APT Security News

Advanced Persistent Threat (APT) groups: nation-state and highly resourced actors, their campaigns and attributed activity.

APT (Advanced Persistent Threat) groups are well-resourced, typically state-linked actors running long, targeted intrusion campaigns rather than opportunistic attacks. Newly attributed activity, campaign reports, and the tools and infrastructure researchers tie back to named groups all land here. Volume is lower than the commodity-crime feeds, but the targets are government bodies, critical infrastructure and high-value corporate networks.

Recent APT items

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks https://cyberscoop.com/senate-telecom-cybersecurity-resilience-act-salt-typhoon/
@PentestingNews · Sep 24, 2026
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks https://ift.tt/Qh6GfyC
@ctinow · Sep 24, 2026
Early Scattered Spider member pleads guilty to cybercrime spree https://cyberscoop.com/scattered-spider-member-guilty-ahmed-elbadawy/
@PentestingNews · Sep 19, 2026
Early Scattered Spider member pleads guilty to cybercrime spree https://ift.tt/YbxMVEr
@ctinow · Sep 18, 2026
Cyber Op Targets South Korean Media & Automotive Sectors 🕵️♂️ A likely North Korean advanced persistent threat APT group used a previously undocumented Linux espionage toolkit to compromise load balan…
@cibsecurity · Sep 17, 2026
Cyber Op Targets South Korean Media & Automotive Sectors 🕵️♂️ A likely North Korean advanced persistent threat APT group used a previously undocumented Linux espionage toolkit to compromise load balan…
@cibsecurity · Sep 16, 2026
Cyber Op Targets South Korean Media & Automotive Sectors 🕵️♂️ A likely North Korean advanced persistent threat APT group used a previously undocumented Linux espionage toolkit to compromise load balan…
@cibsecurity · Sep 16, 2026
Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink https://ift.tt/I15MUpY
@ctinow · Sep 14, 2026
Hackers abused Claude to extract secrets from 1.8M Android apps Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and Chi…
@bleepingcomputer · Sep 11, 2026
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection https://ift.tt/vPio6Nz
@ctinow · Sep 11, 2026
Russian state-sponsored hackers used Claude to rebuild malware whenever security tools detected it.Anthropic says GTG-20006 also used AI for phishing infrastructure and C2 monitoring while targeting m…
@thehackernews · Sep 11, 2026
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separat…
@bleepingcomputer · Sep 10, 2026
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers https://ift.tt/42mA9Kq
@ctinow · Sep 10, 2026
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days https://securityaffairs.com/198783/apt/four-nation-state-actors-used-the-same-chrome-zero-day-exploit-kit-within-12-da…
@PentestingNews · Sep 10, 2026
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days https://ift.tt/rKRBPgx
@ctinow · Sep 10, 2026
It turns out this goop someone sent me in a DM was state-sponsored malware designed to perform espionage on select groups on individuals in South America This malware campaign was attributed to APT-C-…
@vxunderground · Aug 30, 2026
Cybersecurity Newsletter Bulletin– Top 50 Biggest Cybersecurity Stories of the Week – Shell & Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware & More https://gb…
@PentestingNews · Aug 24, 2026
15 NEW Stories. Trust got weaponized everywhere.Defender driver EDR bypass • ClickFix + BYOVD • Grandoreiro sideloading • CircleCI MCP RCE • Gogs 10.0 RCE • n8n RCE • refrigeration controller flaws •…
@thehackernews · Aug 20, 2026
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job https://ift.tt/9oD5fhS
@ctinow · Aug 13, 2026
Sandworm hackers target IT pros with trojanized WireGuard VPN client https://ift.tt/2d4O0EX
@ctinow · Aug 11, 2026
Smile, You’re on Camera! North Korean IT Workers Got Hired and Exposed Live Researchers created a fake company, hired suspected DPRK operatives linked to Lazarus Group, and watched their activity unfo…
@Cyber_Security_Channel · Aug 11, 2026
My new book is now available on AmazonThe Algorithmic BattlefieldIt explores how AI is changing cyberwarfare — autonomous attacks, nation-state operations, deepfakes, critical infrastructure, informat…
@ctinow · Aug 7, 2026
get dm > "smelly, is this goop?" (malware) > "i found it on x" > links GitHub > download > look inside > .net goop > didnt strip metadata > internally refers to itself as FunkyStar > internally does "…
@vxunderground · Aug 1, 2026
July 2026 in Cyber: AI Agents Went on Offense, Vuln Loads Broke Records Autonomous AI agents showed up on both sides — Hugging Face was breached by an external agent looping through a swarm of sandbox…
@Cyber_Security_Channel · Jul 31, 2026
Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - ASEC https://asec.ahnlab.com/en/94696/ https://image.ah…
@malwr · Jul 30, 2026
ALERT >> One visit. No prompt. A compromised South Korean website could infect systems running vulnerable AnySign4PC versions.State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE ba…
@thehackernews · Jul 30, 2026
Leading members of Scattered Spider sentenced in UK to 66 months in jail https://cyberscoop.com/scattered-spider-leaders-sentenced-united-kingdom/
@PentestingNews · Jul 17, 2026
Tracking Advanced Persistent Threat Groups | Recorded Future https://ift.tt/v1cz8uR
@ctinow · Jul 17, 2026
Leading members of Scattered Spider sentenced in UK to 66 months in jail https://ift.tt/VAl3W2Q
@ctinow · Jul 17, 2026
Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecution https://gbhackers.com/two-scattered-spider-hackers-jailed-in-uks/
@PentestingNews · Jul 17, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.