#nation-state
18 stories taggednation-state.

Former NSA Director Paul Nakasone Opens Private Security Advisory Firm
The retired four-star general who ran America's signals intelligence agency for six years is now taking his expertise to paying clients in government, business, and beyond.

AI Agents Ran a Four-Day Hacking Campaign Against Taiwan's Government Systems
Researchers say a cluster of artificial intelligence programs worked in near-total automation to steal credentials, map government networks, and probe a nuclear safety agency, a sign that organised hacking is getting cheaper and faster.

Hackers Are Using a Legitimate Remote-Access Tool to Spy on Companies, and Your Antivirus Won't Notice
A campaign called Smoke#Screen tricks employees into installing ScreenConnect, a genuine remote-support program, which then hands criminals full control of the victim's computer while looking completely normal to security software.

Iranian hackers suspected in attack on 30 US water systems
A wave of cyberattacks hit Minnesota water infrastructure on Sunday and Monday, briefly cutting supply to one town. Investigators say the methods match a known Iranian-linked group, though formal attribution has not yet been made.

Google Gives Hackers New Names, Here Is Why That Matters
Google's threat-intelligence team is replacing its old numbering system with memorable two-word labels for every hacking group it tracks, making it easier for researchers and companies to talk about the same criminals.

Moroccan Intelligence Insider Blows Whistle on Years of Pegasus Spyware Targeting
A former spy describes how Morocco reportedly used phone-hacking software since 2017 to surveil journalists, human rights workers, and foreign politicians, including cabinet ministers in Spain and officials in France.

A Hidden Door in Windows: How Attackers Can Blind Security Software to Malware
Researchers at Bitdefender have shown how a little-known Windows feature called bind links can be twisted to make malicious files invisible to the tools companies rely on to catch intrusions.

Siemens, Schneider Electric, and Rockwell Fix Dozens of Flaws in Factory Control Systems
Three of the world's biggest industrial equipment makers patched a wave of security flaws in the software that runs power plants, factories, and water systems. Here is what that means in plain English.

Your Incident Response Playbook Almost Certainly Does Not Cover AI Failures. That Is a Problem.
Seven in ten organisations have AI plugged into their core systems, yet most security teams are trying to handle AI breakdowns with tools built for a completely different kind of threat.

Security Consultant Who Secretly Fed Intel to BlackCat Ransomware Gang Gets Nearly Six Years
Angelo Martino was hired to help ransomware victims negotiate their way out. Instead, he sold their secrets to the criminals holding them hostage.

Microsoft Exposes GigaWiper, a New Malware That Spies on Victims Before Destroying Them
A newly discovered backdoor called GigaWiper quietly watches infected computers for months, then wipes or encrypts everything on command, with no way to recover the data.

An AI Agent Broke Into a Server, Taught Itself to Adapt, and Left a Ransom Note
Security firm Sysdig says it has documented the first fully autonomous AI-driven ransomware attack, where a program called JadePuffer broke into a database, encrypted thousands of records, and demanded Bitcoin payment without a human criminal directing any step.

Google and FBI Shut Down NetNut, a Criminal Anonymity Network Built on Millions of Hijacked Home Devices
NetNut rented out access to infected home and business routers so criminals and foreign spies could hide their tracks. A joint operation has disrupted it.

DHS Probes Intrusion Into HSIN, the Federal Info-Sharing Platform
The Homeland Security Information Network was compromised, according to the department. Attribution remains open. The exposure question is bigger than the intrusion itself.

FBI Dismantles 13 Sites Tied to Chinese Influence Operation Targeting Cleared US Personnel
The seized domains posed as consulting firms advertising jobs — a tradecraft pattern consistent with state-directed recruitment campaigns against intelligence community insiders.