APT Security News

Advanced Persistent Threat (APT) groups — nation-state and highly resourced actors, their campaigns and attributed activity.

APT (Advanced Persistent Threat) groups are well-resourced, typically state-linked actors running long, targeted intrusion campaigns rather than opportunistic attacks. This feed tracks newly attributed activity, campaign reports and the tools and infrastructure researchers tie back to specific named groups. Coverage here tends to be lower-volume than commodity crime feeds but higher-stakes — APT activity often targets government, critical infrastructure and high-value corporate targets.

Recent APT items

North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Jobhttps://ift.tt/9oD5fhS
@ctinow · Aug 13, 2026
Sandworm hackers target IT pros with trojanized WireGuard VPN clienthttps://ift.tt/2d4O0EX
@ctinow · Aug 11, 2026
My new book is now available on AmazonThe Algorithmic BattlefieldIt explores how AI is changing cyberwarfare — autonomous attacks, nation-state operations, deepfakes, critical infrastructure, informat…
@ctinow · Aug 7, 2026
Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group) - ASEChttps://asec.ahnlab.com/en/94696/https://image.ahnl…
@malwr · Jul 30, 2026
ALERT >> One visit. No prompt. A compromised South Korean website could infect systems running vulnerable AnySign4PC versions.State-sponsored hackers used the chain to install SIGNBT or COPPERHEDGE ba…
@thehackernews · Jul 30, 2026
Leading members of Scattered Spider sentenced in UK to 66 months in jailhttps://cyberscoop.com/scattered-spider-leaders-sentenced-united-kingdom/
@PentestingNews · Jul 17, 2026
Tracking Advanced Persistent Threat Groups | Recorded Futurehttps://ift.tt/v1cz8uR
@ctinow · Jul 17, 2026
Leading members of Scattered Spider sentenced in UK to 66 months in jailhttps://ift.tt/VAl3W2Q
@ctinow · Jul 17, 2026
Two Scattered Spider Hackers Jailed in UK’s Largest Cybercrime Prosecutionhttps://gbhackers.com/two-scattered-spider-hackers-jailed-in-uks/
@PentestingNews · Jul 17, 2026
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hackhttps://ift.tt/pFQn5b7
@ctinow · Jul 16, 2026
Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattackhttps://ift.tt/lEKfozn
@ctinow · Jul 16, 2026
Two Scattered Spider hackers have been sentenced to 5.5 years each for the £29 million TfL attack.The intrusion left 148 systems inoperable, disrupted Dial-a-Ride and payment services, and forced all…
@thehackernews · Jul 16, 2026
Two Scattered Spider Hackers Sentenced to Jail in UKhttps://ift.tt/KUw9Qve
@ctinow · Jul 16, 2026
Scattered Spider members behind TfL hack get five years in prisonhttps://ift.tt/eW4bmLx
@ctinow · Jul 16, 2026
Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’https://cyberscoop.com/eu-uk-russian-cyberespionage-sanctions/
@PentestingNews · Jul 14, 2026
Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’https://ift.tt/vPL6WEO
@ctinow · Jul 13, 2026
Russian FSB-Linked Turla Hackers Target French Ministries, Embassies, and Defense Entitieshttps://gbhackers.com/russian-fsb-linked-turla-hackers/
@PentestingNews · Jul 13, 2026
Synthetic APTs: the Collapse of TTP-Based Attribution Cyber Threat Intelligence (CTI) attribution relies on identifying the Tactics, Techniques, and Procedures (TTPs) that distinguish one threat actor…
@malwr · Jul 10, 2026
Cybercrime did not need one big break this week. It used the usual doors: cloud storage, browser trust, support calls, package names, weak defaults, and exposed admin paths.This week’s #ThreatsDay cov…
@thehackernews · Jul 9, 2026
Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hackerhttps://ift.tt/sFg7wkt
@ctinow · Jul 7, 2026
Alleged Scattered Spider hacker caught by his own Windows device ID.Per a new court filing, he hid the attack behind proxies and fake names.But #Microsoft records tied one device ID to his ngrok acces…
@thehackernews · Jul 7, 2026
CYBER THREAT INTELLIGENCE ANALYSIS AND REPORTING: APT28 EXPLOITED MICROSOFT OFFICE FEATURE BYPASS…https://ift.tt/vm3S9WY
@ctinow · Jul 4, 2026
Alleged Scattered Spider Hacker Extradited to UShttps://ift.tt/pF4NT2z
@ctinow · Jul 3, 2026
Alleged longstanding member of Scattered Spider extradited to UShttps://cyberscoop.com/scattered-spider-peter-stokes-cybercrime-extradition/
@PentestingNews · Jul 2, 2026
Alleged longstanding member of Scattered Spider extradited to UShttps://ift.tt/UbkgzCv
@ctinow · Jul 2, 2026
Alleged Scattered Spider hacker extradited to the United Stateshttps://ift.tt/fJKRiA0
@ctinow · Jul 2, 2026
Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Chargeshttps://securityaffairs.com/194613/security/alleged-scattered-spider-hacker-extradited-to-u-s-to-face-cybercrime-charges.ht…
@PentestingNews · Jul 2, 2026
Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Chargeshttps://ift.tt/k3YpPlB
@ctinow · Jul 2, 2026
Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.https://thecyberexpress.com/scattered-spider-member-extradited/
@PentestingNews · Jul 2, 2026
19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Chargeshttps://ift.tt/uOwMVZN
@ctinow · Jul 1, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.