Advanced Persistent Threat (APT) stories
Older, internet-facing IIS servers are being singled out by China-linked hackers, with one new cluster able to persist despite partial containment.
Nearly 100 organisations were hit in a six-week phishing spree that used GitHub repositories and Visual Studio Code tools to infect developers.
CrowdStrike said state-backed espionage and extortion are surging as AI assets inside tech groups draw hackers seeking code, models and access.
Businesses in Europe and Africa now face localised phishing and malware attacks from a suspected China-aligned group that has widened beyond Asia.
The report says Chinese threat groups are now tracking oil, reconstruction and strategic technologies across Venezuela, Syria, South Korea and the Gulf.
European ministries face a stealthier cyber-espionage campaign as Webworm shifts to Discord and Microsoft cloud tools to steal data.
Repeat breaches exposed an Azerbaijani oil and gas operator to espionage as FamousSparrow exploited Microsoft Exchange flaws for two months.
AI is now being used to write exploits and malware, with Google saying it has traced the first zero-day linked to machine assistance.
Security teams face a broader threat as criminals and state-backed actors use generative AI to speed hacks, phishing and malware.
Small defence contractors are left exposed as state-backed hackers spend years mapping supply chains and laying covert access routes before striking.
Diplomatic missions in Europe and the Middle East face renewed PlugX-backed espionage as TA416 shifts tactics and targets amid regional tensions.
Businesses face credential theft and reinfection risks as DeepLoad hides inside trusted Windows processes and evades routine clean-up.
Existing Threat Scan customers get new free tools to spot ransomware in backups before restoration, reducing the risk of reinfecting production systems.
Dormant implants in carrier systems could expose subscriber data and signals across Europe and APAC, Rapid7 warned.
Iran-linked cyber attacks are spreading beyond the Middle East, with firms tied to Israel or the US warned they face heightened global risk.
Iranian state-aligned hackers are shifting from spying to destructive cyber strikes, putting Western critical infrastructure on high alert.
Attackers push fake Red Alert Android app via SMS, turning Israel rocket warning tool into spyware that steals messages, contacts and location.
New research links Iran conflict to a swift surge in tightly targeted cyber espionage across Middle Eastern governments and embassies.
Attackers are now moving fast enough that patching delays, standing privilege and inherited trust leave organisations exposed within minutes.
Operational technology outages are leaving most manufacturers and critical infrastructure firms facing losses of up to GBP £5 million, a survey found.