Tag: infrastructure
-
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Tags: access, authentication, credentials, cyber, espionage, exploit, flaw, infrastructure, phishing, russia, softwareRussian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence that UNC6293 is an initial-access subcluster of ICE RELIC, formerly tracked as APT29, Cozy Bear, and Midnight Blizzard. Rather than exploiting a software flaw, the operators abuse legitimate authentication…
-
Innovator Coffee EP-42 Powering The AI Compute Boom
AI infrastructure is becoming an energy problem as much as a compute problem. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/innovator-coffee-ep-42-powering-the-ai-compute-boom/
-
Innovator Coffee EP-42 Powering The AI Compute Boom
AI infrastructure is becoming an energy problem as much as a compute problem. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/innovator-coffee-ep-42-powering-the-ai-compute-boom/
-
CrowdStrike Is ‘Cybersecurity’s Infrastructure Layer’ For AI Era: CEO George Kurtz
CrowdStrike has all the right elements to position its comprehensive Falcon platform as the go-to way to secure the usage of AI and agentic tools going forward, CrowdStrike CEO George Kurtz said Wednesday. First seen on crn.com Jump to article: www.crn.com/news/security/2026/crowdstrike-is-cybersecurity-s-infrastructure-layer-for-ai-era-ceo-george-kurtz
-
Nimbus Manticore expands infrastructure and malware arsenal
First seen on scworld.com Jump to article: www.scworld.com/brief/nimbus-manticore-expands-infrastructure-and-malware-arsenal
-
FBI seizes China-linked QScan and QTRouter platforms used to target US critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/brief/fbi-seizes-china-linked-qscan-and-qtrouter-platforms-used-to-target-u-s-critical-infrastructure
-
CISA Red Team Fully Compromised Two Critical Infrastructure Orgs
CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organizations lost full domain control and had their cloud environments compromised. One of them didn’t know until CISA…
-
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. First seen on cyberscoop.com Jump to article: cyberscoop.com/energy-department-cybersecurity-executive-order-rules/
-
Attackers Targeted Over 100 US Water Systems in July Hacks
CISA Guidance Reveals First Federal Count of July Water Sector Targeting. The U.S. Cybersecurity and Infrastructure Security Agency said it observed more than 100 internet-exposed water systems targeted in cyberattacks in July, most reached through programmable logic controllers wired directly to cellular modems, according to recent internet exposure reduction guidance. First seen on govinfosecurity.com Jump…
-
FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure
FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide cyberattacks and target critical infrastructure. The operation matters because it shows how state-backed actors no longer need…
-
FBI, DOJ Seize Chinese Hacker Infrastructure on US Soil
QScan and QTRouter Used US-Registered Domains and Overseas Servers to Mask Operations. The FBI and DOJ seized domains supporting Chinese state-linked QScan and QTRouter infrastructure that used U.S.-registered services and compromised IoT devices to conceal attacks on federal agencies and critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fbi-doj-seize-chinese-hacker-infrastructure-on-us-soil-a-32658
-
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ. First seen on wired.com Jump to article: www.wired.com/story/fbi-disrupts-chinese-proxy-tools-used-in-mass-hacking-of-us-agencies-and-infrastructure/
-
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (å—京鑫玖维网络科技有é™å…¬å¸).&…
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka First seen on thehackernews.com…
-
Iran-linked hackers expand infrastructure across Europe and Middle East, report says
Researchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group. First seen on therecord.media Jump to article: therecord.media/iran-linked-hackers-expand-infrastructure-europe-middle-east
-
FBI disrupts proxy network enabling Chinese espionage operations
The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/
-
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.Both organizations were fully compromised at the domain level, and in both, the red team also First seen…
-
Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel
Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/tortoiseshell-new-backdoor-ssh/
-
Hackers now exploit critical Gitea flaw in code injection attacks
Tags: attack, cybersecurity, exploit, flaw, hacker, infrastructure, injection, service, vulnerabilityAttackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
-
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to render a fake CAPTCHA page and redirect visitors to attacker-controlled infrastructure. The campaign does…
-
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, open-source, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for…
-
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student at the University of Helsinki, Linus Torvalds, announced his work on the comp.os newsgroup.minix Usenet group. He introduced a free operating system for 386/486 AT clones that he…
-
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student at the University of Helsinki, Linus Torvalds, announced his work on the comp.os newsgroup.minix Usenet group. He introduced a free operating system for 386/486 AT clones that he…
-
Interpol’s Jackal IV Disrupts West African Crime Infrastructure
The international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/interpols-jackal-iv-west-african-crime-infrastructure
-
Nigeria Looks to Sovereign Cloud for Cyber, National Security
The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/nigeria-sovereign-cloud-cyber-national-security
-
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Tags: access, attack, cve, cybersecurity, exploit, flaw, infrastructure, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea.The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as…
-
Souveräne Cloud-Edge-Infrastruktur für Europa – ApeiroRA: Ein offenes Cloud-Edge-Kontinuum für Europa
First seen on security-insider.de Jump to article: www.security-insider.de/apeirora-offene-cloud-edge-architektur-sap-fraunhofer-a-fa6b85278736d433b16018d3095bccdb/
-
CISA Red Team Achieves Full Domain Compromise Across Critical Infrastructure Networks
CISA’s latest red team assessment shows how common failures in Active Directory, cloud identity, and SOC processes can turn a phishing foothold into an enterprise-wide compromise. The August 25 advisory contrasts two critical-infrastructure organizations: one missed the intrusion entirely, while the other contained initial access quickly but still exposed major identity and cloud security weaknesses.…
-
US Lawmakers Urge Probe of Trump Cyber Workforce Cuts
House Lawmakers Ask Watchdog to Assess Staffing Losses at US Cyber Agency. House Democrats are asking the Government Accountability Office to examine how staffing reductions and cuts at the Cybersecurity and Infrastructure Security Agency have affected the agency’s ability to defend federal networks and critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/us-lawmakers-urge-probe-trump-cyber-workforce-cuts-a-32653
-
Iran-Linked Hackers Blamed for UK Energy Cyberattack
A cyberattack reportedly linked to Iran forced a small UK energy generator offline for four days, raising fresh concerns about the security of the country’s critical infrastructure and smaller operators that may sit outside existing regulatory thresholds. The UK government has confirmed that a small-scale generator was affected by a cyber incident in July. It…

