Intelligence Division

Raptor Cyber Weapon Reports

Intelligence-grade research reports on cyber weapons, offensive tools, nation-state programs, AI warfare, and zero-day ecosystems. Download PDF versions where available.

Operation Riptide Intensifies: FBI Dismantles State-Sponsored Infrastructure Amid Rising AI-Driven Cyber Threats
State Cyber Warfarecritical 4 min

Operation Riptide Intensifies: FBI Dismantles State-Sponsored Infrastructure Amid Rising AI-Driven Cyber Threats

As of October 2026, the FBI's Operation Riptide is actively dismantling state-sponsored cyber infrastructure. This comes as healthcare and critical sectors face a surge in AI-powered nation-state attacks.

FBI / American Hospital Association
2026-10-03
Autonomous 'CLOSEDQUORUM' Malware Uses Multi-Model AI Voting to Execute Cyber Attacks
AI Cyber Attackscritical 4 min

Autonomous 'CLOSEDQUORUM' Malware Uses Multi-Model AI Voting to Execute Cyber Attacks

Cisco Talos has identified a novel malware strain, CLOSEDQUORUM, that autonomously decides its next attack phase by polling four commercial AI models, eliminating the need for human operators.

Cisco Talos
2026-10-03
Autonomous 'CLOSEDQUORUM' Malware Uses Multi-Model AI Voting to Orchestrate Cyber Attacks
AI Cyber Attackscritical 4 min

Autonomous 'CLOSEDQUORUM' Malware Uses Multi-Model AI Voting to Orchestrate Cyber Attacks

Security researchers have identified CLOSEDQUORUM, a novel strain of malware that autonomously determines its next malicious action by polling four distinct commercial AI models for consensus.

Cisco Talos
2026-10-03
Critical Zero-Day Exploitation Surge: Citrix NetScaler and F5 BIG-IP Under Active Attack
Zero-Day Exploitscritical 4 min

Critical Zero-Day Exploitation Surge: Citrix NetScaler and F5 BIG-IP Under Active Attack

Global infrastructure faces heightened risk as threat actors exploit critical zero-day vulnerabilities in Citrix NetScaler and F5 BIG-IP appliances. Security agencies have issued urgent warnings.

Mandiant
2026-10-02
Critical Zero-Day Exploitation Wave: Citrix and F5 BIG-IP Under Siege
Zero-Day Exploitscritical 4 min

Critical Zero-Day Exploitation Wave: Citrix and F5 BIG-IP Under Siege

Security teams are scrambling to patch critical RCE vulnerabilities in Citrix NetScaler and F5 BIG-IP APM after confirmed in-the-wild exploitation. These zero-days allow unauthenticated remote code execution.

Mandiant
2026-10-02
MI5 Issues Urgent Alert: Chinese MSS-Linked Institute Funding UK Academic Espionage
Cyber Espionagehigh 4 min

MI5 Issues Urgent Alert: Chinese MSS-Linked Institute Funding UK Academic Espionage

British intelligence has exposed a Chinese research institute with deep ties to the Ministry of State Security (MSS) for funding over 100 UK academics. The operation focuses on harvesting sensitive research in AI, cyber warfare, and covert communications.

MI5
2026-10-02
Autonomous 'CLOSEDQUORUM' Malware Uses Multi-LLM Voting to Orchestrate Cyber Attacks
AI Cyber Attackscritical 4 min

Autonomous 'CLOSEDQUORUM' Malware Uses Multi-LLM Voting to Orchestrate Cyber Attacks

Security researchers have identified CLOSEDQUORUM, a novel malware strain that utilizes a consensus-based voting mechanism across four commercial AI models to autonomously determine its next malicious move.

Cisco Talos
2026-10-02
Global Surge in Mercenary Spyware Alerts: Apple Targets 110 Countries in Latest Security Push
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware Alerts: Apple Targets 110 Countries in Latest Security Push

Apple has issued a massive wave of threat notifications to users across 110 countries, warning of targeted mercenary spyware attacks. This escalation highlights the persistent threat posed by private exploit brokers.

Microsoft MSTIC
2026-10-02
ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Extortion Campaigns
Threat Intelligencecritical 4 min

ThreeAM and Morpheus Ransomware Groups Launch Coordinated Global Extortion Campaigns

As of October 2, 2026, the ThreeAM and Morpheus ransomware groups have targeted critical infrastructure in Colombia and Taiwan, respectively, utilizing double extortion tactics to pressure victims.

Dexpose.io
2026-10-02
Autonomous Malware 'CLOSEDQUORUM' Uses Multi-LLM Voting to Execute Cyber Attacks
AI Cyber Attackscritical 4 min

Autonomous Malware 'CLOSEDQUORUM' Uses Multi-LLM Voting to Execute Cyber Attacks

Security researchers have identified CLOSEDQUORUM, a novel malware strain that utilizes a consensus-based voting mechanism across four commercial AI models to autonomously determine its next malicious move.

Cisco Talos
2026-10-02
Escalating Surveillance: Pegasus Zero-Click Exploits Target Civil Society in Eastern Europe
Offensive Toolscritical 4 min

Escalating Surveillance: Pegasus Zero-Click Exploits Target Civil Society in Eastern Europe

Recent forensic analysis confirms the deployment of advanced zero-click spyware against activists in Serbia. This incident highlights the persistent threat posed by commercial surveillance vendors.

Mandiant
2026-10-02
Japanese Railway Infrastructure Targeted in Coordinated Cyber-Espionage Campaign
Critical Infrastructurehigh 4 min

Japanese Railway Infrastructure Targeted in Coordinated Cyber-Espionage Campaign

Recent cyberattacks targeting Japanese railway operators have raised alarms regarding the security of critical transportation networks. Security analysts are investigating potential links to state-sponsored actors seeking to map operational technology vulnerabilities.

Industrial Cyber
2026-10-02
Global Intelligence Alert: BlueMoon Exploit Kit Adopted by Multiple Nation-State Actors
State Cyber Warfarecritical 4 min

Global Intelligence Alert: BlueMoon Exploit Kit Adopted by Multiple Nation-State Actors

Four distinct nation-state threat actors have rapidly adopted the BlueMoon Chrome-and-Windows exploit kit within a 12-day window. This surge suggests a coordinated or AI-accelerated proliferation of zero-day capabilities targeting global infrastructure.

Microsoft MSTIC
2026-10-02
Pentagon Data Breach Exposes Millions of Military Records and Social Security Numbers
Threat Intelligencecritical 4 min

Pentagon Data Breach Exposes Millions of Military Records and Social Security Numbers

A massive data breach at the Pentagon has resulted in the exposure of sensitive military records and Social Security numbers for millions of individuals. This incident marks a significant escalation in the ongoing wave of cyber extortion campaigns targeting high-value government infrastructure.

Malwarebytes Blog
2026-10-01
Escalating Mercenary Spyware Crisis: Pegasus and NoviSpy Campaigns Target Serbian Activists
Offensive Toolscritical 4 min

Escalating Mercenary Spyware Crisis: Pegasus and NoviSpy Campaigns Target Serbian Activists

A surge in zero-click spyware attacks has hit Serbian student activists, with confirmed infections of NSO Group's Pegasus and the emerging NoviSpy tool. This follows a global wave of Apple threat notifications issued to users across 110 countries.

Citizen Lab
2026-10-01
Global Surge in Mercenary Spyware Attacks Triggers Mass Apple Security Alerts
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware Attacks Triggers Mass Apple Security Alerts

Apple has issued a widespread wave of threat notifications to users across 110 countries, warning of sophisticated mercenary spyware targeting high-risk individuals. This escalation follows recent reports of zero-click exploits, including the targeting of activists in Serbia.

Apple Security Intelligence
2026-10-01
Qilin Ransomware Surge Targets Industrial Sector as Global Critical Infrastructure Threats Escalate
Critical Infrastructurecritical 4 min

Qilin Ransomware Surge Targets Industrial Sector as Global Critical Infrastructure Threats Escalate

Industrial sectors face a record-high wave of ransomware attacks in late 2026, with the Qilin group emerging as a dominant threat. Security experts warn that IT/OT convergence is significantly expanding the attack surface for critical infrastructure.

Industrial Cyber
2026-10-01
Critical Zero-Day Exploitation Campaign Targets Citrix NetScaler ADC and Gateway Appliances Globally
Zero-Day Exploitscritical 4 min

Critical Zero-Day Exploitation Campaign Targets Citrix NetScaler ADC and Gateway Appliances Globally

Threat actors are actively exploiting two critical remote code execution zero-day vulnerabilities in Citrix NetScaler ADC and Gateway. CISA has added these flaws to its Known Exploited Vulnerabilities catalog.

CISA
2026-10-01
Iranian-Linked 'Nimbus Manticore' Expands Espionage Arsenal with Advanced Backdoors
Cyber Espionagehigh 4 min

Iranian-Linked 'Nimbus Manticore' Expands Espionage Arsenal with Advanced Backdoors

Security researchers have identified a surge in activity from the Iranian state-sponsored group Nimbus Manticore. The group is deploying sophisticated new backdoors and SSH tunneling tools to maintain long-term persistence in targeted government and critical infrastructure networks.

Group-IB
2026-10-01
Autonomous 'CLOSEDQUORUM' Malware Uses AI Hive Mind for Self-Directed Cyber Attacks
AI Cyber Attackscritical 4 min

Autonomous 'CLOSEDQUORUM' Malware Uses AI Hive Mind for Self-Directed Cyber Attacks

Cisco Talos researchers have identified a new autonomous malware strain, CLOSEDQUORUM, which utilizes a multi-LLM 'hive mind' to make real-time tactical decisions during network intrusions.

Cisco Talos
2026-10-01
China-Linked JDY Botnet Escalates Reconnaissance Against U.S. Military Infrastructure
State Cyber Warfarecritical 4 min

China-Linked JDY Botnet Escalates Reconnaissance Against U.S. Military Infrastructure

Recent intelligence indicates the China-linked JDY botnet has significantly expanded its targeting scope, focusing on U.S. military networks and critical infrastructure for long-term pre-positioning.

Bleeping Computer
2026-10-01
Krybit Ransomware Escalates Operations with Targeted Attack on Indian Construction Sector
Threat Intelligencehigh 4 min

Krybit Ransomware Escalates Operations with Targeted Attack on Indian Construction Sector

The emerging Krybit ransomware group has intensified its operations, successfully breaching and leaking data from an Indian construction firm. This incident highlights a growing trend of sector-specific targeting.

Cyfirma
2026-10-01
Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors
Threat Intelligencecritical 4 min

Chaos and M3rx Ransomware Groups Escalate Attacks on US Professional and Healthcare Sectors

Recent intelligence confirms a surge in double-extortion attacks by Chaos and M3rx, targeting US-based healthcare and legal entities. These groups are leveraging stolen data to force rapid ransom payments.

Microsoft MSTIC
2026-10-01
Emerging 'PromptFlux' Variant Leverages Real-Time LLM Code Injection for Stealthy Persistence
AI Cyber Attackshigh 4 min

Emerging 'PromptFlux' Variant Leverages Real-Time LLM Code Injection for Stealthy Persistence

Security researchers have identified a new iteration of the PromptFlux malware that utilizes live API calls to LLMs to rewrite its own source code, effectively bypassing traditional signature-based detection.

Google Threat Intelligence Group
2026-09-30
State-Sponsored Actors Pivot to Ransomware-as-a-Cover for Global Espionage Campaigns
State Cyber Warfarecritical 4 min

State-Sponsored Actors Pivot to Ransomware-as-a-Cover for Global Espionage Campaigns

Recent intelligence indicates a surge in nation-state actors masking espionage operations as ransomware attacks. This shift complicates attribution and allows groups to bypass traditional security controls.

NCC Group
2026-09-30
Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors
Threat Intelligencecritical 4 min

Chaos and M3rx Ransomware Groups Escalate Attacks on US Healthcare and Legal Sectors

As of September 30, 2026, the Chaos and M3rx ransomware groups have launched targeted double-extortion campaigns against US-based organizations, threatening the release of hundreds of gigabytes of sensitive data.

Dexpose Intel Feeds
2026-09-30
Global Surge in Mercenary Spyware Alerts: Apple Warns High-Risk Users Across 110 Countries
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware Alerts: Apple Warns High-Risk Users Across 110 Countries

Apple has issued a significant wave of threat notifications to users in 110 countries, warning of targeted mercenary spyware attacks. These sophisticated, state-linked operations continue to threaten journalists, activists, and officials globally.

Apple Security Intelligence
2026-09-30
Galago Ransomware Emerges: New Double-Extortion Threat Linked to Panzer Group
Threat Intelligencehigh 4 min

Galago Ransomware Emerges: New Double-Extortion Threat Linked to Panzer Group

A new ransomware operation dubbed Galago has surfaced, showing operational ties to the established Panzer extortion group. Security researchers are monitoring the group's dark leak site as it begins targeting organizations globally.

GBHackers
2026-09-30
Industrial Sector Faces Record Ransomware Surge as Qilin Group Targets Critical Infrastructure
Critical Infrastructurecritical 4 min

Industrial Sector Faces Record Ransomware Surge as Qilin Group Targets Critical Infrastructure

Industrial organizations are currently facing a record-breaking wave of ransomware attacks, with the Qilin threat group accounting for a significant portion of the activity as of late September 2026.

Industrial Cyber
2026-09-30
Critical Zero-Day Exploitation Hits Citrix NetScaler ADC and Gateway Appliances Globally
Zero-Day Exploitscritical 4 min

Critical Zero-Day Exploitation Hits Citrix NetScaler ADC and Gateway Appliances Globally

Citrix has confirmed active, in-the-wild exploitation of two critical remote code execution zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway products.

Rapid7
2026-09-30
Critical Zero-Day Exploitation Confirmed in Citrix NetScaler ADC and Gateway Appliances
Zero-Day Exploitscritical 4 min

Critical Zero-Day Exploitation Confirmed in Citrix NetScaler ADC and Gateway Appliances

Citrix has issued emergency patches for two critical RCE zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, following confirmed in-the-wild exploitation. CISA has added both flaws to its Known Exploited Vulnerabilities (KEV) catalog, urging immediate remediation.

Rapid7
2026-09-30
Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing
Cyber Espionagehigh 4 min

Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing

The Iranian-linked threat actor Nimbus Manticore has launched a new wave of cross-platform cyber espionage campaigns. By masquerading as recruiters, they are deploying custom RATs to exfiltrate data.

The Hacker News
2026-09-30
AI-Driven Cyber Attacks Surge: 89% Increase in Machine-Assisted Threats Reported
AI Cyber Attackscritical 4 min

AI-Driven Cyber Attacks Surge: 89% Increase in Machine-Assisted Threats Reported

Cybersecurity analysts report an 89% surge in machine-assisted attacks as threat actors leverage LLMs to shrink patch windows to 48 hours. AI is now simultaneously the primary weapon and a high-value target.

CrowdStrike
2026-09-30
Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave
Threat Intelligencecritical 4 min

Ransomware Surge: Emperador and SafePay Lead Record-Breaking September 2026 Extortion Wave

Global ransomware incidents hit record highs in late September 2026, with groups like Emperador and SafePay aggressively targeting critical infrastructure and financial services using double-extortion tactics.

Microsoft MSTIC
2026-09-29
Ransomware Surge: Emperador and SafePay Groups Escalate Attacks on US and European Infrastructure
Threat Intelligencecritical 4 min

Ransomware Surge: Emperador and SafePay Groups Escalate Attacks on US and European Infrastructure

Ransomware activity has reached record highs in late 2026, with new campaigns by Emperador and SafePay targeting critical sectors. Over 1,000 organizations were impacted in August alone.

NCC Group / DeXpose
2026-09-29
Kothamine Malware Leverages Tailscale Tailcat for Stealthy Network Evasion
Threat Intelligencehigh 4 min

Kothamine Malware Leverages Tailscale Tailcat for Stealthy Network Evasion

Security researchers have identified the Kothamine malware family utilizing Tailscale's 'tailcat' utility to bypass traditional network security controls. This technique allows attackers to maintain persistent, encrypted access while evading detection by standard perimeter defenses.

Malwarebytes
2026-09-29
Global Surge in Mercenary Spyware: Apple Issues New Wave of High-Risk Alerts Across 110 Countries
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware: Apple Issues New Wave of High-Risk Alerts Across 110 Countries

Apple has expanded its threat-notification system, issuing direct Lock Screen alerts to users in 110 countries targeted by sophisticated mercenary spyware. This escalation highlights the persistent threat posed by commercial surveillance vendors against high-profile individuals.

Apple Security Intelligence
2026-09-29
Global Surge in Mercenary Spyware: Apple Enhances Lock Screen Alerts for High-Risk Targets
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware: Apple Enhances Lock Screen Alerts for High-Risk Targets

Apple has escalated its defense against mercenary spyware by implementing direct Lock Screen notifications for targeted users across 110 countries. This move follows a rise in sophisticated, zero-click attacks.

Apple Security Engineering and Architecture
2026-09-29
Escalating Cyber-Physical Threats Target European and US Energy Grids
Critical Infrastructurecritical 4 min

Escalating Cyber-Physical Threats Target European and US Energy Grids

Recent intelligence indicates a surge in coordinated cyber-physical threats against critical power infrastructure. European energy leaders and US agencies report increased vulnerabilities in OT/ICS environments.

CISA / SecurityWeek / E.ON
2026-09-29
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and Gateway
Zero-Day Exploitscritical 4 min

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and Gateway

CISA has added eight new critical vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog. Threat actors are actively using these flaws for remote code execution.

CISA
2026-09-29
China-Linked Jewelbug Group Escalates Espionage and Crypto Fraud Across Middle East and Asia
Cyber Espionagehigh 4 min

China-Linked Jewelbug Group Escalates Espionage and Crypto Fraud Across Middle East and Asia

Security researchers have identified a massive, coordinated campaign by the China-linked threat actor Jewelbug. The group is leveraging a unified control panel to conduct simultaneous cyber espionage and large-scale cryptocurrency fraud across the Middle East and Asia.

CircleID
2026-09-29
Autonomous AI Malware 'Quorum' Emerges: Multi-LLM Orchestration Removes Human Attackers from the Loop
AI Cyber Attackscritical 4 min

Autonomous AI Malware 'Quorum' Emerges: Multi-LLM Orchestration Removes Human Attackers from the Loop

Security researchers have identified a new class of autonomous malware that utilizes a multi-LLM quorum to execute cyber-attacks without human intervention. This shift marks a significant evolution in AI-powered threats, prioritizing deterministic decision-making across diverse model architectures.

Cisco Talos
2026-09-29
Cisco Talos Exposes Autonomous Windows Malware Orchestrated by Multi-LLM Quorum
AI Cyber Attackscritical 4 min

Cisco Talos Exposes Autonomous Windows Malware Orchestrated by Multi-LLM Quorum

Security researchers have identified a new strain of autonomous Windows malware that utilizes a four-model LLM quorum to execute cyber-attacks, effectively removing human operators from the loop.

Cisco Talos
2026-09-29
Chinese-Linked APTs Deploy AI Agents to Automate Multi-Country Cyber-Espionage Campaigns
State Cyber Warfarecritical 4 min

Chinese-Linked APTs Deploy AI Agents to Automate Multi-Country Cyber-Espionage Campaigns

Recent intelligence reveals Chinese-speaking threat actors are integrating commercial AI models into live cyber-espionage operations. These campaigns target government, education, and industrial sectors across Asia.

Hunt.io
2026-09-29
Panzer Ransomware Group Escalates Global Campaign with Double-Extortion Tactics
Threat Intelligencehigh 4 min

Panzer Ransomware Group Escalates Global Campaign with Double-Extortion Tactics

Emerging threat actor Panzer has rapidly expanded its operations in September 2026, targeting international organizations across multiple sectors. The group utilizes custom encryption and a dedicated leak site.

SOCRadar
2026-09-28
Microsoft Links Storm 2570 Affiliate to Multi-Ransomware Campaign
Threat Intelligencehigh 4 min

Microsoft Links Storm 2570 Affiliate to Multi-Ransomware Campaign

Microsoft has identified a prolific ransomware affiliate, Storm 2570, orchestrating attacks using Qilin, DragonForce, Anubis, and BERT ransomware. The group utilizes consistent credential theft and remote access tools.

Microsoft MSTIC
2026-09-28
Microsoft Identifies NeedyMantis: New Modular Malware Targeting High-Value Infrastructure
Threat Intelligencehigh 3 min

Microsoft Identifies NeedyMantis: New Modular Malware Targeting High-Value Infrastructure

Microsoft Threat Intelligence has uncovered NeedyMantis, a sophisticated, modular post-compromise malware family. The threat is currently being deployed in highly targeted operations against critical sectors.

Microsoft MSTIC
2026-09-28
Global Surge in Mercenary Spyware: Apple Alerts Users Across 110 Countries
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware: Apple Alerts Users Across 110 Countries

Apple has issued a massive wave of threat notifications to users in 110 countries, warning of targeted mercenary spyware attacks. These sophisticated, state-linked operations continue to plague high-risk individuals.

Apple Security / Citizen Lab
2026-09-28
European Energy Grid Operators Warn of Escalating Cyber and Physical Sabotage Threats
Critical Infrastructurecritical 4 min

European Energy Grid Operators Warn of Escalating Cyber and Physical Sabotage Threats

Europe's largest energy grid operators report a significant surge in coordinated cyber and physical attacks. Industry leaders are calling for urgent defensive upgrades to protect critical power infrastructure.

Claims Journal
2026-09-28
Critical Citrix NetScaler Zero-Day Exploits Confirmed Under Active Attack
Zero-Day Exploitscritical 4 min

Critical Citrix NetScaler Zero-Day Exploits Confirmed Under Active Attack

CISA has added two critical zero-day vulnerabilities in Citrix NetScaler ADC and Gateway to its Known Exploited Vulnerabilities catalog. Threat actors are actively leveraging these flaws for remote code execution.

CISA / Citrix / watchTowr
2026-09-28
Critical Citrix NetScaler Zero-Day Exploits Confirmed in Active Global Campaigns
Zero-Day Exploitscritical 4 min

Critical Citrix NetScaler Zero-Day Exploits Confirmed in Active Global Campaigns

CISA has added two critical RCE vulnerabilities in Citrix NetScaler ADC and Gateway to its KEV catalog following reports of active exploitation. Organizations are urged to patch immediately.

CISA / Citrix Security Bulletin
2026-09-28
Singapore Overhauls National Cyber Strategy Following Protracted UNC3886 Espionage Campaign
Cyber Espionagecritical 4 min

Singapore Overhauls National Cyber Strategy Following Protracted UNC3886 Espionage Campaign

Singapore has announced a major shift in its national cybersecurity strategy after a sophisticated, long-term espionage campaign by the APT group UNC3886 targeted the nation's critical telecommunications infrastructure.

Digital Watch Observatory
2026-09-28
JADEPUFFER Group Deploys Agentic Ransomware Orchestration in Latest Wave of AI-Powered Attacks
AI Cyber Attackscritical 4 min

JADEPUFFER Group Deploys Agentic Ransomware Orchestration in Latest Wave of AI-Powered Attacks

Security researchers have identified a surge in autonomous, AI-orchestrated malware development by the threat actor JADEPUFFER. This shift marks a transition from manual exploitation to agentic ransomware.

ZeroFox
2026-09-28
AI Agent-Driven Data Theft Campaigns Surge Following Exvicy Framework Proliferation
AI Cyber Attackscritical 4 min

AI Agent-Driven Data Theft Campaigns Surge Following Exvicy Framework Proliferation

Security researchers have identified a sharp rise in multi-stage data theft attacks orchestrated by autonomous AI agents. The trend follows the emergence of the Exvicy framework, which leverages LLMs to automate complex exfiltration chains.

CrowdStrike
2026-09-28
China-Aligned APTs Pivot to AI and Robotics Espionage in South Korea and Gulf States
State Cyber Warfarehigh 4 min

China-Aligned APTs Pivot to AI and Robotics Espionage in South Korea and Gulf States

Recent intelligence confirms a surge in state-sponsored cyber activity targeting AI research and maritime infrastructure. China-linked actors are leveraging advanced persistent threats to secure strategic technological advantages.

ESET
2026-09-28
Cybercriminal Syndicates Pivot to Hijacked AI Infrastructure for Automated Attack Campaigns
AI Cyber Attackscritical 4 min

Cybercriminal Syndicates Pivot to Hijacked AI Infrastructure for Automated Attack Campaigns

Threat actors are increasingly leveraging compromised enterprise AI accounts and cloud-based LLM instances to automate multi-stage cyber-attacks, marking a shift toward autonomous, AI-driven exploitation.

Microsoft MSTIC
2026-09-27
China-Aligned APTs Intensify Strategic Espionage Targeting AI Robotics and Maritime Infrastructure
State Cyber Warfarehigh 4 min

China-Aligned APTs Intensify Strategic Espionage Targeting AI Robotics and Maritime Infrastructure

Recent intelligence confirms China-linked threat actors are aggressively targeting AI robotics in South Korea and maritime monitoring systems in the Gulf. These operations align with Beijing's long-term economic and security objectives.

ESET
2026-09-27
MedusaLocker Ransomware Escalates Activity with Targeted Attack on Bulgarian Organization Abv
Threat Intelligencehigh 3 min

MedusaLocker Ransomware Escalates Activity with Targeted Attack on Bulgarian Organization Abv

The MedusaLocker ransomware group has claimed responsibility for a recent breach of the Bulgarian organization Abv, resulting in the exfiltration of hundreds of sensitive emails.

DeXpose
2026-09-27
Ransomware Surge: Over 1,000 Organizations Compromised in August 2026 Amidst Escalating Gang Conflicts
Threat Intelligencecritical 4 min

Ransomware Surge: Over 1,000 Organizations Compromised in August 2026 Amidst Escalating Gang Conflicts

New intelligence reveals a record-breaking month for ransomware, with 1,073 organizations hit in August 2026. Meanwhile, inter-group warfare between actors like ShinyHunters and Clop is reshaping the landscape.

NCC Group / Infosecurity Magazine
2026-09-27
Global Surge in Mercenary Spyware Alerts: Apple Warns High-Profile Targets Across 110 Countries
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware Alerts: Apple Warns High-Profile Targets Across 110 Countries

Apple has issued a new wave of high-confidence threat notifications to users in 110 countries, warning of targeted mercenary spyware attacks. These alerts highlight the escalating sophistication of state-linked surveillance operations.

Apple Threat Intelligence
2026-09-27
CISA and FBI Issue Urgent Warning on Third-Party ICS Risks to Critical Infrastructure
Critical Infrastructurehigh 4 min

CISA and FBI Issue Urgent Warning on Third-Party ICS Risks to Critical Infrastructure

Federal agencies have issued a joint advisory warning critical infrastructure operators of escalating risks from third-party vendors. The alert emphasizes the need for strict remote access controls.

CISA
2026-09-27
ShinyHunters Resumes Exploitation of Oracle PeopleSoft via WAF Bypass Technique
Zero-Day Exploitscritical 4 min

ShinyHunters Resumes Exploitation of Oracle PeopleSoft via WAF Bypass Technique

The ShinyHunters extortion group is actively bypassing WAF protections to exploit the critical Oracle PeopleSoft CVE-2026-35273 vulnerability. This follows a surge in zero-day activity throughout September 2026.

Bleeping Computer
2026-09-27
ShinyHunters Bypass WAF Protections to Resume Exploitation of Oracle PeopleSoft Zero-Day
Zero-Day Exploitscritical 4 min

ShinyHunters Bypass WAF Protections to Resume Exploitation of Oracle PeopleSoft Zero-Day

The ShinyHunters extortion group is actively exploiting a critical Oracle PeopleSoft vulnerability (CVE-2026-35273) by utilizing URL-encoding techniques to bypass existing WAF mitigations. This development follows a series of high-profile zero-day disclosures throughout September 2026.

Bleeping Computer
2026-09-27
Iranian Espionage Campaign Deploys 'CHOSEN BRICK' Trojan Against Nationals Abroad
Cyber Espionagehigh 4 min

Iranian Espionage Campaign Deploys 'CHOSEN BRICK' Trojan Against Nationals Abroad

A sophisticated Iranian threat actor is targeting nationals living abroad using social engineering on messaging platforms. The campaign delivers a custom trojan, 'CHOSEN BRICK', disguised as legitimate files.

Truesec
2026-09-27
Surge in LLMjacking and Autonomous AI Agents Driving Global Cyber-Attack Wave
AI Cyber Attackscritical 4 min

Surge in LLMjacking and Autonomous AI Agents Driving Global Cyber-Attack Wave

Cybersecurity researchers report a sharp rise in LLMjacking and autonomous AI-agent attacks, where threat actors hijack premium AI models to automate complex, multi-stage data theft and malware deployment.

CrowdStrike
2026-09-27
Global Ransomware Surge: September 2026 Intelligence Update on ShinyHunters and MedusaLocker Activity
Threat Intelligencecritical 4 min

Global Ransomware Surge: September 2026 Intelligence Update on ShinyHunters and MedusaLocker Activity

Recent intelligence confirms a sustained surge in ransomware activity throughout September 2026. Notable incidents include the ShinyHunters breach of Final statement re PSA and MedusaLocker's targeting of Bulgarian entity Abv.

Microsoft MSTIC
2026-09-26
Ransomware Surge Continues: Qilin and ShinyHunters Lead Global Extortion Campaigns
Threat Intelligencecritical 4 min

Ransomware Surge Continues: Qilin and ShinyHunters Lead Global Extortion Campaigns

Global ransomware activity reached record highs in late 2026, with groups like Qilin and ShinyHunters aggressively targeting diverse sectors. Recent incidents include attacks on US and Bulgarian entities.

SOCRadar
2026-09-26
ShinyHunters Escalates Cyber-Conflict: Rival Ransomware Gangs Clop and ShinyHunters Engage in Digital Warfare
Threat Intelligencehigh 4 min

ShinyHunters Escalates Cyber-Conflict: Rival Ransomware Gangs Clop and ShinyHunters Engage in Digital Warfare

In a rare display of inter-gang hostility, the prolific extortion group ShinyHunters has claimed a successful breach of the Clop ransomware infrastructure. This development marks a significant shift in the 2026 threat landscape as criminal syndicates begin targeting one another.

Infosecurity Magazine
2026-09-26
CISA and FBI Issue Urgent Warning on Third-Party ICS Risks Following Surge in Critical Infrastructure Attacks
Critical Infrastructurecritical 4 min

CISA and FBI Issue Urgent Warning on Third-Party ICS Risks Following Surge in Critical Infrastructure Attacks

Federal agencies have issued a new advisory urging critical infrastructure operators to enforce strict least-privilege access and remote control protocols to mitigate rising third-party supply chain risks.

CISA/FBI Joint Advisory
2026-09-26
Critical Zero-Day Vulnerability CVE-2026-93616 Exploited in Check Point Security Management Infrastructure
Zero-Day Exploitscritical 4 min

Critical Zero-Day Vulnerability CVE-2026-93616 Exploited in Check Point Security Management Infrastructure

Check Point has patched a critical zero-day vulnerability, CVE-2026-93616, which allowed unauthenticated attackers to gain administrative access. The flaw is under active exploitation in the wild.

eSecurity Planet
2026-09-26
Chinese-Linked JDY Botnet Escalates Reconnaissance Against U.S. Military Infrastructure
Cyber Espionagecritical 4 min

Chinese-Linked JDY Botnet Escalates Reconnaissance Against U.S. Military Infrastructure

The China-linked JDY botnet has significantly expanded its targeting scope, focusing on U.S. military networks. Intelligence indicates a shift toward aggressive reconnaissance and persistent access.

Bleeping Computer
2026-09-26
Autonomous AI Agents Emerge as Primary Threat Vector in Recent Cyber-Attack Campaigns
AI Cyber Attackscritical 4 min

Autonomous AI Agents Emerge as Primary Threat Vector in Recent Cyber-Attack Campaigns

Recent intelligence confirms a surge in autonomous AI-agent attacks, including the first recorded incident in Spain and the discovery of malware like PhantomRaven, signaling a shift toward AI-driven operations.

CrowdStrike
2026-09-26
Autonomous AI Agent Attacks Surge: Spain Reports First Fully Automated Cyber-Incursion
AI Cyber Attackscritical 4 min

Autonomous AI Agent Attacks Surge: Spain Reports First Fully Automated Cyber-Incursion

Spanish authorities have confirmed the first incident of an autonomous AI agent conducting a multi-stage cyber attack. This marks a shift from AI-assisted tools to fully self-directed offensive operations.

CrowdStrike
2026-09-26
Global Intelligence Alert: Escalating Nation-State Exploitation of Edge Infrastructure in Q3 2026
State Cyber Warfarecritical 4 min

Global Intelligence Alert: Escalating Nation-State Exploitation of Edge Infrastructure in Q3 2026

Recent intelligence indicates a surge in state-sponsored actors leveraging zero-day vulnerabilities in edge networking hardware. These campaigns prioritize long-term persistence within critical infrastructure.

Microsoft MSTIC
2026-09-26
Storm-2570 Ransomware Operations Surge as Global Attacks Hit Record Highs
Threat Intelligencecritical 4 min

Storm-2570 Ransomware Operations Surge as Global Attacks Hit Record Highs

Microsoft Threat Intelligence reports a significant uptick in Storm-2570 activity, highlighting the evolving tradecraft of RaaS affiliates. This comes as global ransomware incidents reach record levels in late 2026.

Microsoft MSTIC
2026-09-25
ShinyHunters Escalates Cyber-Conflict by Breaching Rival Clop Ransomware Infrastructure
Threat Intelligencehigh 4 min

ShinyHunters Escalates Cyber-Conflict by Breaching Rival Clop Ransomware Infrastructure

In a rare display of inter-group hostility, the prolific extortion group ShinyHunters has successfully breached the infrastructure of the Clop ransomware gang. This development marks a significant shift in the 2026 threat landscape as cybercriminal syndicates increasingly target one another.

Infosecurity Magazine
2026-09-25
ShinyHunters Claims Breach of Rival Ransomware Gang Clop Amidst Record-High 2026 Attacks
Threat Intelligencecritical 4 min

ShinyHunters Claims Breach of Rival Ransomware Gang Clop Amidst Record-High 2026 Attacks

The prolific cyber extortion group ShinyHunters has reportedly compromised the infrastructure of the rival Clop ransomware gang. This development occurs as 2026 ransomware activity hits record highs.

Infosecurity Magazine
2026-09-25
Escalating Pegasus Deployments: New Zero-Click Campaigns Target Civil Society in Serbia
Offensive Toolscritical 4 min

Escalating Pegasus Deployments: New Zero-Click Campaigns Target Civil Society in Serbia

Recent investigations confirm the use of NSO Group's Pegasus spyware against Serbian student activists via iMessage zero-click exploits. This marks a significant escalation in the use of mercenary surveillance tools within the region.

Citizen Lab
2026-09-25
Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts to Targets Across 110 Countries
Offensive Toolscritical 4 min

Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts to Targets Across 110 Countries

Apple has intensified its security efforts, issuing urgent notifications to users in 110 countries regarding potential mercenary spyware infections. These sophisticated, state-sponsored-grade attacks continue to target high-profile individuals, including journalists and diplomats.

Apple Threat Intelligence
2026-09-25
CISA Issues Urgent Warning as Iranian-Linked Actors Target Industrial PLCs in Water Sector
Critical Infrastructurecritical 4 min

CISA Issues Urgent Warning as Iranian-Linked Actors Target Industrial PLCs in Water Sector

CISA has issued an urgent alert regarding a surge in cyber attacks targeting Programmable Logic Controllers (PLCs) within water and wastewater systems. Threat actors are actively locking out operators and disrupting critical water services across multiple states.

CISA
2026-09-25
CISA Adds Three Linux Kernel Flaws to KEV Catalog Amid Active Exploitation Concerns
Zero-Day Exploitscritical 4 min

CISA Adds Three Linux Kernel Flaws to KEV Catalog Amid Active Exploitation Concerns

The Cybersecurity and Infrastructure Security Agency (CISA) has officially added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These flaws are currently being targeted in the wild, prompting urgent patching requirements for enterprise systems.

CISA
2026-09-25
CISA Adds Three Linux Kernel Vulnerabilities to KEV Catalog Amid Active Exploitation Reports
Zero-Day Exploitshigh 4 min

CISA Adds Three Linux Kernel Vulnerabilities to KEV Catalog Amid Active Exploitation Reports

CISA has officially added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Security teams are urged to prioritize patching to mitigate active in-the-wild threats.

CISA
2026-09-25
Chinese APT 'Fire Ant' Escalates Global Espionage via Cisco Router Hijacking
Cyber Espionagecritical 4 min

Chinese APT 'Fire Ant' Escalates Global Espionage via Cisco Router Hijacking

The China-nexus actor Fire Ant has expanded its operations, utilizing compromised Cisco routers to exfiltrate credentials and manipulate security logs. This campaign highlights a shift toward leveraging trusted network infrastructure to maintain long-term persistence in high-value targets.

The Hacker News
2026-09-25
ClosedQuorum Malware Deploys Multi-LLM Voting System for Autonomous Cyber Attacks
AI Cyber Attackscritical 4 min

ClosedQuorum Malware Deploys Multi-LLM Voting System for Autonomous Cyber Attacks

A new Go-based malware, ClosedQuorum, has emerged, utilizing a sophisticated voting mechanism across four major LLMs to autonomously execute post-compromise attack stages without human intervention.

Cisco Talos
2026-09-25
ClosedQuorum Malware Leverages Multi-LLM Voting System for Autonomous Cyber Attacks
AI Cyber Attackscritical 3 min

ClosedQuorum Malware Leverages Multi-LLM Voting System for Autonomous Cyber Attacks

A new Go-based malware strain, ClosedQuorum, has emerged, utilizing a sophisticated voting mechanism across four major AI models to autonomously execute post-compromise attack decisions.

Cisco Talos
2026-09-25
China-Linked APT Group QTFY Escalates Targeting of Global Military and Critical Infrastructure
State Cyber Warfarecritical 4 min

China-Linked APT Group QTFY Escalates Targeting of Global Military and Critical Infrastructure

Recent intelligence confirms that the China-linked threat actor QTFY has intensified its campaign against military and critical infrastructure sectors. The group is utilizing advanced persistent threat tactics to compromise sensitive networks globally.

Microsoft MSTIC
2026-09-25
Ransomware Surge: Record 1,073 Victims in August 2026 as ShinyHunters Targets Rival Clop Gang
Threat Intelligencecritical 4 min

Ransomware Surge: Record 1,073 Victims in August 2026 as ShinyHunters Targets Rival Clop Gang

Ransomware activity hit a record high in August 2026 with over 1,000 victims reported. Simultaneously, the threat landscape is shifting as major groups like ShinyHunters engage in inter-gang cyber warfare.

Infosecurity Magazine
2026-09-24
Secp0 and Qilin Ransomware Groups Escalate Global Attacks on Real Estate and Electronics Sectors
Threat Intelligencecritical 4 min

Secp0 and Qilin Ransomware Groups Escalate Global Attacks on Real Estate and Electronics Sectors

Recent intelligence confirms a surge in ransomware activity as groups Secp0 and Qilin target major firms in the US and Japan. These attacks highlight the persistent threat of double extortion tactics.

DeXpose
2026-09-24
RatHat Android Malware Leverages AI for Automated Device Control and Banking Fraud
Threat Intelligencehigh 4 min

RatHat Android Malware Leverages AI for Automated Device Control and Banking Fraud

A sophisticated new Android malware, RatHat, has emerged, utilizing AI-powered subsystems to automate device navigation and bypass security controls for banking theft.

Zimperium zLabs
2026-09-24
Escalating Cyber-Physical Threats: Water Sector Resilience Under Pressure in Q3 2026
Critical Infrastructurecritical 4 min

Escalating Cyber-Physical Threats: Water Sector Resilience Under Pressure in Q3 2026

Recent intelligence confirms a sustained campaign targeting US water infrastructure, highlighting critical vulnerabilities in OT/ICS environments. Agencies are pivoting to new defense frameworks.

CISA / Viakoo / McDonald Hopkins
2026-09-24
Check Point Management Server Zero-Day Exploited by Ransomware Gangs
Zero-Day Exploitscritical 4 min

Check Point Management Server Zero-Day Exploited by Ransomware Gangs

Check Point has issued an urgent warning regarding a zero-day vulnerability in its Quantum Security Gateways being actively exploited by ransomware actors. The flaw allows unauthorized access to admin panels.

BleepingComputer
2026-09-24
Google Patches Actively Exploited Android Zero-Day CVE-2026-58704 Affecting Pixel Devices
Zero-Day Exploitshigh 4 min

Google Patches Actively Exploited Android Zero-Day CVE-2026-58704 Affecting Pixel Devices

Google has issued an urgent security update for Pixel devices to address CVE-2026-58704, a high-severity zero-day vulnerability in the modem subcomponent currently under limited, targeted exploitation.

Google Security Advisory
2026-09-24
New Iranian Cyber Espionage Campaign Targets Global Dissidents and Journalists
Cyber Espionagehigh 3 min

New Iranian Cyber Espionage Campaign Targets Global Dissidents and Journalists

A newly identified Iranian cyber espionage campaign is actively targeting dissidents, activists, and journalists worldwide. The operation utilizes sophisticated social engineering and custom malware.

Truesec
2026-09-24
New 'ClosedQuorum' Malware Uses Four-LLM Hive Mind for Autonomous Cyber Attacks
AI Cyber Attackscritical 4 min

New 'ClosedQuorum' Malware Uses Four-LLM Hive Mind for Autonomous Cyber Attacks

Cisco Talos has identified 'ClosedQuorum,' a novel Windows malware that utilizes a voting system between four different LLMs to autonomously execute post-compromise attack stages without human intervention.

Cisco Talos
2026-09-24
New 'ClosedQuorum' Malware Uses Autonomous AI Voting to Execute Cyber Attacks
AI Cyber Attackscritical 4 min

New 'ClosedQuorum' Malware Uses Autonomous AI Voting to Execute Cyber Attacks

A novel Windows malware strain, ClosedQuorum, has emerged, utilizing a multi-model AI voting system to autonomously determine post-compromise attack vectors without human intervention.

Cisco Talos
2026-09-24
Chinese-Linked APTs Deploy AI Agents in Multi-Country Cyberespionage Campaign
State Cyber Warfarecritical 4 min

Chinese-Linked APTs Deploy AI Agents in Multi-Country Cyberespionage Campaign

Recent intelligence reveals Chinese-speaking threat actors are utilizing autonomous AI agents to automate cyberattacks against government and industrial targets across Asia. This shift marks a significant escalation in the use of generative AI for large-scale, persistent espionage operations.

Security Affairs
2026-09-24
LockBit 5.0 and Termite Ransomware Surge: New Attacks Hit Financial and Mortgage Sectors
Threat Intelligencecritical 4 min

LockBit 5.0 and Termite Ransomware Surge: New Attacks Hit Financial and Mortgage Sectors

Recent intelligence confirms a spike in double-extortion activity as LockBit 5.0 targets Ethiopian banking infrastructure and the Termite group compromises a major U.S. mortgage firm.

CrowdStrike
2026-09-23
Gunra and Medusa Ransomware Groups Intensify Double-Extortion Campaigns Against Critical Infrastructure
Threat Intelligencecritical 4 min

Gunra and Medusa Ransomware Groups Intensify Double-Extortion Campaigns Against Critical Infrastructure

Recent intelligence updates from federal agencies highlight a surge in double-extortion attacks by Gunra and Medusa ransomware groups. These RaaS operations are actively targeting healthcare and manufacturing.

AHA News / FBI / CISA
2026-09-23
RatHat Android Malware Leverages AI-Driven Automation for Remote Device Control
Threat Intelligencehigh 4 min

RatHat Android Malware Leverages AI-Driven Automation for Remote Device Control

A sophisticated new Android malware family, RatHat, has emerged, utilizing an AI-powered subsystem to automate remote device navigation. Researchers have linked the campaign to Chinese-speaking threat actors.

Zimperium zLabs
2026-09-23
Global Energy Utilities Report Surge in Targeted Cyber Reconnaissance Against OT Infrastructure
Critical Infrastructurehigh 4 min

Global Energy Utilities Report Surge in Targeted Cyber Reconnaissance Against OT Infrastructure

Recent intelligence indicates a sharp increase in sophisticated reconnaissance operations targeting Operational Technology (OT) environments within European and North American energy sectors. Utilities are reporting heightened scanning activity and unauthorized access attempts on critical grid-connected assets.

CISA / NCSC / Viakoo
2026-09-23