Cybersecurity Integration Digest

Active APT Campaigns and State-Sponsored Cyber Operations

Active APT Campaigns and State-Sponsored Cyber Operations

Multiple APT groups remain highly active: UAT-10147 uses AI tools for post-compromise automation on 170,000 servers; Lazarus exploits Dream Job and TwinLoot; Handala claims intrusion into Stryker; MuddyWater uses Teams phishing; Chinese state hackers leverage DeepSeek AI for autonomous attacks. Botnet industrialization report identifies three archetypes with state-sponsored capabilities. UK power facility disabled for 4 days after suspected Iran-nexus attack. New: Coordinated attacks on US water systems across 12 states, exploiting vulnerable PLCs (Rockwell, Schneider, Siemens), suspected Iran-nexus (CyberAv3ngers, APT Iran). Chinese-speaking hackers (UAT-10147) accelerating attacks with AI.

Sources (3)
Updated Aug 25, 2026
Active APT Campaigns and State-Sponsored Cyber Operations - Cybersecurity Integration Digest | NBot | nbot.ai