APT Security News

Advanced Persistent Threat (APT) groups — nation-state and highly resourced actors, their campaigns and attributed activity.

APT (Advanced Persistent Threat) groups are well-resourced, typically state-linked actors running long, targeted intrusion campaigns rather than opportunistic attacks. This feed tracks newly attributed activity, campaign reports and the tools and infrastructure researchers tie back to specific named groups. Coverage here tends to be lower-volume than commodity crime feeds but higher-stakes — APT activity often targets government, critical infrastructure and high-value corporate targets.

Recent APT items

Cybersecurity Newsletter Bulletin– Top 50 Biggest Cybersecurity Stories of the Week – Shell & Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware & More https://gb…
@PentestingNews · Aug 24, 2026
15 NEW Stories. Trust got weaponized everywhere.Defender driver EDR bypass • ClickFix + BYOVD • Grandoreiro sideloading • CircleCI MCP RCE • Gogs 10.0 RCE • n8n RCE • refrigeration controller flaws •…
@thehackernews · Aug 20, 2026
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job https://ift.tt/9oD5fhS
@ctinow · Aug 13, 2026
Sandworm hackers target IT pros with trojanized WireGuard VPN client https://ift.tt/2d4O0EX
@ctinow · Aug 11, 2026
My new book is now available on AmazonThe Algorithmic BattlefieldIt explores how AI is changing cyberwarfare — autonomous attacks, nation-state operations, deepfakes, critical infrastructure, informat…
@ctinow · Aug 7, 2026
Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - ASEC https://asec.ahnlab.com/en/94696/ https://image.ah…
@malwr · Jul 30, 2026
ALERT >> One visit. No prompt. A compromised South Korean website could infect systems running vulnerable AnySign4PC versions.State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE ba…
@thehackernews · Jul 30, 2026
Leading members of Scattered Spider sentenced in UK to 66 months in jail https://cyberscoop.com/scattered-spider-leaders-sentenced-united-kingdom/
@PentestingNews · Jul 17, 2026
Tracking Advanced Persistent Threat Groups | Recorded Future https://ift.tt/v1cz8uR
@ctinow · Jul 17, 2026
Leading members of Scattered Spider sentenced in UK to 66 months in jail https://ift.tt/VAl3W2Q
@ctinow · Jul 17, 2026
Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution https://gbhackers.com/two-scattered-spider-hackers-jailed-in-uks/
@PentestingNews · Jul 17, 2026
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack https://ift.tt/pFQn5b7
@ctinow · Jul 16, 2026
Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack https://ift.tt/lEKfozn
@ctinow · Jul 16, 2026
Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack.The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all…
@thehackernews · Jul 16, 2026
Two Scattered Spider Hackers Sentenced to Jail in UK https://ift.tt/KUw9Qve
@ctinow · Jul 16, 2026
Scattered Spider members behind TfL hack get five years in prison https://ift.tt/eW4bmLx
@ctinow · Jul 16, 2026
Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ https://cyberscoop.com/eu-uk-russian-cyberespionage-sanctions/
@PentestingNews · Jul 14, 2026
Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ https://ift.tt/vPL6WEO
@ctinow · Jul 13, 2026
Russian FSB-Linked Turla Hackers Target French Ministries, Embassies, and Defense Entities https://gbhackers.com/russian-fsb-linked-turla-hackers/
@PentestingNews · Jul 13, 2026
Synthetic APTs: the Collapse of TTP-Based Attribution Cyber Threat Intelligence (CTI) attribution relies on identifying the Tactics, Techniques, and Procedures (TTPs) that distinguish one threat actor…
@malwr · Jul 10, 2026
Cybercrime did not need one big break this week. It used the usual doors: cloud storage, browser trust, support calls, package names, weak defaults, and exposed admin paths.This week’s #ThreatsDay cov…
@thehackernews · Jul 9, 2026
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker https://ift.tt/sFg7wkt
@ctinow · Jul 7, 2026
Alleged Scattered Spider hacker caught by his own Windows device ID.Per a new court filing, he hid the attack behind proxies and fake names.But #Microsoft records tied one device ID to his ngrok acces…
@thehackernews · Jul 7, 2026
CYBER THREAT INTELLIGENCE ANALYSIS AND REPORTING: APT28 EXPLOITED MICROSOFT OFFICE FEATURE BYPASS… https://ift.tt/vm3S9WY
@ctinow · Jul 4, 2026
Alleged Scattered Spider Hacker Extradited to US https://ift.tt/pF4NT2z
@ctinow · Jul 3, 2026
Alleged longstanding member of Scattered Spider extradited to US https://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition/
@PentestingNews · Jul 2, 2026
Alleged longstanding member of Scattered Spider extradited to US https://ift.tt/UbkgzCv
@ctinow · Jul 2, 2026
Alleged Scattered Spider hacker extradited to the United States https://ift.tt/fJKRiA0
@ctinow · Jul 2, 2026
Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges https://securityaffairs.com/194613/security/alleged-scattered-spider-hacker-extradited-to-u-s-to-face-cybercrime-charges.h…
@PentestingNews · Jul 2, 2026
Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges https://ift.tt/k3YpPlB
@ctinow · Jul 2, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.