ZeroHour

Search: “State Department”

143 stories in the last 30d

Italian tech collective Autistici/Inventati shuts down after US terrorist designation

Italian privacy collective Autistici/Inventati shut down after a US State Department terrorist designation triggered its domain suspension and bank account closure.

The volunteer-run Italian collective Autistici/Inventati, founded in 2001, announced Sunday it would shut down after the State Department labeled it an extremist group on August 26, 2026. The designation led the Public Interest Registry to suspend the group's .org domain on August 28 and its bank, Banca Etica, to suspend its account. The collective hosted roughly 16,000 email addresses, 1,500 websites, 5,500 mailing lists, and about 10,000 blogs, including the Noblogs platform. European Digital Rights warned the move sets a dangerous precedent for non-commercial European hosts and digital sovereignty.

The Record · 8d agoPolicy & legal

US offers $10 million for info on Iranian leaders behind CyberAv3ngers water utility attacks

The US offered $10 million for information on six IRGC-CEC officials behind CyberAv3ngers' 2023 hacks of Unitronics PLCs at US water utilities.

The State Department named six Iranian security officials, including IRGC Cyber-Electronic Command head Hamid Reza Lashgarian, and offered up to $10 million for information on their whereabouts. CyberAv3ngers publicly claimed compromises of Israel-made Unitronics Vision PLCs in October 2023, forcing the Municipal Water Authority of Aliquippa, Pennsylvania, to take systems offline and switch to manual operations. The US had sanctioned the six men in February for targeting critical infrastructure, and CISA notified water operators using Unitronics devices while urging default-password changes. A watchdog also criticized the EPA for lacking a comprehensive water-sector cyber risk strategy.

The Record · 8d agoPolicy & legal in the wild 3 sources

U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks

The U.S. State Department offered up to $10 million for information on Amir Yaryab, an IRGC cyber chief linked to critical infrastructure attacks.

The U.S. State Department's Rewards for Justice program offers up to $10 million for information identifying or locating Amir Yaryab, who allegedly oversees the Cyber Operations Command of Iran's IRGC Cyber-Electronic Command (IRGC-CEC). Officials tie him to units called Shahid Hemmat and Shahid Shushtari conducting cyber and information campaigns against defense, telecommunications, energy, and finance sectors across the US, Europe, and the Middle East, and to groups including CyberAv3ngers and Dadeh Afzar Arman. CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs, including 34 in US water and wastewater facilities, between November 2023 and January 2024.

Cyber Security News · 8d agoPolicy & legal

NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

New York DFS issued cybersecurity guidance defining expectations for risk assessments that regulated financial services entities must conduct.

On September 10, 2026, NYS DFS Acting Superintendent Kaitlin Asrow issued new cybersecurity guidance on conducting risk assessments sufficient to inform cybersecurity programs. The guidance covers scope, frequency, and the role of assessments for DFS-regulated financial services entities. It does not describe any incident or vulnerability, but sets regulatory compliance expectations under DFS cybersecurity rules.

DataBreaches.net · 3d agoPolicy & legal

US charges Iranians for sprawling hacking campaign on government agencies, universities

DOJ indicts 17 Iranians tied to Mabna Institute IRGC hacking-for-hire campaign that stole 31TB from universities, agencies, and UN organizations.

The U.S. Justice Department unsealed a 14-count superseding indictment charging 17 people linked to the Mabna Institute, allegedly operating on behalf of the IRGC, in a campaign running since around 2013. The group breached 144 US universities, 42 US companies, 178 foreign universities, 11 foreign companies, and agencies including the Department of Labor, Federal Energy Regulatory Commission, and Hawaii and Indiana state governments, plus UN organizations such as UNICEF, stealing at least 31 terabytes of academic and proprietary data and about 8,000 professor email accounts. The State Department offered a $10 million reward for five individuals including Behzad Mesri, previously indicted for the $6 million HBO extortion; universities spent roughly $20 million on investigation and remediation.

The Record · 8d agoPolicy & legal 2 sources

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Weekly recap: actively exploited Chrome V8 zero-day, MikroTik RouterOS zero-day chain, Magento StyleSmuggler backdoor, and critical N-able N-central flaws.

Google patched an actively exploited Chrome V8 type confusion zero-day, CVE-2026-85046 (CVSS 8.8), the sixth exploited Chrome zero-day of 2026. CERT Polska warned of the MikroTrick exploit chain (CVE-2026-67276 and CVE-2026-86060, CVSS 9.2) giving unauthenticated full control of MikroTik RouterOS devices via SSH, observed since September 2. Sansec disclosed the StyleSmuggler Magento/Adobe Commerce zero-day used since September 4 to inject a Rust backdoor into online stores, while N-able patched three critical N-central flaws (CVE-2026-86206, CVE-2026-86207, and CVE-2026-86218, CVSS 10.0) with Huntress observing likely exploitation. Elastic and Morphisec also detailed RevStealer, an information stealer spread via game cheats and a fake Claude Desktop app.

The Hacker News · 9d agoExploit / PoC in the wildCVE-2026-85046CVE-2026-86206CVE-2026-86207+7 CVEs

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 16d agoPolicy & legal

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal

Ukraine's top prosecutor Ruslan Kravchenko resigned after NABU arrested a deputy for taking bribes protecting scam call centers running fake investment platforms.

Ukraine's anti-corruption bureau NABU arrested Serhiy Kropyva, Deputy Head of International Cooperation at the Prosecutor General's Office, alleging officials took monthly protection fees from a network of 100-500 scam call centers luring victims into fake investment platforms, with bribes reportedly growing from $700,000 to $3.5 million per month. Prosecutor General Ruslan Kravchenko resigned on Monday, calling it a political decision, while Kropyva was fired with bail set at 120 million hryvnias ($2.7 million) and over 100 call centers shut down in the past month. The newsletter also briefly covers a cyberattack crippling more than 80 Luxembourg medical practices via payment vendor BMS Engineering, ShinyHunters' claimed theft of 200,000 Florida DMV driver records, a cyberattack on the American Meteor Society, and school closures in Springfield, Massachusetts.

Risky Business News · 7d agoPhishing & fraud

Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna Institute

US prosecutors unsealed a superseding indictment charging 17 Iranians in the Mabna Institute's state-sponsored theft of 31.5 terabytes from universities and companies.

The superseding indictment unsealed in the Southern District of New York charges 17 people affiliated with Tehran's Mabna Institute, adding eight defendants to the 2018 indictment of nine. The institute allegedly compromised over 100,000 professor email accounts worldwide, including 8,000 accounts at 144 US universities, and stole at least 31.5 terabytes of academic journals, dissertations, and e-books. US universities spent approximately $3.4 billion procuring the stolen data, and victims also included at least five federal and state agencies, 42 US companies, and 11 foreign companies including HBO. The State Department's Rewards for Justice program is offering up to $10 million for information on four of the defendants.

CyberScoop · 28d agoPolicy & legal

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin refuses ransom demands after Rhysida claimed stealing 5.79 TB from the city-state network, including mobility department data on 12,076 individuals.

Berlin's state government confirmed an extortion attempt following the August compromise of its state administrative network and said it will not pay. Forensics found data exfiltrated from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and 12, 2026; Rhysida's leak site claims 5.79 TB, 1.44 million files, and personal data on 12,076 individuals. State criminal police, prosecutors, and federal authorities are investigating, and officials say the September 20 Abgeordnetenhaus election environment remains unaffected. Separately, Manchester Airports Group confirmed theft of customer data including emails, phone numbers, and vehicle registrations across three airports.

The Hacker News · 18d agoRansomware in the wildCVE-2020-1472

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.

Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.

Risky Business News · 28d agoThreat actor in the wild1

US charges 17 Iranian hackers over 31-terabyte academic data theft

US indicts 17 Iranian Mabna Institute hackers who stole 31TB of academic data from universities, companies, and agencies via spearphishing.

The US Department of Justice charged 17 alleged Mabna Institute members, adding eight defendants to the nine charged in 2018, for a 2013-2017 campaign largely conducted for Iran's Islamic Revolutionary Guard Corps. The group stole over 31TB of academic data and intellectual property from 144 US and 178 foreign universities, at least 42 US companies, and at least five federal and state agencies, compromising about 8,000 of 100,000 spearphished professor email accounts. US universities spent roughly $3.4 billion procuring the stolen data; one defendant also hacked HBO and sought about $6 million in bitcoin ransom. The State Department offers up to $10 million for information on five defendants, none of whom are in US custody.

Help Net Security · 27d agoPolicy & legal in the wild

US Indicts 17 Iranians Over Years

US unsealed superseding indictment charging 17 Mabna Institute Iranians for IRGC-linked espionage stealing 31TB from universities, companies, and government agencies.

The Justice Department unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute, which conducted hacking campaigns since at least 2013 on behalf of the IRGC and other Iranian clients. The group compromised 144 US and 178 foreign universities, at least 42 US companies, and multiple government agencies, stealing over 31 terabytes of academic data and IP plus employee email inboxes. Hackers breached roughly 8,000 of 100,000 targeted professor accounts across 24 countries, selling stolen research through Megapaper.ir and Gigapaper.ir. Behzad Mesri, tied to the HBO breach and $6 million Bitcoin extortion, is among eight new defendants, and five defendants carry State Department Rewards for Justice bounties up to $10 million.

Security Affairs · 27d agoThreat actor in the wild

OpenAI disrupts 20 campaigns to misuse its tech as federal officials mull international use of AI

OpenAI disrupted 20+ nation-state operations misusing ChatGPT, including CyberAv3ngers using it for reconnaissance and malware code debugging.

OpenAI's 54-page threat report detailed more than 20 disrupted operations by actors from China, Iran, Russia, Israel and other countries using ChatGPT for writing malware code, rewriting phishing emails and reconnaissance. Banned accounts linked to Iran's CyberAv3ngers (tied to the IRGC) queried default PLC credentials, asked about obfuscating malicious code and researched known vulnerabilities; OpenAI judged the AI use offered no novel capability. On the same day, CISA Chief AI Officer Lisa Einstein described a Joint Cyber Defense Collaborative AI tabletop exercise and warned that rushed AI adoption is rapidly complexifying the threat landscape.

The Record · 8d agoAI safety & security

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 12d agoPolicy & legal

Treasury’s Scott Bessent says no liability exemptions for AI labs

Treasury Secretary Scott Bessent urged Congress to reject AI labs' requested liability exemptions, arguing creator liability is the best safety guarantee.

Testifying before the House Financial Services Committee, Treasury Secretary Scott Bessent said the government should not grant frontier labs liability waivers, responding to Anthropic CEO Dario Amodei's slowdown essay. He cited Treasury's AI safety work since the release of Anthropic's Mythos model, whose cybersecurity risks prompted an April meeting, and coordination with banks and labs after the July Hugging Face cyberattack. Bessent also highlighted the Gold Eagle clearinghouse run with CISA and called for more US-built open-source models to counter China.

CyberScoop · 5h agoAI policy

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Google tracks three Russia-linked espionage clusters abusing OAuth, app passwords, and device code phishing against Western researchers and diplomats.

Google's Threat Intelligence Group documented three suspected Russia-linked clusters, UNC6293, UNC7005, and UNC5976, abusing legitimate authentication flows. UNC6293, a likely APT29/ICE RELIC sub-cluster, impersonates US State Department officials in app password and OAuth phishing targeting fewer than five victims at a time. UNC7005, tracked by Microsoft as STORM-2945, spoofs the GLOBSEC conference, runs device code phishing against Microsoft and WhatsApp accounts, and deploys VIDAR and AtomicStealer infostealers. Targets include researchers, academics, diplomats, think-tank analysts, and defense personnel in Europe and the United States.

Security Affairs · 26d agoThreat actor in the wild1

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Google tracked three suspected Russian espionage clusters abusing OAuth flows, app passwords, and WhatsApp linking to hijack accounts of diplomats and defense targets.

Google Threat Intelligence Group detailed three suspected Russian espionage clusters, UNC6293, UNC7005 (Storm-2945), and UNC5976, targeting academia, aerospace, defense, governments, and think tanks in Europe, the US, Ukraine, and Armenia. UNC6293, assessed as a sub-cluster of APT29/Ice Relic, conducted OAuth and application-specific password phishing while impersonating State Department officials. UNC5976 registered file-sharing-themed domains hosting fake OAuth login pages and deployed a malicious Excel plugin codenamed HEADRUSH, while UNC7005 abused WhatsApp device linking to hijack accounts and record victims' audio and video.

The Hacker News · 26d agoThreat actor in the wild

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

UK, US, and Dutch agencies expose CHOSEN BRICK spyware used by Iranian MOIS hackers to surveil dissidents, journalists, and activists via fake MRI lures.

The UK NCSC, FBI, and Dutch AIVD jointly warned that Iranian state-sponsored hackers deploy CHOSEN BRICK Windows spyware against dissidents, activists, and journalists since at least 2025. Operators build rapport over WhatsApp and Telegram, often posing as known contacts or tech support, then deliver malicious files disguised as an MRI scan or installers for Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass. The malware steals contacts, emails, and social media messages, captures screen content and microphone audio, adds Microsoft Defender exclusions, and uses per-victim Telegram bots for command and control. The FBI attributes the tradecraft to Iran's Ministry of Intelligence and Security, including the 'Handala Hack' persona, and stolen data has surfaced on pro-Iranian leak sites.

The Record · 1d agoThreat actor in the wild1

14th September – Threat Intelligence Report

Check Point weekly digest: Microsoft's record 974-vuln Patch Tuesday ships two actively exploited Windows zero-days; IDScan.net, Mathspace, Revolut suffer breaches.

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited privilege-escalation zero-days, CVE-2026-85880 and CVE-2026-81963, plus 20 flaws allowing unauthenticated remote code execution. Disclosed breaches include IDScan.net (identity documents), Mathspace (over 1 million people via Metabase CVE-2026-72898), Revolut, and Florida DMV (ShinyHunters). GitLab fixed critical CVSS 10.0 path traversal CVE-2026-85706, and MikroTik fixed chainable RouterOS flaws CVE-2026-67276 and CVE-2026-86060. The report also covers the PuzzleMask LLM jailbreak technique, GoldFactory's Gigabud Android fraud, and the BlueMoon Chromium exploit chain (CVE-2026-85046).

Check Point Research · 2d agoExploit / PoC in the wildCVE-2026-72898CVE-2026-85880CVE-2026-81963+4 CVEs2· 1 read

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

ShinyHunters breached Florida's DMV using credentials stolen from a police officer's personal device; the state confirmed the breach and is investigating.

Florida's Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach after ShinyHunters obtained DMV data using credentials a criminal actor took from a Plant City police officer's personal electronic device. The department learned of the breach on September 4, is investigating with the Florida Digital Service, and ShinyHunters shared a DMV record of Jeffrey Epstein as proof of access. Experts initially speculated a link to the IDScan breach of 153 million driver's licenses. Anthropic reported that suspected ShinyHunters affiliates use AI to scan credentials, map systems, and exfiltrate data, in one case moving from a stolen developer token to cloud admin access in about three hours.

The Recordupdated · 1h agofirst · 4d agoData breach in the wild 3 sources

Doctor Doom Thanked Seattle for All the Surveillance Cameras

Activist dressed as Doctor Doom urged Seattle's council to curb Axon and Flock surveillance after a committee voted to redirect $250,000 from CCTV expansion.

Clifford Cawthon, a policy advisor at the Washington State Department of Commerce, appeared at a Seattle Public Safety Committee meeting in costume as Doctor Doom to protest the city's expanding mass surveillance. He criticized Seattle PD's access to 62 cameras feeding an Axon real-time crime center that ingests CCTV, body camera, geolocation, ALPR, and dispatch data from vendors like Axon and Flock. His group Community Not Cameras submitted a petition with five demands, and a committee already voted to move $250,000 away from CCTV expansion pending full council approval.

404 Media · 7d agoPolicy & legal

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

CISA, FBI, and HHS updated their Medusa ransomware advisory, reporting over 500 victims and detailing the gang's access-broker and exploit tactics.

A joint advisory update from CISA, the FBI, and HHS expands the March 2025 Medusa guidance, drawing on a year of FBI investigations. The ransomware-as-a-service group's known victim tally grew from more than 300 to more than 500 between March 2025 and April 2026, with the Healthcare and Public Health sector frequently hit. Medusa pays access brokers $100 to $1 million, has exploited flaws such as Fortra GoAnywhere and BeyondTrust vulnerabilities, and leverages newly announced exploits within 24 hours, sometimes a week before public disclosure. The group uses living-off-the-land techniques, remote monitoring and management software, and RDP for lateral movement, and has been linked to actors including Microsoft-tracked Storm-1175 and North Korean hackers targeting healthcare.

CyberScoop · 29d agoRansomware in the wild

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Treasury sanctioned nearly 60 Iran-linked entities, including MOIS-affiliated Mabna Institute hackers behind breaches of U.S. critical infrastructure and millions in crypto theft.

The U.S. Treasury launched Operation Economic Outcast, designating nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, cyber, and digital asset networks. Five sanctioned individuals are members of the Tehran-based Mabna Institute indicted last week; three allegedly breached and exfiltrated data from U.S. energy, defense, healthcare, IT, and financial organizations since late 2023. TRM Labs traced roughly $16.8 million across 30 wallets tied to the members, and the State Department announced a reward of up to $10 million. The action follows Iranian hacking of FBI Director Kash Patel's email and attacks on over 30 U.S. water and wastewater utilities.

The Hacker News · 21d agoPolicy & legal in the wild

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM

Hacker News ThreatsDay roundup: Defender BTR.sys driver abuse, DoJ charges 17 Mabna Institute members over IRGC-linked intrusions, Grandoreiro sideloading, OpenAI monitoring.

Check Point researchers showed Microsoft's signed Defender Boot-Time Removal driver (BTR.sys) can be repurposed as a universal kernel operation engine to bypass endpoint security without BYOVD. The DoJ charged 17 members of Iran's Mabna Institute, which on behalf of the IRGC stole over 31 TB of academic data from 144 US universities and compromised roughly 8,000 of 100,000 targeted professor accounts; the State Department offered a $10 million reward for five defendants. Separately, Acronis tracked a Grandoreiro campaign abusing DLL sideloading in the Duplicate Files Finder app across Latin America and Spain, while ErrTraffic ClickFix campaigns deliver Cruciferra (BYOVD) and Remus Stealer. OpenAI also previewed Private Safety Processing, a privacy-centric approach to monitoring model misuse without retaining customer content.

The Hacker News · 26d agoThreat actor1

Expanding AI access and cyber defense for federal, state, local, and tribal governments

OpenAI and GSA agreed to provide ChatGPT to federal, state, local, and tribal governments with $0 licenses, 50% off usage, and cyber-defense access.

OpenAI for Government and the U.S. General Services Administration announced a 27-month agreement (October 1, 2026 through December 31, 2028) waiving the $15 per-user monthly license fee and cutting usage costs 50% for federal, state, local, and tribal agencies. More than one million government employees already have ChatGPT access, with eligibility extending across a roughly 23 million-person U.S. public-sector workforce. Every verified government entity is approved for Daybreak Blue cyber-defender access at 50% off, with Daybreak Red available for vulnerability research, exploit validation, and red teaming at standard pricing. The deal builds on the $1 billion Daybreak for Frontline Defenders commitment announced the prior week.

OpenAI Newsupdated · 6d agofirst · 6d agoAI industry 3 sources1

The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced

A comparison of 12 mobile threat defense vendors highlights Zimperium's on-device detection and notes Kaspersky's US exit and Wandera's Jamf absorption.

The buyer's guide compares 12 mobile threat defense (MTD) products, naming Zimperium best for fully on-device detection and Microsoft Defender for Endpoint as the best-value bundled option. It reminds readers that Kaspersky cannot legally be sold or updated in the US following a Commerce Department determination, and that Wandera was acquired by Jamf. Most MTD pricing is quote-based per device or per user.

GBHackers · 6d agoIndustry 4 sources

Berlin refuses to be blackmailed after network breach

Rhysida extorts Berlin's state government after stealing 5.79 TB across 1.44 million files, demanding roughly 2 million euros in bitcoin.

Berlin's state government confirmed an extortion attempt after data theft from its administrative network between August 7 and 12, with affected departments disconnected only on August 14. The Rhysida ransomware gang lists 5.79 TB across 1.44 million files on its leak site, including HR files, contracts, 148 IBANs, personal data on 12,076 individuals, and plaintext credentials from internal systems including Berlin's leadership. Der Spiegel reports a 30 bitcoin demand of about 2 million euros; officials say the city will not pay and investigators include the State Criminal Police Office and federal agencies. Forensics revealed additional leaks in the Senate Department for Mobility, Transport, Climate Protection and the Environment, while the Berlin House of Representatives election environment is reported secure.

Help Net Security · 15d agoRansomware in the wild

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

Leaked Bauman Moscow State Technical University files reveal a hidden GRU training pipeline feeding APT28 and Sandworm units.

More than 2,000 leaked Bauman Moscow State Technical University documents show that Department No. 4, a hidden program inside the Military Training Center, trained roughly 250 career and reserve students for GRU cyber and intelligence roles across six academic years. Graduates were linked to Military Unit 26165 (APT28), Unit 74455 (Sandworm/APT44) and Unit 29155, and former Unit 26165 commander Viktor Netyksho was involved in department oversight. Reporting by The Insider, The Guardian, Le Monde, Der Spiegel and other outlets, with independent analysis by DomainTools, estimates 10-15 students annually were selected for GRU-related assignments before graduating.

Security Affairs · 13d agoThreat actor1

US sanctions Iranian cyber actors as UK discloses power plant attack

US Treasury sanctioned six Iranian MOIS-linked hackers for breaching US agency and UN email accounts as the UK disclosed a four-day power plant shutdown.

The US Treasury sanctioned at least six Iranian nationals tied to a hacking team inside Iran's Ministry of Intelligence and Security (MOIS) active since 2023; four were indicted last week for breaching employee email accounts at the Department of Labor, the Federal Energy Regulatory Commission and United Nations organizations. Treasury said the group compromised energy, defense, healthcare, IT and financial sector targets, multiple US government offices in summer 2024, and stole cryptocurrency for personal gain. Separately, Iranian actors reportedly shut down a small British power plant for four days without grid impact, days after FBI and NSA warned of hackers targeting programmable logic controllers in energy, water and agriculture.

The Record · 22d agoThreat actor in the wild

Officials disrupt Chinese espionage operation that hit multiple federal agencies

FBI and DOJ seized QTFY infrastructure, disrupting a Chinese state-sponsored group that compromised federal agencies and critical infrastructure since 2018.

Authorities seized three domains powering QScan and QTRouter, the hacking suite of QTFY, a Chinese government-funded group operating through front company Nanjing Xinjiuwei Network Technology. Targets include the Departments of Energy, Justice, and Health and Human Services, the Federal Reserve, NASA, NIH, financial institutions, defense contractors, utilities, telecoms, and hospitals; the group exploited zero-days in Ivanti, Pulse Secure, Fortinet, Citrix, and others, intruding three DOE national labs in September 2024. QScan carried over 200 proof-of-concept exploits and processed more than two million scanning tasks in a single day in 2024.

CyberScoop · 21d agoThreat actor in the wild1

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iranian hackers knocked a small UK power plant offline for four days in July 2026, with no noticeable impact on the national grid.

Sources told The Telegraph that a British power plant was offline for four days in July 2026 following a suspected Iranian cyberattack, reported to the National Cyber Security Centre. The UK energy minister said the incident affected a small-scale energy generator with no noticeable effect on the power supply, and energy CEOs were briefed and given further advice afterward. The attack followed warnings about Iranian cyber activity against US energy, water, and government networks, including a coordinated attack on 30+ US community water utilities.

Help Net Security · 23d agoThreat actor

US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate

DOJ takes down QScan and QTRouter Chinese obfuscation platforms used to breach Federal Reserve, DOE, DOJ, and Senate since 2018.

The DOJ and FBI seized domains hard-coded into QScan and QTRouter, platforms run by Nanjing Xinjiuwei Network Technology Company and used by China's Ministry of State Security and PLA. QScan automatically infected IoT devices worldwide which were absorbed into QTRouter, allowing attackers to disguise intrusions as originating from other countries or local sources. Victims included the Federal Reserve, Department of Energy, DOJ, US Senate, NASA, HHS, NIH, plus hospitals, telecoms, power companies, financial institutions, and defense contractors. The FBI investigated QTFY since 2018, tracing a 2019 NASA incident through Pulse Secure VPN exploitation.

The Record · 21d agoThreat actor in the wild

Supreme Court denies Trump request to allow USPS mail ballot changes

Supreme Court denied the Trump administration's emergency request to implement USPS mail ballot changes before the 2026 midterms, calling it arbitrary and capricious.

The U.S. Supreme Court rejected 7-2 the Trump administration's petition to change how the U.S. Postal Service handles mail-in ballots for the 2026 midterm elections. Justice Ketanji Brown Jackson wrote the administration was unlikely to succeed, while Justice Brett Kavanaugh cited unreasonably short timelines for state election officials. The blocked executive order would have required USPS citizenship verification, barcode tracking of ballot envelopes, and DHS-compiled "State Citizenship Lists"; a whistleblower alleged a rushed effort to install three restrictive IT verification systems. Justices Alito and Thomas dissented, arguing states and organizations lacked standing.

CyberScoop · 1d agoPolicy & legal

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

FBI seizes China-linked QScan and QTRouter hacking platforms used by QTFY to obfuscate intrusions against US federal agencies.

The DOJ and FBI seized domains hard-coded into QScan and QTRouter, two platforms operated by China-based Nanjing Xinjiuwei Network Technology Company on behalf of state-sponsored group QTFY. QScan automatically infected thousands of IoT devices which were added to QTRouter, an obfuscation network routing malicious traffic through compromised and proxy devices outside China. Targets included NASA, the Federal Reserve, Departments of Energy, Justice, and HHS, NIH, and the US Senate, exploiting flaws in Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Log4j, and others.

Security Affairs · 21d agoThreat actor in the wild

Treasury sanctions alleged Iranian hackers as part of ‘economic D

US Treasury sanctioned four Iranians linked to MOIS-directed hacks that compromised and exfiltrated data from US critical infrastructure, energy, defense, and financial targets.

The Treasury Department designated four Iranian individuals over alleged hacking and cybertheft against US companies in energy, defense, healthcare, IT, and financial sectors since at least late 2023, as part of an 'economic D-Day' sanctions package. It is the second action in weeks against the group, following an indictment of cybercriminals affiliated with Tehran's Mabna Institute; leadership includes Behzad Mesri, first sanctioned in 2018, and the attacks are described as directed by the Ministry of Intelligence and Security (MOIS). Treasury also expanded secondary-sanction categories across digital assets, technology, gold, aviation, and shipping, and noted some group members pursued personal enrichment, including targeting Iranian companies.

CyberScoop · 22d agoPolicy & legal

Top 10 Best Endpoint Encryption Software in 2026

A 2026 roundup of ten endpoint encryption products argues the engines are solved and buyers should choose management layers like Intune, Sophos, or Trellix.

The guide ranks ten endpoint encryption options, arguing BitLocker and FileVault have won the engine war so the real purchase decision is the management layer for compliance proof, key escrow, and cross-platform policy. Microsoft BitLocker with Intune is named the baseline for Windows estates, with Sophos, ESET, Trend Micro, Check Point, Trellix, and others covering mixed or regulated fleets. It also warns that TrueCrypt-lineage freeware is unmaintained and that Kaspersky cannot be sold to US customers.

Cyber Security News · 6d agoIndustry

The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced

GBHackers compares 12 business antivirus products on detection, EDR depth, pricing, and platform coverage, ranking CrowdStrike and Bitdefender joint top at 8.8.

The roundup scores 12 enterprise endpoint protection vendors across detection, EDR depth, management, pricing transparency, and platform coverage. CrowdStrike and Bitdefender tie at 8.8, with Microsoft Defender for Endpoint scoring 8.5 and noted as effectively free for Microsoft 365 E5 licensees. The piece also flags that Kaspersky cannot legally be sold in the US and that Panda and Webroot now sit under WatchGuard and OpenText respectively.

GBHackers · 8d agoIndustry 2 sources1

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI and Lumen disrupted QTFY's QScan and QTRouter botnet platforms used by Chinese state-sponsored hackers to conceal intrusions into U.S. agencies.

The U.S. DoJ announced court-authorized seizure of domains behind QScan and QTRouter, operated by the Chinese state-sponsored group QTFY and employed by Nanjing Xinjiuwei Network Technology Company. QTFY has been active since May 2018 and targeted NASA, the Federal Reserve, the Department of Energy, DoJ, HHS, NIH, the U.S. Senate, and academic institutions. QScan exploits vulnerable IoT devices, feeding them into QTRouter, an OpenWrt-based proxy obfuscation network likened to an operational relay box (ORB) that masks attack origins. The group exploited zero-days such as Ivanti CSA flaws CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380, plus numerous N-days, and maintained persistence with RATs, web shells, and legitimate credentials.

The Hacker News · 14d agoThreat actor in the wildCVE-2018-13379CVE-2019-10068CVE-2019-19781+10 CVEs

A California county wants to hire Tina Peters to help run its elections

Shasta County, California plans to hire Tina Peters, convicted of stealing voting system software, as assistant registrar of voters.

Shasta County registrar of voters Clint Curtis said he plans to hire former Mesa County clerk Tina Peters as assistant registrar after Colorado Governor Jared Polis commuted her nine-year sentence for seven felonies, including identity theft, breaking into an election office, and stealing voting system software. Senators Alex Padilla and Adam Schiff asked California Secretary of State Shirley Weber to provide maximum oversight to prevent Peters from improperly accessing ballots, voting systems, or data of over 100,000 registered voters. The county board of supervisors recently censured Curtis after investigations found he was verbally abusive or physically threatening toward staff.

CyberScoop · 27d agoPolicy & legal