procurement of NERO R-ONE high-speed traffic cameras. The compromise involved a Cyprus-based shell company utilizing fraudulent certifications to secure no-bid contracts, bypassing standard security vetting. Investigation by the National Security Authority (NBU) identified a hardware-level backdoor within the devices, facilitating remote code execution (RCE) via SMS-based command-and-control (C2) using hardcoded Russian mobile numbers. This vulnerability allows for unauthorized remote manipulation of traffic data and potentially high-level espionage against government facilities, representing a significant escalation in Russian hybrid warfare tactics within the European Union.
Iranian-Linked Cyber Av3ngers Campaign Targeting Unitronics PLCs
IRGC-linked threat actor "Cyber Av3ngers" is targeting U.S. critical infrastructure by exploiting internet-exposed Unitronics Programmable Logic Controllers (PLCs). Attackers leverage default credentials and exposed web interfaces to manipulate PLC logic and disrupt industrial control protocols, specifically targeting the water and wastewater sectors across 12 states. Impact includes operational downtime of up to 12 hours in municipalities such as Cape May and Childersburg. The campaign signals a shift toward kinetic operational disruption via the manipulation of Modbus and proprietary Unitronics communication patterns, requiring immediate remediation of internet-facing OT assets.
Patchcord APT: Custom Backdoor Campaign Targeting South Asian Critical Infrastructure
The Patchcord APT group has deployed a bespoke, custom-engineered backdoor (PE/ELF) targeting critical infrastructure, telecommunications, and government sectors across South Asia. The campaign utilizes a sophisticated C2 infrastructure to facilitate long-term intelligence gathering and surveillance of regional telecom traffic and government communications. Persistence is achieved through registry modifications, scheduled tasks, and service injection. Technical artifacts indicate the use of specialized lateral movement toolsets tailored for telecom network architectures and obfuscated data exfiltration methods. This operation poses a severe risk to national security and operational stability through the strategic exfiltration of sensitive government metadata and real-time traffic.
Kimsuky Integration of Local LLMs Ollama, GPT4All, Msty and GitHub C2
Kimsuky, a North Korean-linked threat actor, is evolving its social engineering and command-and-control (C2) methodologies through the integration of local Large Language Models (LLMs) and developer-centric infrastructure. By utilizing local frameworks such as Ollama, GPT4All, and Msty, the group generates high-fidelity AI-driven decoy documents to enhance spear-phishing efficacy while maintaining operational security against cloud-based monitoring. Concurrently, Kimsuky is leveraging GitHub and Git for C2 communication and payload distribution, alongside "Living-off-the-Land" (LotL) techniques using PowerShell and LNK files. This shift from manual phishing to AI-augmented, infrastructure-obfuscated operations targets diplomatic, military, and cryptocurrency sectors, necessitating a transition from signature-based detection to advanced behavior-based EDR and SaaS usage monitoring.
Chinese State-Sponsored Ransomware Campaigns Exploiting N-able RMM and Microsoft SharePoint
Chinese state-sponsored threat actors are pivoting from long-term espionage to high-velocity ransomware deployment. By exploiting critical vulnerabilities in Microsoft SharePoint and weaponizing N-able Remote Monitoring and Management (RMM) tools, attackers have compressed the dwell time from weeks to hours. This strategy leverages legitimate administrative software for lateral movement and automated payload execution, targeting Managed Service Providers (MSPs) and global enterprise sectors to maximize disruptive impact and financial gain while evading traditional detection mechanisms through the use of trusted system tools.
PolinRider: DPRK Supply Chain Offensive Targeting npm, Claude Code, and GitHub CLI
North Korean state-sponsored actors, associated with the PolinRider operation and Contagious Interview campaign, are executing a multi-vector supply chain offensive targeting the developer ecosystem. By compromising GitHub maintainer accounts and utilizing package impersonation, the actors injected malicious code into npm, Packagist, and Go ecosystems. The campaign specifically targets modern toolchains, including Claude Code and GitHub CLI, to deploy Windows Remote Access Trojans (RATs), Linux native C rootkits, and credential stealers aimed at SSH keys and developer tokens. With over 108 unique malicious packages and extensions identified, the operation seeks persistent high-level access to DevOps environments and AI-assisted coding workflows.
Counter-Intelligence Operation Against North Korean State-Sponsored APT Infrastructure
Security researcher Vangelis Stykas conducted an active defense operation by infiltrating the command-and-control (C2) infrastructure of North Korean state-sponsored threat actors. Through two years of persistent access to adversary servers, Stykas exfiltrated internal databases, C2 configurations, and victim lists, revealing hundreds of compromised networks worldwide. The operation uncovered a significant "visibility gap," demonstrating that current industry telemetry drastically underestimates the scale of North Korean espionage and financial theft. The breach provided direct access to the actors' custom toolsets, persistence mechanisms, and lateral movement logs across diverse sectors including finance, defense, and cryptocurrency.
Dropping Elephant Patchwork Espionage APT: Multi-Platform Tactics and Tooling
Dropping Elephant, also known as Patchwork, is a persistent espionage-focused APT active since late 2015. The actor employs a dual-platform attack strategy targeting high-value sectors including defense, energy, and government across Asia, Europe, Türkiye, and the United States. On Windows, the group utilizes malicious .lnk files disguised as PDF documents to execute obfuscated PowerShell downloaders and staged payloads. Simultaneously, the threat actor deploys trojanized Android applications via social engineering and romance-themed lures. These mobile payloads facilitate extensive data exfiltration, including keystroke logging, call recording, and message interception, enabling long-term intelligence gathering and organizational espionage.
Russian Intelligence Espionage Campaign Targeting IP Cameras and IoT Edge Devices
Russian intelligence services are leveraging remote access vulnerabilities in IP camera firmware to compromise IoT edge devices across the Netherlands and NATO member states. The operation targets internet-exposed physical security infrastructure to facilitate real-time surveillance of NATO military logistics and weapon shipments destined for Ukraine. By exploiting firmware flaws, the actors maintain persistence on edge devices to transform civilian and commercial surveillance hardware into a distributed espionage network for strategic military intelligence gathering.
China-Nexus JDY Botnet Expands SOHO/IoT Infrastructure for Targeted Reconnaissance
China-nexus state-sponsored actors have scaled the JDY botnet to over 1,500 compromised SOHO and IoT devices, serving as a high-performance reconnaissance engine following the disruption of the KV-botnet. Targeting MIPS and MIPSEL Linux architectures, the botnet utilizes Tor-based C2 to orchestrate high-speed SYN scanning, banner grabbing, and TLS certificate collection. This infrastructure is primarily used for the industrialized mapping of U.S. military assets and critical infrastructure in the energy and defense sectors. By leveraging compromised edge devices from vendors like Cisco and Ubiquiti, actors mask malicious traffic within residential IP space to bypass geolocation and reputation-based filters during the preparation phase of the kill chain.
Tata Electronics: Supply Chain Breach Compromising Apple and Tesla Intellectual Property
A sophisticated supply chain breach targeting Tata Electronics has resulted in the exfiltration of critical intellectual property belonging to downstream clients, including Apple and Tesla. The threat actor, identified as "World Leaks," bypassed the robust perimeters of primary tech corporations by targeting the manufacturer's IT infrastructure. Compromised assets reportedly include sensitive CAD schematics, manufacturing processes, proprietary firmware, and technical specifications related to iPhone production and Tesla vehicle components. Investigations are currently focused on determining whether initial access was achieved via phishing, exploited VPN vulnerabilities, or third-party software supply chain compromises. This incident highlights the systemic risk of secondary targeting in high-tech manufacturing ecosystems.
Fortinet FortiGate: Industrial-Scale 'FortiBleed' Credential Exposure
The 'FortiBleed' campaign targeted approximately 74,000 internet-facing Fortinet FortiGate firewalls across 194 countries. Threat actors exploited an open directory vulnerability or misconfiguration to extract configuration files containing authentication hashes. Utilizing a specialized 45-GPU cluster, attackers conducted an estimated 1.16 billion brute-force attempts to crack these hashes, gaining unauthorized administrator and SSL VPN access. This initial perimeter breach served as a gateway for lateral movement into internal enterprise networks, specifically targeting Active Directory (AD) for privilege escalation and full domain compromise.
Telegram Bot API Abuse in Middle East Government Espionage Campaign
An East Asian threat actor is targeting Middle Eastern government entities using a multi-stage malware chain consisting of TELESHIM, MIXEDKEY, and BINDCLOAK. The operation leverages the Telegram Bot API for HTTPS-based Command and Control (C2), effectively blending malicious traffic with legitimate encrypted communication to bypass traditional network monitoring. To evade Endpoint Detection and Response (EDR) and automated sandboxes, the attackers utilize environmental keying, ensuring execution occurs only on specific, high-value target systems. The primary objective is long-term espionage and strategic data exfiltration from public sector organizations.
Rhysida, Interlock, and The Gentlemen: Modular Supply Chain Targeting VMware ESXi
Rhysida and Interlock ransomware operations have shifted to a modular supply chain model, leveraging Initial Access Brokers (IABs) and specialized crypter services to target VMware ESXi hypervisors. By employing the "GentleKiller" framework—an EDR-terminating toolset targeting over 400 security processes across 48 products—affiliates (including Storm-2697) disable guest-level defenses before deploying Go-based, self-propagating encryptors. This strategy enables the mass encryption of multiple virtual machines simultaneously at the virtualization layer, utilizing per-file ephemeral key encryption to maximize operational paralysis and extortion leverage.
HOLLOWGRAPH Campaign Abuses Microsoft 365 Graph API for Stealthy C2
The HOLLOWGRAPH espionage campaign utilizes a .NET DLL implant to establish stealthy command-and-control (C2) by abusing the Microsoft Graph API. The malware hijacks compromised Microsoft 365 mailboxes, using calendar appointments specifically dated to May 13, 2050, as dead-drop resolvers for operator instructions and data exfiltration. By routing traffic through legitimate Microsoft cloud infrastructure, the operation bypasses traditional network monitoring and avoids the use of attacker-controlled infrastructure. Linked to the Cavern C2 framework and suspected Iranian-nexus actors (Lyceum), the campaign has primarily targeted entities in Israel; no patch is available as it leverages legitimate platform functionality.
GitHub Internal Repository Breach via Poisoned Nx VS Code Extension
A high-impact supply chain attack has compromised approximately 3,800 of GitHub's internal repositories. The breach originated from a poisoned version of the 'nrwl.angular-console' (Nx Console) Microsoft Visual Studio Code extension. By infiltrating a GitHub employee's development environment, the threat actor likely leveraged token-stealing mechanisms or a VS Code zero-day vulnerability to exfiltrate authentication tokens and access proprietary source code. The compromised data, including sensitive internal intellectual property, has reportedly been listed for sale on underground dark web forums. This incident highlights critical risks in developer tooling and the potential for secondary compromises through stolen credentials.
Mirage Kitten Deploys NightLedger Backdoor and WebSocket Tunneling Tools
The Iranian state-sponsored actor Mirage Kitten (also tracked as Nimbus Manticore and UNC1549) is conducting a cyber-espionage campaign targeting organizations across the Middle East, Africa, and South Asia. The group utilizes a previously undocumented Windows backdoor named NightLedger to establish persistent access. To evade network security controls, the actor employs two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, which encapsulate C2 traffic to bypass traditional firewall restrictions and network detection systems.
Nova Ransomware Group Attack on Universitas Nasional
The Nova Ransomware Group has claimed a successful breach of Universitas Nasional, part of an aggressive expansion targeting high-value academic, government, and professional services sectors. Utilizing a double-extortion model, the threat actor prioritizes massive data exfiltration—with recent breaches of KPMG Netherlands and Universitat de València yielding between 300GB and 500GB of data. The campaign likely utilizes initial access via RDP brute-forcing or edge device exploitation, followed by lateral movement and exfiltration using tools like Rclone or FileZilla. This incident risks the exposure of student PII, faculty research, and administrative credentials, posing a significant threat of secondary extortion through dark web leak sites.
Supply Chain Compromise of ViPNet Secure Communication Software
Threat actors compromised the update mechanism of ViPNet secure communication software by injecting malicious code into trusted binaries. By leveraging compromised digital signatures, attackers bypassed perimeter defenses to target Russian government agencies and critical infrastructure. The operation utilized modified software updates to establish long-term persistence and facilitate lateral movement across defense, energy, and finance sectors. The campaign is characterized by the use of specialized post-exploitation toolsets and C2 infrastructure designed to maintain stealth within high-security, government-grade environments.
CyberAv3ngers Target Unitronics, Federal Signal, and Genmark Siren Controllers in Psychological Warfare Campaign
The IRGC-linked threat actor CyberAv3ngers is executing a targeted campaign against critical infrastructure, specifically exploiting internet-facing Unitronics Vision PLCs, Federal Signal, and Genmark siren controllers. By leveraging weak or default credentials and unauthorized access to Human-Machine Interfaces (HMIs), the group manipulates emergency alert protocols and public warning systems. This shift from technical sabotage to "cyber-psychological warfare" aims to trigger mass public panic and erode societal trust in civil safety mechanisms. The campaign serves as a non-kinetic extension of regional geopolitical tensions, requiring urgent hardening of OT network segmentation and credential management to prevent mass societal destabilization.
Emergency Security Patching for Microsoft Windows Netlogon and Defender Zero-Days
Microsoft has released emergency security patches to address several critical vulnerabilities, most notably CVE-2026-41089, a Windows Netlogon Remote Code Execution (RCE) flaw currently under active exploitation. The threat, associated with the "BlueHammer" campaign, leverages this flaw to achieve total domain compromise through "domain-killing" mechanics. Additionally, at least three zero-day vulnerabilities in Microsoft Defender have been identified, compromising endpoint security integrity. These vulnerabilities affect the Windows kernel and core network services, providing attackers with high-privilege access and the ability to bypass standard security controls. Organizations must remediate these flaws before the June 2026 deadline to prevent widespread enterprise infiltration and potential loss of Active Directory integrity.
Parallel Intrusion: Storm-2603 and Unattributed Actors Target Microsoft SharePoint
Parallel intrusions were identified in on-premises Microsoft SharePoint environments via the exploitation of CVE-2025-49704, CVE-2025-49706, and CVE-2025-53770. Two distinct threat actors operated concurrently: Storm-2603, a ransomware group utilizing BYOVD and legitimate remote tools, and an unattributed actor focused on Active Directory (AD) credential theft via DLL sideloading and custom backdoors. This overlapping activity created significant "signal noise," complicating forensic detection and containment. The intrusions highlight a critical failure in patching internet-facing legacy infrastructure, enabling both immediate financial extortion and long-term espionage within the same network perimeter.
Dragonforce Ransomware Group Abuses Microsoft Teams for C2 in Aptora Intrusion
The Dragonforce ransomware group has executed a sophisticated intrusion against Aptora, a major U.S.-based civil engineering firm, by employing a "Living off Trusted Services" (LOTS) technique. The attackers deployed 'Backdoor.Turn', a custom Go-based Remote Access Trojan (RAT), which utilizes the Microsoft Teams relay infrastructure for Command-and-Control (C2). By routing malicious traffic through legitimate Microsoft SaaS endpoints, the group successfully masked C2 communications as standard HTTPS/TLS telemetry and messaging. This method allows the threat actor to bypass traditional network security monitoring and EDR solutions, facilitating long-term persistence and increasing the risk of large-scale data exfiltration and subsequent ransomware deployment.
US DOJ Charges Russian National Denis Obrezko for Facilitating Large-Scale Ransomware Operations
The U.S. Department of Justice has charged Denis Obrezko, a Russian national extradited from Thailand, for providing critical infrastructure to Russia-aligned ransomware syndicates. Obrezko allegedly managed Command and Control (C2) servers, proxy networks, and access brokerage tools used to compromise U.S. corporate entities, including industrial targets like Westinghouse. By facilitating initial access and maintaining persistence via specialized infrastructure, Obrezko enabled the deployment of ransomware strains and the subsequent extortion of victims via cryptocurrency. This operation specifically targets the "facilitator" layer of the cybercrime ecosystem to disrupt the supply chain of access brokerage used by APTs and ransomware groups.
INC Ransomware: Technical Evolution to Lynx RaaS
INC Ransomware has evolved into Lynx RaaS, transitioning its core encryption engine to a Rust-based codebase to enhance execution speed, ensure memory safety, and bypass modern EDR/XDR detections. By capitalizing on the disruption of LockBit and BlackCat, the group recruited high-tier affiliates, claiming over 830 victims since August 2023. The operation utilizes sophisticated RaaS management panels for affiliate deployment, though researchers have identified vulnerabilities within the group's backend infrastructure. This transition signals a professionalization of their operational security and technical capabilities, posing a heightened risk to global enterprises.
Dreamfyre Ransomware Breach of GkNur Gıda
GkNur Gıda has been targeted by the Dreamfyre ransomware group, resulting in the unauthorized exfiltration of sensitive organizational data and the encryption of critical system assets. The attack likely involved an initial compromise via RDP exploitation or VPN vulnerabilities, followed by lateral movement using Cobalt Strike beacons and Mimikatz for privilege escalation. The threat actors employed double extortion tactics, leveraging tools such as Rclone and MegaSync to exfiltrate PII and financial records prior to deploying a payload utilizing AES-256 and RSA-2048 encryption. This incident underscores the persistent risk of emerging ransomware splinter groups targeting food production supply chains to maximize operational leverage.
APT28 Exploitation of Edge Device Vulnerabilities and EOL Hardware
Russian-linked threat actor APT28 is strategically targeting network edge devices—including VPN concentrators, firewalls, and gateways—to establish persistence and bypass host-based security controls such as EDR and MFA. By exploiting vulnerabilities in unpatched or End-of-Life (EOL) firmware, APT28 implements perimeter traversal chains that remain invisible to standard endpoint monitoring. This campaign specifically targets US Federal agencies and critical infrastructure, creating high-risk entry points into Cyber-Physical Systems (CPS). Remediation is mandated via CISA advisory AA26-097A, requiring the immediate replacement or patching of unsupported edge hardware to eliminate unpatchable attack surfaces.
The Operationalization of Criminal AI-as-a-Service: FraudGPT, BruteForceAI, and Xanthorox
The 2026 threat landscape is defined by the operationalization of Criminal AI-as-a-Service (C-AIaaS), utilizing platforms like FraudGPT, BruteForceAI, and Xanthorox to compress the attack lifecycle. Technical vectors include specialized jailbreak wrappers for LLM safety bypass and virtual camera injection for real-time deepfake KYC bypass. Attackers leverage hijacked enterprise API keys for unauthorized compute and use LLMs to systematically analyze exfiltrated RAG embeddings. This shift has reduced average eCrime breakout times to 29 minutes and increased phishing click-through rates to 54% by eliminating traditional linguistic indicators of fraud.
Zero-Day Exploitation of Oracle PeopleSoft by UNC6240
UNC6240 (ShinyHunters) conducted a zero-day exploitation campaign targeting Oracle PeopleSoft (PeopleTools 8.61 and 8.62) between May 27 and June 9, 2026. The actors exploited CVE-2026-35273, a critical Server-Side Request Forgery (SSRF) vulnerability (CWE-918) in the Updates Environment Management component, to achieve unauthenticated Remote Code Execution (RCE). Following initial access, the group deployed MeshCentral remote management agents disguised as Microsoft Azure services to maintain persistence and perform reconnaissance. Data was compressed using 'zstd' and exfiltrated for extortion on the ShinyHunters Data Leak Site. CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on June 12, 2026, following widespread targeting of the higher education sector.
Cisco Catalyst SD-WAN Authentication Bypass Zero-Day
A critical authentication bypass vulnerability, tracked as CVE-2026-20182, has been identified in the peering authentication mechanism of the Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager. Exploited in the wild by the sophisticated threat actor UAT-8616, this flaw allows unauthenticated attackers to bypass security checks, facilitating unauthorized access to the SD-WAN infrastructure. The vulnerability carries a CVSS score of 10.0, posing a maximum risk of full control plane compromise, which could enable large-scale network traffic interception or redirection. Organizations are urged to apply official Cisco patches immediately to prevent targeted exploitation and potential network-wide lateral movement or data exfiltration.