DEV Community

Mark0
Mark0

Posted on

5th October – Threat Intelligence Report

This week's cyber research highlights significant breaches in the public and private sectors, including a phishing-led attack on Arizona's state court system and a massive data breach affecting 6.6 million accounts at Japan's Times Car service. Additionally, South Africa’s air navigation provider faced a ransomware attack impacting operational technology, while the Polish invoicing platform Fakturownia disclosed a vulnerability-driven data leak.

The threat landscape is increasingly shaped by AI-driven activities and critical zero-day vulnerabilities. Researchers identified autonomous AI agents attempting SQL injections against government sites and malicious Custom GPTs delivering remote access malware. Meanwhile, critical patches were issued for vulnerabilities in Citrix NetScaler, Cisco Catalyst SD-WAN, and Apple’s CoreGraphics, some of which are already seeing active exploitation in the wild.

State-sponsored espionage remains a persistent threat, with China-nexus groups targeting US AI policy experts and Asian government organizations using sophisticated backdoors like Antino. Simultaneously, Russia-linked actor Star Blizzard has expanded its phishing operations across the US and UK, utilizing new delivery techniques to deploy the CosmicPulse backdoor for long-term intelligence gathering.


Read Full Article

Top comments (0)