Nation-State Attacks & Cyber Espionage

Tortoiseshell Adds a wtsapi32 Backdoor and Reverse SSH Tunneller Across Europe and the Gulf

The Iran-linked cluster, also tracked as Mirage Kitten, UNC1549 and Nimbus Manticore, disguised both tools as the Windows Terminal Server DLL for search-order hijacking. Infrastructure nodes spanned the UAE, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia and Japan.

breach-confirmed iran espionage unc1549 backdoor
Critical Infrastructure & Industrial Attacks

CISA Advisory AA26-237A Reports Full Domain Compromise at Two Critical Infrastructure Bodies

Parallel red team assessments fully compromised a government services body and a water utility at domain level, reaching sensitive business systems and cloud resources. One defender quarantined the intrusion quickly; the other missed it entirely amid false positives across unlinked security operations centres.

critical-infrastructure red-team cisa water-utilities detection-gap
Privacy Rights & Data Protection

Meta Settles State Child-Harms Litigation for 18 Billion Dollars

Twenty-nine states alleged Instagram and Facebook were engineered to addict minors and collected children's data without parental consent in breach of COPPA. Meta agreed to pay roughly 18 billion dollars over ten years and impose daily teen time limits, admitting no wrongdoing.

coppa children-privacy settlement meta social-media
Nation-State Attacks & Cyber Espionage

DOJ and FBI Seize QScan and QTRouter Platforms Used Against NASA and the Federal Reserve

Three domains supporting the QScan and QTRouter intrusion platforms were seized from QTFY, a China state-sponsored group operating through Nanjing Xinjiuwei Network Technology. Victims spanned NASA, the Federal Reserve, the Senate, the Departments of Energy, Justice and Health, hospitals, power companies and defence contractors.

breach-confirmed china espionage domain-seizure critical-infrastructure
Critical Infrastructure & Industrial Attacks

CISA Puts the July Water-Sector Intrusion Count Above 100 Exposed Systems

The agency confirmed attackers reached more than 100 internet-exposed water and wastewater systems, far above the 30 Minnesota utilities in the initial count. Targeting focused on internet-facing programmable logic controllers from Rockwell, Schneider Electric and Siemens, causing outages without affecting supply.

critical-infrastructure water-utilities plc iran ics
Data Breaches & Exposures

DireWolf Leak-Site Post Targets National Kidney Registry With 253 GB of Donor Data

The group allegedly exfiltrated 253 GB across 180,000 files, including 15,050 donor records and 24,791 transplant recipient records. Claimed data classes cover Social Security numbers, dates of birth, medical histories, imaging and HLA typing. The registry has not verified the listing.

breach-claimed direwolf healthcare ransomware extortion
Disinformation and Influence Operations

OpenAI Bans Russian Accounts Running the International Burke Institute Influence Campaign

Operators working in Russian used VPNs to reach ChatGPT and draft Substack, Telegram, X, Facebook and LinkedIn posts for a fabricated think tank that falsely listed Francis Fukuyama and Noam Chomsky. Of 36 expert articles reviewed, 34 were plagiarised. Engagement stayed low.

russia influence-operation ai-abuse fake-think-tank
Data Breaches & Exposures

Boston Scientific Cyberattack Disrupts Order Processing and Shipping Worldwide

The medical device maker detected an intrusion that cut access to key information systems and business applications, including those used to process and ship customer orders. Incident response protocols were activated with third-party experts engaged, and no restoration timeline was set.

breach-confirmed healthcare medical-devices operational-disruption
Cyber Law, Policy & Regulation

UK Cyber Security and Resilience Bill Amendments Allow Undisclosed Bans on High-Risk Suppliers

Ministers would gain powers modelled on the Huawei telecoms regime but stripped of its transparency duties, with no requirement to designate a vendor publicly or to notify it. The reach extends to managed service providers, data centres, energy, water, transport and health.

united-kingdom supply-chain legislation high-risk-vendors
Privacy Rights & Data Protection

Tift Regional Health System Pays 1.2 Million Dollars to Settle Breach Litigation

The Georgia health system agreed to fund a class settlement covering patients whose information was taken in a prior intrusion, adding to a run of seven-figure healthcare breach resolutions. Payment resolves the civil claims without any admission of liability by the operator.

settlement healthcare class-action united-states
Software & Supply Chain Attacks

Twenty-Four Malicious npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Attackers published packages whose only purpose was to place phishing redirect content on trusted content delivery mirrors, lending registry reputation to fraudulent verification prompts. The technique turned package hosting infrastructure into a delivery channel for social engineering rather than executable payloads.

npm supply-chain clickfix phishing
Cybercrime, Fraud & Underground Markets

Mirage2FA Phishing Service Compromises 4,532 Microsoft 365 Accounts Across US and EU Firms

The commercial adversary-in-the-middle toolkit proxied Microsoft 365 login and two-factor flows in real time, harvesting passwords and session cookies from browser-executed attachments. Of 9,426 targeted addresses roughly 48 percent fell, with technology, manufacturing and education firms hit hardest.

phishing aitm microsoft-365 phishing-as-a-service
AI Governance & Regulation

Linux Foundation Takes Governance of TRACE, a Hardware-Attested AI Runtime Evidence Standard

The specification, contributed by OPAQUE and built with AMD, Intel, Microsoft and TII, defines a signed artifact proving an agent ran under a stated policy inside verified hardware on identified data. It builds on RATS, EAT, SLSA, SCITT and SPIFFE.

ai-governance attestation confidential-computing standards
Cybercrime, Fraud & Underground Markets

Operation Jackal IV Arrests 58 and Identifies 263 Black Axe Suspects Across 22 Countries

An eight-month INTERPOL operation running from November 2025 to June 2026 targeted Black Axe money laundering, romance fraud and business email compromise. South Africa accounted for 39 arrests after raids on seven Johannesburg locations, and Argentina identified 196 crime-as-a-service associates.

interpol black-axe west-africa business-email-compromise fraud
Surveillance, Spyware & Intelligence Agencies

ICE Seeks Nationwide Voter Records Through a 125 Million Dollar Thomson Reuters Contract

Procurement records show Immigration and Customs Enforcement buying data broker access covering names, addresses, Social Security numbers, ethnicity, social media posts and geolocation to investigate claimed voter fraud. A parallel solicitation sought a contractor to process state voter registration files.

ice data-broker voter-data united-states