Back to Feed

Tag

Nation-state

State-sponsored campaigns, APT operations, cyber warfare

50 items tagged #nation-state

Articles

RT @DarkWebInformer: ‼️ LAPSUS$ Group announces a joint for sale post with TeamPCP for the GitHub...

LAPSUS$ Group collaborates with TeamPCP to sell GitHub internal repositories.

Another Windows zero day released by Nightmare Eclipse (sort of) It turns out Microsoft just str...

Microsoft failed to properly patch 2020 Windows CVE, allowing Nightmare Eclipse exploitation.

🚨 Nightmare Eclipse just released another vulnerability called MiniPlasma GitHub: https://t.co/...

Nightmare Eclipse releases MiniPlasma vulnerability (CVE-2020-17103) in Windows Cloud Files Mini Filter Driver

Maximum Severity Cisco SD-WAN Bug Exploited in the Wild

Cisco SD-WAN maximum severity vulnerability exploited in active attacks.

CVE-2026-20182: Critical Cisco SD-WAN Auth Bypass Under Active Exploitation

Cisco SD-WAN Controller/Manager CVE-2026-20182 critical auth bypass under active exploitation

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Cisco patches critical SD-WAN Controller authentication bypass (CVE-2026-20182) exploited in active zero-day attacks.

1/2‼️🇬🇹 Guatemalan Ministry of Finance allegedly breached: 130,000 RGAE registrations and 235,0...

Guatemalan Ministry of Finance allegedly breached; 130K RGAE registrations and 235K PDFs exposed via IDOR.

‼️🇮🇶 Iraqi Ministry of Interior allegedly breached: 2025-2026 census data exposed from the Iraq...

Iraqi Ministry of Interior breached; 2025-2026 census and civil registry data exposed for sale.

Kazuar: Anatomy of a nation-state botnet

Microsoft details Kazuar, a modular P2P botnet attributed to Russian state actor Secret Blizzard.

Researcher Drops YellowKey, GreenPlasma Windows Zero-Days

Researcher publicly discloses YellowKey BitLocker bypass and GreenPlasma privilege escalation zero-days in Windows.

Ministry of Health of Vietnam Allegedly Breached Exposing 480,000 Medical Staff Records From the Vietnamese Government Health Authority

Threat actor claims breach of Vietnamese Ministry of Health exposing 480,000 medical staff records.

‼️🇻🇳 Ministry of Health of Vietnam Allegedly Breached Exposing 480,000 Medical Staff Records Fr...

Vietnam's Ministry of Health allegedly breached, exposing 480,000 medical staff records.

CI Fortify | CISA

CISA launches CI Fortify initiative urging critical infrastructure operators to prepare for geopolitical conflict

LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly

LatAm Vibe threat campaigns use AI agents to generate custom hacking tools targeting Mexico and Brazil.

Government to Scrutinize Instructure Over Canvas Disruption, Data Breach

US House Committee demands briefing on Instructure Canvas data breach affecting 275M individuals

Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended

ShinyHunters' clearnet domain suspended after Canvas LMS attacks; group relocates to dark web.

Yippie Two new Microsoft Windows 0days. The exploits have cool and badass mysterious names to be...

Two new Microsoft Windows zero-day vulnerabilities disclosed with codenames GreenPlasma and YellowKey.

Two more public disclosures, it will never stop

Researcher discloses two Microsoft vulnerabilities via GitHub, threatens escalation.

Public Authority for Civil Information Allegedly Breached Exposing 5.23 Million Kuwaiti Citizen Records From the Kuwaiti Government Identity Authority

Kuwait's Public Authority for Civil Information breached, exposing 5.23M citizen records and sensitive government

‼️🇰🇼 Public Authority for Civil Information Allegedly Breached Exposing 5.23 Million Kuwaiti Ci...

Kuwait's Public Authority for Civil Information breached, exposing 5.23M citizen records.

New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots

TrickMo Android banking trojan variant uses TON blockchain for C2 and SOCKS5 proxying across France, Italy, Austria.

‼️🇫🇷 La Suite Numérique allegedly breached exposing over 18 million records from the French gov...

La Suite Numérique breach exposes 18M+ records from French government digital workspace.

Over 500 Organizations Hit in Years-Long Phishing Campaign

Operation HookedWing phishing campaign steals 2,000+ credentials from 500+ organizations over four years.

‼️🇬🇧 LAPSUS$ Group has leaked the data of Vodafone. https://t.co/lEyJoScTp6

LAPSUS$ Group claims to have leaked Vodafone customer data.

‼️🇮🇷 Iran Nuclear allegedly breached with 77.56 GB of data threatened for release under "Pay Or...

Threat actor claims 77.56 GB breach of Iranian nuclear program data with extortion demand.

‼️🇮🇩 Indonesian Ministry of Transportation (Dishub) allegedly breached exposing 93GB+ of vehicl...

Indonesian Ministry of Transportation database with 93GB+ vehicle and owner records allegedly breached.

‼️🇨🇦 CarePoint Health allegedly listed on Genesis ransomware leak site with 70GB countdown The...

Genesis ransomware group lists CarePoint Health with 70GB data and 4-day publication countdown.

1/2‼️🇮🇳 BLS International allegedly breached exposing 29 million records, source code, and SSH...

BLS International allegedly breached, exposing 29M records, source code, and SSH keys.

‼️🇺🇸 Houghton Mifflin Harcourt Company has been added to the ShinyHunters Pay or Leak portal ht...

Houghton Mifflin Harcourt added to ShinyHunters extortion portal.

1/2‼️🇻🇪 MAJOR CLAIM: SAIME, SAREN, and Carnet Fronterizo allegedly breached exposing 35M Venezu...

Threat group 'L4TAMFUCKERS' claims breach of Venezuelan identity systems exposing 35M IDs and 13.4M birth certificates.

Ransomware negotiator tied to $56M in attacks was sentenced, DPRK-linked fraudulent IT worker sch...

Ransomware negotiator sentenced for $56M attacks; DPRK IT fraud disrupted; PCPJack targets cloud credentials; Palo Alto

In Other News: Train Hacker Arrested, PamDOORa Linux Backdoor, New CISA Director Frontrunner

SecurityWeek roundup: US targets 72-hour patch cycles, PamDOORa Linux backdoor, CISA director frontrunner named.

CISA gives feds four days to patch Ivanti flaw exploited as zero-day

CISA mandates four-day patch deadline for zero-day Ivanti EPMM flaw being actively exploited.

Polish Security Agency Reports ICS Breaches at Five Water Treatment Plants

Polish security agency reports ICS breaches at five water treatment plants with state-sponsored attribution.

Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks

Ivanti patches CVE-2026-6973 zero-day in EPMM exploited in targeted attacks.

Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State Hacking

Palo Alto Networks zero-day CVE-2026-0300 exploited by likely Chinese state-sponsored group CL-STA-1132.

‼️🇺🇾 Antel TuID Digital Allegedly Breached Exposing 8GB of Data From the Uruguayan State Teleco...

Antel TuID Digital, Uruguay's state telecom e-government platform, allegedly breached exposing 8GB of data.

PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage

PAN-OS CVE-2026-0300 RCE under active exploitation by suspected state-sponsored actors.

Looks the Outlook Web App of "Mpumalanga Department of Social Development (a provincial governmen...

South African provincial government's Outlook Web App compromised to host PlugX malware samples.

Palo Alto Networks firewall zero-day exploited for nearly a month

Palo Alto Networks firewall zero-day exploited by state-sponsored hackers for nearly a month.

Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion

Threat actors used Claude AI to guide attack on Mexican water utility's OT systems in January 2026.

In this @WIRED video about fast16, @a_greenberg walks through the whole arc: A 2005 sabotage mal...

20-year-old sabotage malware from 2005 identified after NSA leak exposure.

1/2‼️🇦🇷 Argentine government and https://t.co/0cuZke1yBc allegedly breached exposing 80M creden...

Argentine government and educational institutions breached, 80M credentials exposed.

‼️🇧🇷 CEMIG allegedly breached exposing a 190GB Watson instance dump from the Brazilian energy u...

CEMIG Brazilian utility allegedly breached; 190GB Watson dump offered for sale.

‼️🇭🇰 KGI (https://t.co/Ls4XAbNDQk) allegedly breached exposing 5M+ Hong Kong stock investor rec...

FuckSpy threat actor offers 5M+ Hong Kong KGI investor records for sale.

Rowhammer Attack Against NVIDIA Chips - Schneier on Security

Rowhammer attacks on NVIDIA Ampere GPUs enable full system compromise via GDDR bitflips.

CISA: Critical Infrastructure Must Master Isolation, Recovery

CISA issues CI Fortify guidance for critical infrastructure to master isolation and recovery against nation-state

Palo Alto Networks warns of firewall RCE zero-day exploited in attacks

Palo Alto Networks reports critical PAN-OS User-ID portal RCE zero-day under active exploitation.

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Palo Alto PAN-OS buffer overflow CVE-2026-0300 under active exploitation enables unauthenticated RCE.

Palo Alto Networks to Patch Zero-Day Exploited to Hack Firewalls

Palo Alto Networks patches critical PAN-OS zero-day buffer overflow in Captive Portal affecting PA/VM firewalls.