Active APT Campaigns, Supply-Chain Intrusions, Phishing Operations, and Cloud-Hosted C2
Flax Typhoon is reportedly exploiting five newly cataloged KEVs against critical infrastructure and OT, using scanning, password spraying, persistence, and exfiltration before the October 11 federal deadline. Shiny Hunters-related reporting and the alleged FBI contractor compromise reinforce third-party exposure and credential-theft risks, but attribution and technical breach evidence require corroboration.
Sources (13)
Updated Oct 10, 2026