A case involving two former intelligence-sector figures accused of links to Russian services points to a larger change in tradecraft: human networks, data, AI, and cyber access are increasingly converging.
A reported intrusion tied to Thailand's finance ministry shows how an open-source agent in "YOLO mode" can turn approval bypass into a serious security problem.
Researchers identified a cyber-espionage campaign targeting Thailand’s Ministry of Finance in which hackers reportedly used an autonomous AI agent, a signal that agentic systems are entering offensive tradecraft.
A roundup touching malware, kernel flaws, webmail espionage, industrial gear, and ransomware shows how varied threat activity can pressure security teams at once.
A zero-day in Zimbra Classic UI let a malicious message run code inside the webmail session, shifting the attack goal from inbox access to broader account and identity theft.
An open staging host tied to the JadeProx label allegedly revealed shell history, webshell paths, phishing material, and a post-exploitation toolkit, offering a rare look at how operators organize a multi-stage campaign.
A suspected espionage campaign aimed at Signal users shows how phishing, account abuse, and device linking can threaten a secure messenger without breaking its encryption.
Dutch intelligence warnings point to a familiar weak spot in modern security: exposed IP cameras that can be repurposed for surveillance, reconnaissance, and broader network risk.
A suspected compromise at South Korea’s diplomatic academy is a reminder that foreign-policy institutions can be prized targets even when the technical path remains hidden.
A reported APT42 campaign shows how patient messaging, trusted cloud services, and a PowerShell backdoor can turn ordinary conversation into an intrusion path.
A new State Department accusation about Cuban infiltration points to a familiar but often overlooked danger: trusted access can matter more than malware.
A newly described espionage implant is using Microsoft 365 calendar objects as a covert relay, showing how trusted cloud APIs can double as low-noise channels for command and data theft.
The arrest-linked investigation in Italy points less to a flashy hack than to a harder problem: how insiders, privileges, and sensitive repositories can be turned into a quiet intelligence channel.
A newly identified malware family linked to Southeast Asian government and diplomatic targets shows how modern espionage often depends on staged access, credential harvesting, and delayed exfiltration rather than loud disruption.
A Go-based remote access trojan linked to government and diplomatic targets in Southeast Asia shows how long dwell time and ordinary file services can make espionage harder to spot.
A Go-based backdoor, stolen credentials, and share-based transfer paths point to an espionage workflow built for patience, not noise.
The European Union publicly condemned what it called Russia’s “malicious cyber ecosystem” and linked the FSB’s 16th Centre to Turla operations, turning attribution into a political and technical signal.
A Taiwan-linked intrusion shows how old espionage implants and newly observed SYSTEM-level malware can sit side by side without revealing the full playbook behind them.
An allegation involving Italian politicians, journalists, and managers on Signal is a reminder that secure messaging is only as strong as the phone, account, and linked sessions behind it.
A suspected espionage effort aimed at a narrow circle of Italian figures shows how encrypted messaging can still be pressured through identity checks, linked devices, and account control.