Digital Privacy Watch

Nation-state cyber threats: Russia, China, NK, Iran — supply chain attacks, AI weaponization, and espionage; AI agent hijacking, BitLocker zero-days, CISA alerts; AI-generated browser ransomware; FortiBleed pipeline; first autonomous AI ransomware agent; BlueNoroff deepfake; Iranian timeline; Russian hotel WiFi hacks; Hungary farm subsidy attack; Salt Typhoon telecom infrastructure; ExfilSquad; CISA water system PLC exposure; Gunra ransomware surges to 50+ victims; Trump memo authorizes private offensive cyber ops; China-nexus group exploiting vCenter flaw; DOJ targets Russian bulletproof hosting; NK IT worker alert; NSA/FBI advisory on AI-generated scripts targeting Siemens PLCs in healthcare

Nation-state cyber threats: Russia, China, NK, Iran — supply chain attacks, AI weaponization, and espionage; AI agent hijacking, BitLocker zero-days, CISA alerts; AI-generated browser ransomware; FortiBleed pipeline; first autonomous AI ransomware agent; BlueNoroff deepfake; Iranian timeline; Russian hotel WiFi hacks; Hungary farm subsidy attack; Salt Typhoon telecom infrastructure; ExfilSquad; CISA water system PLC exposure; Gunra ransomware surges to 50+ victims; Trump memo authorizes private offensive cyber ops; China-nexus group exploiting vCenter flaw; DOJ targets Russian bulletproof hosting; NK IT worker alert; NSA/FBI advisory on AI-generated scripts targeting Siemens PLCs in healthcare

Key Questions

What scale of US voter data has China collected?

PRC-linked entities collected 204 million US voter records over a decade through metadata forensics, supporting influence operations and person-matching efforts. President Trump referenced similar figures of 220 million records since 2020.

What nation-state threats involve AI?

AI agent hijacking, autonomous ransomware like JADEPUFFER, and AI-generated browser ransomware via tools such as DeepSeek have been reported. NSA has embedded with Anthropic for offensive operations.

Which countries are conducting supply chain and espionage campaigns?

Russia, China, North Korea, and Iran-linked groups have conducted supply chain attacks, zero-day exploits, and espionage including Chinese APT targeting Microsoft 365 and Iranian disruption of California water facilities.

Widespread threats: cPanel/PAN-OS zero-days, GitHub Megalodon, AI agent autonomous breach, OpenAI Codex supply chain, NSA embeds Anthropic for offensive Mythos ops, AI worm PoC, Red Hat npm backdoor, Miasma worm, Cisco SD-WAN zero-day, Chinese APT targeting M365, Android spyware, 87% of AI agents hacked. Iran Handala/MuddyWater: Stryker 50TB wipes, Lockheed $600M, LA transit breach, Holocaust center attack, MuddyWater expands to 9 countries. Five Eyes warns of fake job ads. IBM whistleblower lawsuit confirms 56,000 Chinese state-sponsored breaches covered up (APT10). Chrome zero-day. Handala claims FBI drone hack (unverified). Iran-linked hackers disrupt California water facility. 400 Arch Linux packages compromised. AI coding agent hijacking (agentjacking). BitLocker zero-days. CISA alerts. AI-generated browser ransomware via DeepSeek. FortiBleed pipeline. JADEPUFFER autonomous AI ransomware. Authenticator app phishing campaign. 220 million US voter records collected by PRC-linked entities over a decade — declassified by Trump, metadata forensics reveal scale and purpose for influence ops and person-matching. BlueNoroff (North Korea) using deepfake Zoom to steal crypto. Iranian cyberattack timeline reinforces persistent risk to US critical infrastructure (water systems, banks, etc.). Russian state hackers compromise hotel WiFi globally — DNS manipulation and OAuth token abuse to bypass MFA, targeting travelers. Russia-linked ransomware encrypts Hungary's EU farm subsidy payment agency — expands critical infrastructure targeting in Europe. House committee report reveals US telecom data center links to Chinese state-owned carriers enabled Salt Typhoon breaches — FCC drafting ban on Chinese data center components. Minnesota water utilities hit by coordinated attack, likely Iranian. ExfilSquad emerges as new threat actor, claims UK DfE and PNLD breaches. CISA director confirms water system PLCs still exposed online amid multistate hacks, no attribution yet. Gunra ransomware gang (North Korea ties, Conti code, double extortion, US/SK warning) — now surged to 50+ victims across healthcare, finance, critical infrastructure; joint FBI/CISA advisory. New: Trump memo authorizes private US firms for offensive cyber ops against foreign criminals — blurs state/corporate lines, risks escalation and blowback. New: China-nexus group exploiting vCenter flaw for Babuk ransomware (361 IPs, 47 countries, reverse SSH persistence). New: DOJ targets Russian bulletproof hosting; NK IT worker alert. New: NSA/FBI advisory on AI-generated scripts targeting Siemens PLCs in healthcare — active threats to critical infrastructure.

Sources (2)
Updated Aug 22, 2026