Threat Intelligence — Page 16

Meta Catches NSO Spear-Phishing on WhatsApp, Asks Court to Hold Vendor in Contempt
The injunction was supposed to keep Pegasus operators away from WhatsApp users. Meta says NSO came back anyway — and is now asking a judge to do something about it.

VerdantBamboo Ports BRICKSTORM to BSD, Goes Hunting for Linux Appliances
A China-nexus crew is rewriting its toolkit to live on the boxes most EDR vendors forgot about.

UNC3753 Hit U.S. Professional Services Firms With Vishing and Walk-In Intrusions
Dozens of legal, financial, and consulting firms were hit between January and May 2026 in a data-theft extortion run that blended phone-based social engineering with physical site visits.

How Ukraine Turned a Nation-State Cyberwar Into a Masterclass in Operational Resilience
Former foreign minister Dmytro Kuleba details how pre-planned contingencies — not ad-hoc crisis management — kept Ukrainian government and business functions alive under sustained Russian attack.

Microsoft Bakes a Two-Hour Quarantine Into VS Code Extension Auto-Updates
The delay is a soft tripwire against marketplace supply chain attacks — buying defenders a window to flag malicious updates before they propagate.

Silent Ransom Group Escalates Vishing Campaign Against U.S. Law Firms
Mandiant tracks rapid data theft following fake IT-support calls, raising fresh questions about Form 8-K Item 1.05 disclosure timing for affected firms.

Bright Data's iOS SDK Quietly Conscripts Smart TVs Into a Scraping Proxy Network
A reverse-engineering of the SDK shows how consumer apps — including always-on televisions — relay traffic for the proxy giant now courting AI customers.

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected
The campaign — tracked publicly as Miasma — propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.

npm Hit by Dual Supply-Chain Campaigns: Rust Stealer With eBPF Rootkit, Self-Spreading Worm
Researchers flagged two parallel intrusions into the npm registry. One delivers a kernel-level credential scraper. The other propagates through more than 50 poisoned packages.

Asin Android Spyware Surfaces in Arabic-Language Lures, ESET Says
ESET ties early-2025 campaigns to decoy sites posing as utilities, war-tracking tools and a fake government news portal.

OP-512 Cluster Hits IIS Servers With Custom Web Shell Kit, Researchers Link Activity to China
A previously unreported intrusion set is dropping a bespoke web shell framework on Microsoft IIS servers, with espionage indicators pointing toward Beijing.

Five Eyes Warns: Chinese Intelligence Officers Posing as Recruiters to Harvest Government Secrets
A joint advisory flags a persistent social engineering campaign targeting personnel with access to classified material — fake job offers, real espionage.

World Cup 2026 Phishing Infrastructure Is Already Stood Up
Lookalike FIFA domains, trojanized streaming apps, and credential harvesters are live weeks before kickoff. The pattern is familiar; the scale isn't.

TA4922 Broadens Phishing Sweep Into U.K., Germany, Italy and South Africa
The China-linked crew is rotating through ValleyRAT, Atlas RAT and freshly minted payloads at a pace researchers describe as unusually fast.

The Week the Tape Came Off: Old Bugs, Cheap C2, and AI That Breaks Things
A roundup of the criminal-economy churn driving this week's intrusions, from plugin holes to agentic AI gone feral.