Active APT Campaigns and State-Sponsored Cyber Operations
Multiple APT groups remain highly active: UAT-10147 uses AI tools for post-compromise automation on 170,000 servers; Lazarus exploits Dream Job and TwinLoot; Handala claims intrusion into Stryker; MuddyWater uses Teams phishing; Chinese state hackers leverage DeepSeek AI for autonomous attacks. Botnet industrialization report identifies three archetypes with state-sponsored capabilities. UK power facility disabled for 4 days after suspected Iran-nexus attack. New: Coordinated attacks on US water systems across 12 states, exploiting vulnerable PLCs (Rockwell, Schneider, Siemens), suspected Iran-nexus (CyberAv3ngers, APT Iran). Chinese-speaking hackers (UAT-10147) accelerating attacks with AI.