🚨 Heads up! 🚨 APT41 is getting creative, using Google Calendar 🗓️ as their latest C2 trick. Google Threat Intelligence Group just pulled back the curtain 🎭 on the TOUGHPROGRESS malware campaign and how we shut it down 💪. Dive into the details here: 🚀https://t.co/x9CeAPmpX0
For far too long, a China-linked espionage group has been quietly stealing sensitive information in America’s academic, medical, and military research communities. Protecting our nation’s research from our adversaries is crucial and we must be vigilant against cybersecurity threats. Business, governments, and universities must do more to protect vital research.
https://t.co/n9ydxctnHM
GTIG uncovered a Chinese cyber espionage operation targeting medical research centers across the US. The operator also searched a medical target for their broader collection requirements, giving us insight into their other interests (AI, chips, military, cyber, etc). https://t.co/9koUaQIcz3
🚨 A trusted cloud feature became a spying tool.
Google says China-linked hackers breached North American research networks via REDCap, then abused Google Workspace rules to secretly BCC emails matching nearly 150 keywords.
Read: https://t.co/iK654AWVdF
PRC-nexus actor UNC6508 targeted North American research, exploiting REDCap servers to deploy INFINITERED malware.
The actor remained undetected for over a year and abused enterprise admin tools for covert data exfil.
Analysis, guidance and IOCs ➔ https://t.co/xLenVImMxH
🚨New Blog!🚨
🇨🇳-Nexus actors #UNC6508 targeting NA academic, medical and military research institutions with #INFINITERED malware.
https://t.co/YubNfAHVrh
#threatintel#PRC
🚨 Our latest research reveals a new sophisticated PRC-nexus campaign! 🚨 The threat actor is pursuing defense intelligence on AI, UVS, offensive cyber, medical research, and geo-strategic policy 🧑💻💉🌏. Read the full report here: https://t.co/DAztvoxiOi
3. Behind the 1.5 million AI agents on @moltbook ?
Something closer to 17k likely human owners.
And zero mechanism to validate what was what.
In fact, a human could post to it just using an HTTP POST request.
And any user could be impersonated....
https://t.co/xdW9DAenbE
2/ I have seen many posts highlighting the agents talking about "their human". They are prompted to do this in their skills\.md. This file defines that they should interact with each other like a social network. LLMs exceed at this type of role play.
CVE-2025-55182 (aka "React2Shell") continues to be exploited 🚨
Google Threat Intelligence Group has observed multiple campaigns, including China-nexus and financially motivated activity.
Get the latest insights to identify and remediate this threat ➡️ https://t.co/8hun0561kB
Still Spying: even after getting hit with U.S. sanctions, spyware vendor Intellexa (Predator) is still dodging restrictions, exploiting 0days and selling digital weapons to the highest bidder. @google 🧵 #zerodayexploit#spyware https://t.co/LJKlOsBd73
This campaign is fascinating. The malicious JS was likely delivered to millions of endpoints, but the malware payload was only delivered to precise targets based on device fingerprinting.
https://t.co/LzNVX7ZNtE
This is a very interesting read and we will likely see more of this going forward.
The report left me wondering how exactly the threat actor was using Claude. What were they prompting? What data were they sending? What jailbreaks/prompt injection techniques? How many accounts?
We believe this is the first documented case of a large-scale AI cyberattack executed without substantial human intervention. It has significant implications for cybersecurity in the age of AI agents.
Read more: https://t.co/VxqERnPQRJ
CYBERWARCON is ONE WEEK AWAY! 💣💥💻 ✉️
Check out our website to view the agenda and plan your day, read more about our speakers, or buy a last minute ticket!
We can't wait to see everyone in Arlington, VA on November 19th!
https://t.co/n9FPeIrGTs
Unit 42 has observed #StatelyTaurus (aka #MustangPanda) used the following domains in various campaigns to enable its globally spanning espionage operations in the last 90 days: https://t.co/vFtuwuyPyj
I couldn't have asked for a better venue than @RooCon_AU 🇦🇺 for my first Cyber Threat Intel talk! It was an amazing and surreal experience. A huge thanks to the organizers for having me and another thanks to everyone that attended!