Tag: spy
-
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
-
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
-
Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe, and other…
-
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/
-
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and activate…
-
China spy chief points at US AI models in cyber threat warning
China’s spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development. First seen on therecord.media Jump to article: therecord.media/china-spy-chief-warns-of-us-ai-models
-
Thorough reorganization at NSA will create five ‘mission centers,’ including cyber and AI
The largest electronic spy agency in the world is reorganizing. And fast. First seen on therecord.media Jump to article: therecord.media/nsa-reorganization-five-mission-centers
-
4 Spy Groups Used BlueMoon on Chrome, Windows in One Week
Four spy groups used BlueMoon to chain Chrome and Windows zero-days in one week, showing why fast patching and post-compromise hunting matter. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-bluemoon-chrome-windows-exploit-kit/
-
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, First seen on thehackernews.com Jump to…
-
DPRK-Linked Hackers Backdoor HAProxy Servers to Spy on South Korean Organizations
A previously undocumented Linux espionage toolkit linked with medium confidence to DPRK-aligned threat actors has been used to compromise South Korean organizations in the automotive and media sectors. The campaign is notable because it does not exploit a flaw in HAProxy itself. Instead, the operators appear to have obtained code execution on targeted edge servers…
-
House Intel Warns AI Could Help Terrorists Build Weapons
House Intel Committee Warns Frontier Models Could Help Rogue Actors Build Weapons. The House Intelligence Committee warned in a 66-page review of the 9/11 Commission Report that frontier large language models could make it significantly easier for terrorists to build weapons of mass destruction, while urging U.S. spy agencies to speed up their own AI…
-
âš¡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.Elsewhere, fake apps, helpful support calls, cheap banking…
-
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users’ meeting information and potentially join calls. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/ai-notetaker-spy-government-corporate-video-calls
-
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers’ login credentials and infect devices with espionage malware, Microsoft said. First seen on therecord.media Jump to article: therecord.media/russian-wifi-hackers-hotels
-
Hackers used autonomous AI agent to spy on Thailand’s finance ministry
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand’s Ministry of Finance, researchers discovered. First seen on therecord.media Jump to article: therecord.media/thailand-hackers-ai-finance-ministry
-
Project CAV3RN Hides Its C2 in Outlook Calendar Events to Spy on Israel
At a glance Threat actor Project CAV3RN cluster; linked to OilRig (APT34) with low confidence Activity type Cyberespionage; First seen on securityonline.info Jump to article: securityonline.info/project-cav3rn-outlook-calendar-c2/
-
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Tags: advisory, cctv, cybersecurity, intelligence, Internet, military, russia, service, spy, ukraineAt least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and military…
-
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel. First seen on therecord.media Jump to article: therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands
-
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel. First seen on therecord.media Jump to article: therecord.media/russian-intelligence-compromising-cameras-nato-ukraine-netherlands
-
Hackers exploit Roundcube flaw to spy on academic researchers
A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-roundcube-flaw-to-spy-on-academic-researchers/
-
Canada’s spy agency conducted state-authorized cyberattacks against drug traffickers and ransomware gangs
First seen on scworld.com Jump to article: www.scworld.com/brief/canadas-spy-agency-conducted-state-authorized-cyberattacks-against-drug-traffickers-and-ransomware-gangs
-
Alibaba Bans Claude Code Over Spy-Like Tracking Code
Supply-Chain Risks Cited After Hidden Code Checked for China-Related Indicators. The latest twist in the U.S.-China AI race sees Alibaba ban Anthropic’s Claude Code after hidden tracking code sparked backlash, adding another layer to an increasingly bitter battle over AI leadership. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/alibaba-bans-claude-code-over-spy-like-tracking-code-a-32162
-
Canadian spy agency reports hacking three criminal groups in 2025
A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada’s Communications Security Establishment. First seen on therecord.media Jump to article: therecord.media/canada-cse-2025-cyber-operations-ransomware-drugs-extremism
-
Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year
The hacking operations disclosed in a Canadian spy agency’s annual report underscores some pressing national security threats facing the country and its top allies. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/06/canadian-spy-agency-says-it-hacked-drug-traffickers-extremists-and-a-ransomware-gang-last-year/
-
Canadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last year
The hacking operations disclosed in a Canadian spy agency’s annual report underscores some pressing national security threats facing the country and its top allies. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/06/canadian-spy-agency-says-it-hacked-drug-traffickers-extremists-and-a-ransomware-gang-last-year/
-
Glitch SPY RAT Abuses Android Accessibility Service for Full Device Control
An emerging Android remote-access trojan platform, tracked as Glitch SPY, that leverages a fraudulent Polish apartment-rental website to trick victims into sideloading a malicious APK. The dropper, identified as the Brokewell Android Loader, presents a plausible rental-app experience while secretly installing Glitch SPY and coercing users to enable Android Accessibility Service an abuse that gives…
-
Canada’s spy agency uses threat reduction powers to neutralize foreign botnets
First seen on scworld.com Jump to article: www.scworld.com/brief/canadas-spy-agency-uses-threat-reduction-powers-to-neutralize-foreign-botnets
-
Canada’s Spy Agency Used FirstIts-Kind Warrant to Clean Botnet-Infected Devices
Canada’s spy service got a judge’s permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers…
-
4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
AryStinger hijacks outdated routers via old flaws, turning 4,300+ devices into a stealth network for reconnaissance and intrusion support. On March 12, 2026, QiAnXin’s XLab threat detection system flagged a single IP address, 107.150.106.14, spreading a Linux binary through two vulnerabilities that were disclosed in 2013 and 2016 respectively. The binary had zero detections on…
-
Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone
Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users.The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio device…

