#StateSponsored

2026-02-07

Hello everyone! It's been a pretty active 24 hours in the cyber world, with a significant ransomware incident, a deep dive into a global state-sponsored espionage campaign, and some critical warnings about social engineering on messaging apps. We're also seeing more scrutiny on biometric data and AI surveillance. Let's get into it:

Payment Gateway Hit by Ransomware ⚠️
- BridgePay Network Solutions, a major US payment gateway, has confirmed a ransomware attack caused widespread outages across its core production systems.
- The incident, which began on Friday, led to merchants nationwide being unable to process card payments, forcing some to go cash-only.
- While initial forensics suggest no payment card data was compromised, the attack encrypted files and highlights the critical impact of ransomware on payment infrastructure.

🤖 Bleeping Computer | bleepingcomputer.com/news/secu

Global Espionage Operation 'Shadow Campaigns' Uncovered 🕵️
- Palo Alto Networks' Unit 42 has detailed "Shadow Campaigns," a global espionage operation by an Asia-based state-sponsored actor (tracked as TGR-STA-1030/UNC6619) active since January 2024.
- The group has compromised at least 70 government and critical infrastructure organisations in 37 countries, with reconnaissance efforts targeting 155 nations.
- Initial access methods include tailored phishing with a custom 'Diaoyu' loader and exploitation of 15 known vulnerabilities, alongside the deployment of 'ShadowGuard', a custom Linux kernel eBPF rootkit designed for stealthy persistence.

🤖 Bleeping Computer | bleepingcomputer.com/news/secu

State-Sponsored Signal Phishing Targets High-Value Individuals 📱
- German intelligence agencies (BfV and BSI) are warning of state-sponsored phishing attacks via the Signal messaging app, targeting politicians, military personnel, diplomats, and journalists.
- Attackers impersonate "Signal Support" to trick victims into revealing their Signal PIN or scanning a malicious QR code, gaining access to contacts, profile information, and potentially message history.
- This campaign doesn't exploit Signal vulnerabilities but weaponises its legitimate features; similar tactics could extend to WhatsApp, underscoring the need for Registration Lock and vigilance against social engineering.

📰 The Hacker News | thehackernews.com/2026/02/germ

Biometric Surveillance Under Scrutiny 🔒
- New York City's MTA is trialling AI-powered cameras in subway gates to detect fare evasion, generating physical descriptions of suspected individuals and raising significant privacy concerns.
- This initiative is part of a broader trend of increasing biometric surveillance in NYC by both government and retailers, prompting warnings about "sleepwalking into a surveillance state."
- Separately, the DHS Inspector General has launched an audit into the Department of Homeland Security's privacy practices, specifically focusing on the collection and management of biometric data by ICE and OBIM amid allegations of civil liberties violations.

🗞️ The Record | therecord.media/nyc-explores-a
🤫 CyberScoop | cyberscoop.com/dhs-ig-audit-ic

#CyberSecurity #Ransomware #Espionage #APT #StateSponsored #Phishing #SocialEngineering #SignalApp #DataPrivacy #BiometricSurveillance #AI #InfoSec #ThreatIntelligence #IncidentResponse

2026-02-06

State-sponsored hackers compromised a beloved developer tool while AI platforms exposed millions of sensitive records.
#cybersecurity #supplychainattack #stateSponsored #botnet #databreach

cybernewsweekly.substack.com/p

דער קערפער פֿון השםdukepaaron@babka.social
2026-01-27

“History teaches us that this crime was not a momentary aberration, but the result of systematic hate rhetoric, #statesponsored #propaganda, and society’s tolerance of inhumanity,” KIS said.

“Yet today we see that #antisemitism is once again present, manifesting itself in new forms and under different guises. It is no longer ‘latent’; it no longer lurks beneath the surface or teeters at the margins. Goebbels-style propaganda has been replaced by #revisionism, #disinformation, and the #demonization of #Jews as a social and national collective.” 🔥

ekathimerini.com/in-depth/soci

2025-12-25

BBC: Amazon blocks 1,800 job applications from suspected North Korean agents. “A top Amazon executive has said the US technology giant has blocked more than 1,800 job applications from suspected North Korean agents. North Koreans tried to apply for remote working IT jobs using stolen or fake identities, Amazon’s chief security officer Stephen Schmidt said in a LinkedIn post.”

https://rbfirehose.com/2025/12/25/bbc-amazon-blocks-1800-job-applications-from-suspected-north-korean-agents/
2025-12-21

Tom’s Hardware: North Korean hackers stole record $2 billion in crypto in 2025, including single heist worth $1.5 billion, report claims — rogue state accounts for 60% of all reported crypto thefts this year, $6.75 billion total since records began. “North Korean hackers have hit an infernal milestone of stealing $2.02 billion of crypto in 2025, which is nearly 60% of the total $3.4 billion […]

https://rbfirehose.com/2025/12/21/toms-hardware-north-korean-hackers-stole-record-2-billion-in-crypto-in-2025-including-single-heist-worth-1-5-billion-report-claims-rogue-state-accounts-for-60-of-all-reported-crypto-t/
2025-12-02

Korea Times: Democracies at risk of persistent foreign manipulation, EU official warns. “The European Commission’s executive vice president for technology sovereignty, security and democracy has warned that democracies are facing ‘constant hybrid attacks’ from foreign actors and called for closer cooperation with Korea to counter cyberthreats, misinformation and online manipulation.”

https://rbfirehose.com/2025/12/02/korea-times-democracies-at-risk-of-persistent-foreign-manipulation-eu-official-warns/

דער קערפער פֿון השםdukepaaron@babka.social
2025-12-01

"Many #Americans know of #JosefStalin’s Terror of the late 1930s, during which more than 1 million people were arrested for #politicalcrimes, and over 680,000 #executed.

Fewer know about the repressions that began after #WorldWarII and ended with #Stalin’s death in 1953. Much like the repressions of the 1930s, they involved fabricated #plots, #arrests, coerced #confessions and #purges. Unlike the Terror of the 1930s, they were accompanied by a wave of #statesponsored #antisemitism – including the purge of #Jews from multiple occupations and unwritten quotas that limited their professional and educational opportunities.

The abolition of the #Jewish #AntiFascist Committee on Nov. 20, 1948, and the arrest and execution of its members was central to this postwar #assault."

theconversation.com/stalins-po

2025-11-28

Gizmodo: Congress Calls Anthropic CEO to Testify About AI Cyberattack Allegedly From China. “The House Homeland Security Committee has sent a letter to Anthropic CEO Dario Amodei to testify on Dec. 17 about a cyberattack campaign allegedly conducted by China-affiliated actors using the company’s Claude AI, according to a new report from Axios.”

https://rbfirehose.com/2025/11/28/gizmodo-congress-calls-anthropic-ceo-to-testify-about-ai-cyberattack-allegedly-from-china/

2025-11-23

The Guardian: Hundreds of English-language websites link to pro-Kremlin propaganda. “Hundreds of English-language websites – from mainstream news outlets to fringe blogs – are linking to articles from a pro-Kremlin network flooding the internet with disinformation, according to a study released by a London-based thinktank.”

https://rbfirehose.com/2025/11/23/the-guardian-hundreds-of-english-language-websites-link-to-pro-kremlin-propaganda/

2025-11-23

Daily Beast: Top MAGA Influencers Accidentally Unmasked as Foreign Trolls. “Upon rollout, rival factions began to inspect just where their online adversaries were really based on the combative social platform—with dozens of major MAGA and right-wing influencer accounts revealed to be based overseas.”

https://rbfirehose.com/2025/11/23/daily-beast-top-maga-influencers-accidentally-unmasked-as-foreign-trolls/

2025-11-20

Ars Technica: 5 plead guilty to laptop farm and ID theft scheme to land North Koreans US IT jobs . “Five men have pleaded guilty to running laptop farms and providing other assistance to North Koreans to obtain remote IT work at US companies in violation of US law, federal prosecutors said.”

https://rbfirehose.com/2025/11/20/ars-technica-5-plead-guilty-to-laptop-farm-and-id-theft-scheme-to-land-north-koreans-us-it-jobs/

2025-11-13

The Register: North Korean spies turn Google’s Find Hub into remote-wipe weapon. “North Korean state-backed spies have found a new way to torch evidence of their own cyber-spying – by hijacking Google’s Find Hub service to remotely wipe Android phones belonging to their South Korean targets.”

https://rbfirehose.com/2025/11/13/the-register-north-korean-spies-turn-googles-find-hub-into-remote-wipe-weapon/

2025-11-10

Jamestown Foundation: Kremlin Shifts Focus to Information Warfare. “Russia’s draft 2026 budget cuts military spending by $2.4 billion compared to 2025 while boosting funding for state-run media by 54 percent, signaling a potential pivot toward intensified information warfare.”

https://rbfirehose.com/2025/11/10/jamestown-foundation-kremlin-shifts-focus-to-information-warfare/

2025-11-08

Ars Technica: Wipers from Russia’s most cut-throat hackers rain destruction on Ukraine. “One of the world’s most ruthless and advanced hacking groups, the Russian state-controlled Sandworm, launched a series of destructive cyberattacks in the country’s ongoing war against neighboring Ukraine, researchers reported Thursday.”

https://rbfirehose.com/2025/11/08/ars-technica-wipers-from-russias-most-cut-throat-hackers-rain-destruction-on-ukraine/

2025-10-30

The Register: Major telecom supplier compromised by unnamed nation-state attackers. “Nation-state snoops broke into Ribbon Communications – an outfit that provides software and networking gear to Verizon, CenturyLink, and the US Defense Department – last December, remained hidden for about nine months, and stole files belonging to three customers, according to the US telecommunications firm.”

https://rbfirehose.com/2025/10/30/the-register-major-telecom-supplier-compromised-by-unnamed-nation-state-attackers/

2025-10-22

Over 100 government organizations hit by a single, stealthy campaign. MuddyWater’s new Phoenix backdoor uses cutting-edge tactics to slip past top defenses. Could this signal a new era in cyber espionage?

thedefendopsdiaries.com/the-ph

#muddywater
#phoenixbackdoor
#statesponsored
#cyberespionage
#malwareanalysis

💧🌏 Greg CocksGregCocks@techhub.social
2025-10-16

Chinese Gang Used ArcGIS As A Backdoor For A Year – And No One Noticed
[State sponsored] Crims turned trusted [#ESRI] mapping software into a hideout - no traditional malware required
--
theregister.com/2025/10/14/chi <-- shared media article
--
scworld.com/brief/novel-flax-t <-- shared technical media article
--
reliaquest.com/blog/threat-spo <-- shared security technical article
--
securityaffairs.com/183398/apt <-- shared security technical article
--
“A Chinese state-backed cybergang known as Flax Typhoon spent more than a year burrowing inside an ArcGIS server, quietly turning the trusted mapping software into a covert backdoor..."
#GIS #spatial #mapping #security #malware #exploit #ArcGIS #server #China #statesponsored #FlaxTyphoon #espionage #SOE #objectextension #hidden #payload #backups #risk #hazard #restapi #credentials #flaw #malicious #persistence

2025-10-08

CNN: Suspected Chinese government operatives used ChatGPT to shape mass surveillance proposals, OpenAI says. “Suspected Chinese government operatives asked ChatGPT to help write proposal for a tool to conduct large-scale surveillance and to help promote another that allegedly scans social media accounts for ‘extremist speech,’ ChatGPT-maker OpenAI said in a report published Tuesday.”

https://rbfirehose.com/2025/10/08/cnn-suspected-chinese-government-operatives-used-chatgpt-to-shape-mass-surveillance-proposals-openai-says/

2025-09-24

Ars Technica: US uncovers 100,000 SIM cards that could have “shut down” NYC cell network. “The US Secret Service announced this morning that it has located and seized a cache of telecom devices large enough to ‘shut down the cellular network in New York City.’ And it believes a nation-state is responsible.”

https://rbfirehose.com/2025/09/24/ars-technica-us-uncovers-100000-sim-cards-that-could-have-shut-down-nyc-cell-network/

2025-09-23

State hackers exploited a tiny email attachment flaw to take control of a major security gateway—but Libraesva shut it down with an emergency fix in just 17 hours. Curious how one small breach can rock the world of email security?

thedefendopsdiaries.com/librae

#libraesva
#cve202559689
#emailsecurity
#commandinjection
#statesponsored
#cybersecurity
#vulnerability
#incidentresponse
#patchmanagement

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst