Interlock ransomware gang exploits Cisco firewall zero-day in targeted attacks
Interlock had been abusing the flaw as a zero-day issue in real-world attacks as early as January 26.
Interlock had been abusing the flaw as a zero-day issue in real-world attacks as early as January 26.
Attackers gained initial access by compromising GitHub accounts and force-pushing malicious commits into existing projects.
The group is now using AI-assisted malware that includes anti-analysis features, helping it stay hidden in compromised systems for longer periods.
Russia systematically employs diplomatic missions for intelligence collection, cyber operations, and influence campaigns.
Attackers are now incorporating Bench.sh as a lightweight reconnaissance utility after gaining initial access.
Three companies and two individuals are accused of carrying out cyberattacks targeting EU member states and international partners.
Attackers distributed malicious files through South Korea’s popular KakaoTalk messaging platform.
The activity shares similarities with a previous operation conducted by the threat group Laundry Bear aka UAC-0190.
The campaign, tracked as CL-STA-1087, focuses on carefully targeted intelligence gathering rather than large-scale data theft.
The operation, codenamed ‘Operation Synergia III,’ ran from July 2025 to January 2026 and involved authorities from 72 countries.
Showing elements 261 - 270