Approaching cyclone: Vortex Werewolf attacks Russia

In December 2025 and January 2026, BI.ZONE Threat Intelligence detected malicious activity by a new cluster Vortex Werewolf (SkyCloak). The attacks targeted Russian government and defense organizations. BI.ZONE researchers findings indicate that the adversary used phishing emails to deliver malware Read More …

China’s Salt Typhoon hackers broke into Norwegian companies

The Norwegian government has accused the Chinese-backed hacking group known as Salt Typhoon of breaking into several organizations in the country. In a report published on Friday, the Norwegian Police Security Service said the hacking group, believed to be working Read More …

Novel Technique to Detect Cloud Threat Actor Operations

Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. The difficulty doesn’t lie in an inability to identify complex alerting operations across thousands of cloud resources or in a failure Read More …

Dynowiper: Destructive Malware Targeting Poland’s Energy Sector

The coordinated destructive campaign against critical energy infrastructure occurred on December 29, 2025, during a period of severe winter weather in Poland. According to CERT Polska’s report, the campaign targeted: 30+ wind and solar farms across Poland; A major CHP Read More …

Pakistan, China to boost liaison in intelligence sharing, cybercrime prevention

Pakistan and China on Thursday agreed to enhance cooperation in intelligence sharing and cybercrime prevention. The understanding was reached during a meeting between Federal Interior Minister Mohsin Naqvi and Chinese Ambassador in Pakistan Jiang Zaidong. Upon his arrival at the Read More …

Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT

Stan Ghouls (also known as Bloody Wolf) is an cybercriminal group that has been launching targeted attacks against organizations in Russia, Kyrgyzstan, Kazakhstan, and Uzbekistan since at least 2023. These attackers primarily have their sights set on the manufacturing, finance, Read More …

Substack confirms data breach affects users’ email addresses and phone numbers

Newsletter platform Substack has confirmed a data breach in an email to users. The company said that in October, an “unauthorized third party” accessed user data, including email addresses, phone numbers, and other unspecified “internal metadata.” Substack specified that more Read More …

Data breach at govtech giant Conduent balloons, affecting millions more Americans

A data breach at government technology giant Conduent appears to affect far more people than first disclosed, with the number of victims potentially stretching to dozens of millions of people across the United States. The January 2025 ransomware attack, which Read More …