WORLDINTELLIGENCE
.live · global situation
UTC--:--:--
CRITICALEastern EuropeSustained energy-infrastructure strike pattern observedHIGHRed SeaVessel-traffic anomaly continues in southern transit laneHIGHEast AsiaMultiple grey-zone incursions across median line in 24h windowMEDIUMSahelCivilian-protection deterioration in northern provincesMEDIUMAndesMagnitude 6.1 seismic event, shallow depthLOWGlobalCrypto OTC desks observe elevated cross-border settlement volumesCRITICALEastern EuropeSustained energy-infrastructure strike pattern observedHIGHRed SeaVessel-traffic anomaly continues in southern transit laneHIGHEast AsiaMultiple grey-zone incursions across median line in 24h windowMEDIUMSahelCivilian-protection deterioration in northern provincesMEDIUMAndesMagnitude 6.1 seismic event, shallow depthLOWGlobalCrypto OTC desks observe elevated cross-border settlement volumes
APT · Ransomware · CVE · ICS

Cyber Intelligence

Tracked APT activity

Cyber news

cyber
Dark Readingabout 6 hours ago

Pakistan Spies on Afghan Finance Ministry With Xeno RAT

Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.

cyber
BleepingComputerabout 12 hours ago

Chinese hackers use new Atlas RAT malware in European cyberattacks

A Chinese-speaking cybercrime group has expanded its targeting to the European space, deploying previously undocumented malware and the Atlas backdoor. [...]

cyber
Dark Readingabout 12 hours ago

Attackers Use AI to Automate EDR Evasion Testing

Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.

cyber
BleepingComputerabout 13 hours ago

U.S. sanctions Nobitex crypto exchange used by Iranian ransomware actors

The U.S. Treasury's Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments related to terrorist activities. [...]

cyber
BleepingComputerabout 13 hours ago

CISA warns of cyberattacks targeting fuel tank monitoring systems

CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors. [...]

cyber
Dark Readingabout 14 hours ago

Tropical Blend: Cyber & Politics Ramp Up Across Latin America

China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.

cyber
Dark Readingabout 14 hours ago

Cyber Insurance Rates Are Dropping, but Exclusions Widen

Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.

cyber
BleepingComputerabout 14 hours ago

New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute

A new denial-of-service (DoS) attack dubbed HTTP/2 Bomb can be launched from a single machine to take down web servers within seconds. [...]

cyber
Dark Readingabout 15 hours ago

Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover

A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data.

cyber
BleepingComputerabout 18 hours ago

CISA warns of active attacks exploiting Android, Linux bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting vulnerabilities in the Linux kernel and Android operating system. [...]

cyber
BleepingComputerabout 19 hours ago

What 345 Days of Untested Exposure Looks Like at a Bank

A two-week penetration test can leave roughly 345 days of real-world exposure unvalidated. Sprocket Security explores why continuous testing is becoming critical as attack surfaces constantly change. [...]

cyber
Dark Readingabout 22 hours ago

Malicious Notifications Could Trick Google Gemini Users

A prompt injection flaw in Google Gemini's voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more.