Tag: russia
-
Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras
An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most. A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia. Hunt.io reconstructed the…
-
Hackers target Ukrainian agency managing assets seized from sanctioned Russians
The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages. First seen on therecord.media Jump to article: therecord.media/hackers-target-ukraine-agency-sanctioned-russians
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
Clop Claims Data Theft From More Than 40 Companies
Victims Are Assessing Claims of Stolen Databases, CAD Files and Backups. Russia-linked Clop claims it stole databases, engineering files, backups and other sensitive corporate data from more than 40 organizations in a breach wave tied to exploitation of a critical remote code execution flaw in PTC Windchill and FlexPLM. First seen on govinfosecurity.com Jump to…
-
Russian military hackers pose as recruiters to target Ukrainian IT workers
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency. First seen on therecord.media Jump to article: therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-it-workers
-
New Zealand sanctions Russian hackers, propaganda groups over Ukraine war
New Zealand announced new sanctions on Russian hackers, technology companies and Kremlin-linked organizations over their roles in supporting Moscow’s war against Ukraine. First seen on therecord.media Jump to article: therecord.media/new-zealand-russian-hackers-sanctions
-
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Tags: attack, cybersecurity, exploit, flaw, kaspersky, programming, russia, software, threat, vulnerabilityThe threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.The activity involves exploiting a vulnerability chain First seen on thehackernews.com…
-
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48 hours. Researcher Paul McCarty documented the campaign, tracked as WEL1DROPPER, and the package count has since grown past 1,000. WEL1DROPPER marks an evolution in AI slopsquatting, where attackers register randomly…
-
Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists
Georgia’s State Security Service is investigating whether foreign entities were behind the spread of fabricated stories claiming that Georgians were mistreating Russian tourists. First seen on therecord.media Jump to article: therecord.media/georgia-alleges-foreign-disinformation-scare-russian-tourists
-
Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials
Microsoft warns Russian hackers are exploiting hotel Wi-Fi to deliver malware, steal credentials, and compromise corporate travelers’ cloud accounts worldwide. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-russian-hackers-hotel-wifi/
-
Britain’s next war won’t be an away game: Q&A with former head of Defence Intelligence
As Chief of Defence Intelligence, General Sir Jim Hockenhull decided to declassify and publish what London knew of Russia’s plans to invade Ukraine, down to a map of the routes its forces would take. First seen on therecord.media Jump to article: therecord.media/interview-jim-hockenhull-uk-defence-intelligence-russia-ukraine
-
Russian businesses erase Durov-linked products after ‘terrorist’ designation
The designation, announced last week, came a day after Russia’s Federal Security Service (FSB) charged Durov with aiding terrorist activity and said it would seek to place him on an international wanted list. The agency accused Telegram of failing to remove channels and bots allegedly used by Ukrainian intelligence, as well as terrorist and extremist…
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/midnight-blizzard-hotel-wi-fi-networks-hacking/
-
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.”The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the…
-
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
-
Travelers Beware: Russian Intel Hacking Hotel Wi-Fi
Russian Intelligence Hackers Capture Captive Portals. Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest. Microsoft’s threat intelligence arm began tracking the threat in early May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/travelers-beware-russian-intel-hacking-hotel-wi-fi-a-32405
-
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/
-
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/captivecrunch-midnight-blizzard/
-
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers’ login credentials and infect devices with espionage malware, Microsoft said. First seen on therecord.media Jump to article: therecord.media/russian-wifi-hackers-hotels
-
Russian Hackers Exploit Hotel Wi-Fi in New CaptiveCrunch Espionage Campaign
Microsoft Threat Intelligence has uncovered CaptiveCrunch, a cyber espionage campaign linked to Storm-2945, a subgroup of Midnight Blizzard, the Russian state-linked threat actor associated with Russia’s Foreign Intelligence Service (SVR). First seen on thecyberexpress.com Jump to article: thecyberexpress.com/captivecrunch-midnight-blizzard/
-
Security Affairs newsletter Round 588 by Pierluigi Paganini INTERNATIONAL EDITION
Tags: adobe, email, flaw, hacker, international, microsoft, russia, vulnerability, WeeklyReview, wifiA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in…
-
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…
-
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-7-states-water-systems-hit-by-cyberattacks-likely-tied-to-iran/
-
Finland to disconnect fiber-optic link to Russia as lease expires
Finland stopped power transmissions with Russia at the start of the war in Ukraine, and two related telecom connections will stop at the end of this year, authorities said. First seen on therecord.media Jump to article: therecord.media/finland-russia-fiber-optic-disconnection
-
Breach Roundup: OpenAI Models on a Hacking Tear
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production. This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department and Angola teleco breached, SonicWall credential stuffing, Telegram founder charged in Russia, hidden prompt turns Microsoft Copilot into an AI worm. First seen on govinfosecurity.com…
-
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan. First seen on therecord.media Jump to article: therecord.media/telegram-belarus-activist-russia-cyberattack

