Iran-linked wipers/APTs/OT and Russian router hijacking
Key Questions
What new Iranian-linked wiper activity was reported?
Handala conducted Intune, Entra, PLC, and ABB wipes targeting OT environments alongside Lazarus and APT28 operations.
Which Chinese APTs are highlighted in the summary?
Brickstorm targets IIS with custom webshells while another APT uses AI-written IceCube stealer against university physics departments via Roundcube chains.
What does the I-Soon leak reveal about Chinese espionage?
Leaks show a vanity-driven culture and guanxi-based patronage within groups like Salt Typhoon, exposing operational vulnerabilities alongside Volt Typhoon pre-positioning.
Handala Intune/Entra/PLC/ABB wipes; NK Lazarus; APT28 NTLM; Iran cyber espionage (Kim Wolf botnet, Ghost CMS); FrostyNeighbor targeting Ukraine. Chinese APT Brickstorm targeting IIS with custom webshells. Chinese APT targeting US/Canadian university physics departments via Roundcube XSS/deserialization chain, using AI-written IceCube stealer. Comprehensive state cyber threat assessment details Chinese APTs Salt Typhoon (telecom compromises) and Volt Typhoon (critical infrastructure pre-positioning). New: Joint CISA/FBI/NSA advisory on Russian state-sponsored router hijacking targeting critical infrastructure globally. New: Inside China's cyber espionage business — I-Soon leaks reveal vanity-driven culture and guanxi-based patronage as vulnerabilities; Salt Typhoon as collection of groups; AI time-compression effect. Pri: airgaps/MDM/OT inventory.