Silent Push: A North Korean IT worker was recruiting Westerners to be his face — they sit on camera and talk to the client, he feeds answers and writes the code. The ad turned up on a Discord server for writing mouse reviews. Split: 35% proxy, 65% him. https://t.co/lit2DWWPwZ
Zscaler: Pakistan-nexus threat actor APT36 used four newly identified tools in activity against government and defense organizations in India and Afghanistan. https://t.co/ynVeeaREyG
DomainTools: A leaked Russian framework called Lemmings industrialises the creation and upkeep of fake online personas. It was built by Okenit, a St Petersburg firm licensed for state-secret work, about eleven miles from the old Internet Research Agency. https://t.co/I6Kjs3FHwF
Acronis: Red Heron weaponised a Gitea n-day within days, kept a 477-system Taiwan target list and sorted targets into Simplified Chinese categories — defence, election systems, energy, aerospace. Acronis assesses a PRC-linked context, moderate confidence. https://t.co/4y5JJAYfBc
WSJ: A trove of internal data belonging to a China-based cybersecurity company, Zhengzhou Zhirong Network Technology Co., or ZRON, was reviewed by The Wall Street Journal. The material includes intelligence reports internal chat logs, and a slide deck. https://t.co/vFNFCorGRm
https://t.co/UBdVVgXzYC: A cloned RTX homepage exposed SpiceRAT servers spoofing Turkmengaz, the Galkynysh gas field, Tojiktelecom and Turkmenistan's foreign ministry. Some china links and possible overlap with IndigoZebra. https://t.co/qAYmj1yAh7
NCSC/FBI/AIVD: A joint advisory covers CHOSEN BRICK, Iranian malware built to surveil a person rather than a network. It captures the screen, switches on the microphone, lifts Telegram and WhatsApp data out of browsers — and can wipe the machine. https://t.co/d7qcdcrmeQ
Sophos: Cyclops Blink is back, rebuilt for 64-bit Linux on compromised Cisco FMC devices — five modules for recon, scanning, file transfer, packet surveillance and persistence. Sophos assesses a Russian nexus at high confidence, Sandworm at moderate. https://t.co/Of8PNElMhb
https://t.co/3hk9xPCy1L: From May through August 2026, Feral Wolf conducted a campaign against Russian companies in retail, construction, manufacturing and information technology. several initial-access methods including an Atlassian Confluence exploit. https://t.co/G1DPfYp04B
Kaspersky: NightEagle, an APT that spent years working against Asian targets, is now hitting Russian companies. In most incidents it used valid stolen credentials to corporate VPNs. https://t.co/2dzyzICnbc
Group-IB: HEAVYGRAM is a Telegram-based Windows backdoor used against Iranian dissidents and journalists. The malware has been utilized since the fall of 2023 and is attributed to Handala Hack, an Iranian MOIS-linked cluster. https://t.co/Im7eXn2hoT
ESET: China-aligned actor FamousSparrow is retiring SparrowDoor for SparroWocky, a new modular C++ backdoor — and pointing it almost entirely at Latin American government targets. https://t.co/8qAlU916zZ
SOCRadar: An exposed server laid bare a French-speaking crew running an AI agent across a dozen campaigns. The actors were using Hermes with DeepSeek. https://t.co/2NEiG7bpnS
Zscaler: "SloppyRAT" is a new remote access trojan turning up in ransomware intrusions, offering 47 built-in commands that mimic PowerShell plus reverse SOCKS tunnels for lateral movement. Delivery is ClickFix — victims are tricked into running finger.exe. https://t.co/FNbCH4oEIK
Dragos: AI is handing OT knowledge to adversaries who never had it. In one Mexican government breach a model flagged that a compromised system was an interface into a government water utility, and supplied the vendor and default credentials unprompted. https://t.co/tvzu0qUSEp
arXiv: Researchers ran the first systematic study of malicious LLM API routers — the middlemen between agents and model providers — and found 9 of the routers they examined actively injecting malicious code into responses. https://t.co/7SPfbODPq4
Qihoo 360: Kimsuky is hiding LNK droppers inside fake software installers, ending in a modular .NET backdoor. The PowerShell stage checks 42 analyst tool names and VM artifacts before running, then persists as a scheduled task posing as a Chrome update. https://t.co/yFSyH1MtB7
Anthropic: A report on malicious activity detected and disrupted on Claude between December 2025 and August 2026 across seven harm areas including cyber operations. Multiple state and criminal operations detailed. https://t.co/989Dbod0rF
CISA/NSA/FBI: A joint advisory says six China-based AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and https://t.co/gV29liDDQO — extracted billions of tokens from Claude, GPT, Gemini and Grok since late 2024, likely with government awareness. https://t.co/Xe8K0PJRCz
SOCRadar: "Anubis Market" is a Tor marketplace running ~11,000 listings, led by digital goods (2,951) and counterfeits (2,871), with fraud — stolen cards, bank accounts and credentials — the largest digital subcategory. https://t.co/QxX7grZDCA