CyberCynical
cybercynical.bsky.social
CyberCynical
@cybercynical.bsky.social
Always cynical / Always sceptical #cybercrime #cyberattacks #techsavvy #techcynic #hacking #IoT #privacyandsecurity #socialcommentator #socialmedia #infosec
泄露文件显示,中国公司ZRON利用AI系统将从外国政府窃取的机密信息解读并整理成更易理解的内容,然后出售给警方。
www.wsj.com/tech/how-a-c...
How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying
Internal company materials illustrate an AI-powered effort to make pilfered foreign government documents digestible for police; targets include Russia, Pakistan.
www.wsj.com
September 22, 2026 at 7:39 AM
美国方面称,多家中国 AI 公司正大规模“蒸馏”美国前沿模型,通过 API、代理和聚合平台等方式批量提取模型输出,试图快速复制推理、编程和 Agent 等能力。美国情报机构警告,这可能加速先进 AI 能力扩散,带来安全风险。
#AI #人工智能 #AI安全 #网络安全
thehackernews.com/2026/09/us-a...
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. agencies accuse six China-based AI firms of industrial-scale distillation to extract proprietary capabilities from frontier AI models.
thehackernews.com
September 10, 2026 at 12:02 PM
VMware vCenter CVE-2026-59310 遭全球利用

QUIRSO 发现该漏洞在披露后 5 天便出现利用活动,发现 47 个国家/地区的 361 个受害 IP 地址。

攻击者利用漏洞获取 vCenter 代码执行能力,并建立持久化、获取凭据、进行 vSphere 探测及部署 Reverse SSH,最终入侵 ESXi 主机并部署 Babuk 衍生勒索软件。

QUIRSO 以中等置信度评估该活动与疑似具有中国关联(Chinese-nexus)的威胁行为者有关,但尚无足够证据将其归因于 APT 组织或中国政府。

medium.com/@quirso_de/g...
Global Exploitation of CVE-2026–59310 by Suspected Chinese-Nexus APT & Related CVE-2026–59309…
QUIRSO’s Incident Response team recently investigated a VMware vCenter compromise that uncovered a coordinated, global exploitation…
medium.com
August 18, 2026 at 12:09 PM
Reposted by CyberCynical
300K WordPress sites at risk from CVE-2026-15748 — a critical file upload flaw letting unauthenticated attackers run malicious code. Patch your form plugins now. ⚠️ #cybersecurity #infosec #CVE #WordPress Read more -> cyberthreats247.com
August 18, 2026 at 11:30 AM
Reposted by CyberCynical
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
Researchers linked the latest malicious activity to a Chinese company, after one of the spyware's operators placed an order with KFC using their real name and office address.
techcrunch.com
August 6, 2026 at 7:25 PM
中国关联的黑客组织Storm-1175部署了名为StormEncryptor的新型勒索软件,可能利用CVE-2026-18577获取初始访问权限。

thehackernews.com/2026/08/chin...
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft says Storm-1175 is deploying new StormEncryptor ransomware, likely after exploiting N-able N-central CVE-2026-18577 for access.
thehackernews.com
August 12, 2026 at 10:57 AM
中国关联的TA4922将钓鱼攻击扩展至英国、德国、意大利和南非。#网络安全 #钓鱼攻击 #威胁情报 #网络防御
June 25, 2026 at 11:55 AM
Reposted by CyberCynical
AI’s cyber revolution is coming. China may not be far behind.
AI’s cyber revolution is coming. China may not be far behind.
The U.S. has at most six to 12 months before Beijing can compete with this new wave of hyper-advanced AI models.
dlvr.it
June 7, 2026 at 11:04 AM
Reposted by CyberCynical
Prominent cybersecurity leaders have warned that sidelining Mythos 5 and Fable 5 could give China a significant AI advantage.

A public letter from tech and cybersecurity executives called for restrictions on Fable 5 to be repealed on Sunday.
www.theverge.com/ai-artificia...
June 16, 2026 at 2:45 PM
ShadowPad -- 值得关注的网络安全威胁。

ShadowPad 是一种高度复杂的模块化恶意软件,已成为网络安全领域的重要威胁。 该恶意软件最初被归因于与中国有关联的国家支持型威胁组织 APT41,但此后已逐渐演变为多个高级持续性威胁(APT)组织共享使用的攻击工具。
#网络安全 #网络威胁 #威胁情报 #恶意软件 #APT

cyberint.com/blog/dark-we...
The Growing Threat of ShadowPad Malware and Its Business Impact
Introduction to ShadowPad Malware ShadowPad, a sophisticated modular malware, has emerged as a significant cybersecurity threat. Attributed initially to Chinese state-sponsored threat actors (APT41), ...
cyberint.com
June 25, 2026 at 11:40 AM
一项代号为“Dragon Weave"的新网络间谍活动被发现针对捷克共和国和台湾的官员和公民。 #中国 #间谍 #网络安全

thehackernews.com/2026/06/chin...
China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan
Operation Dragon Weave delivers AdaptixC2 via phishing; Azure-based AZUREVEIL enables covert control, impacting Czech and Taiwan targets.
thehackernews.com
June 3, 2026 at 12:48 PM
据研究人员,与中国有关的黑客发起网络钓鱼攻击,盯上记者和维权人士
##网络安全 #网络钓鱼 #黑客攻击 #记者安全 #维权人士
May 19, 2026 at 1:34 PM
Reposted by CyberCynical
@talosintelligence.com
Talos uncovered a BadIIS variant operating as a MaaS ecosystem for Chinese-speaking threat actors, enabling SEO fraud and traffic hijacking.
-
IOCs: BadIIS, demo. pdb, lwxatisme
-
#BadIIS #Malware #ThreatIntel
Tracking the BadIIS MaaS Ecosystem
blog.talosintelligence.com
May 19, 2026 at 12:50 PM
近日,网络安全研究员发现一个与中国有关联的网络间谍组织已渗透波兰及亚洲多地的关联网络。该新发现的组织攻击政府机构、国防承包商、科技公司及运输业。研究显示,该组织在部署ShadowPad恶意软件前,已在受害组织内部潜伏长达8个月之久。
www.theregister.com/2026/04/30/c...
Chinese spy group caught lurking in Poland, Asia networks
Exclusive: Just in time for the Trump-Xi summit
www.theregister.com
April 30, 2026 at 1:10 PM
中国关联APTGopherWhisper入侵蒙古政府12系统,利用Go/C++后门通过Slack/Discord/Outlook/file.io窃数据.

#网络安全 #APT攻击 #信息安全 #数据泄露

thehackernews.com/2026/04/chin...
China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
GopherWhisper infected 12 Mongolian government systems in January 2025, abusing Slack and Discord for C2, exposing wider espionage risks.
thehackernews.com
April 23, 2026 at 11:31 AM
与中国相关的黑客组织Storm-1175利用0day漏洞72小时内部署Medusa勒索软件。近期发生的网络入侵事件对澳大利亚、英国和美国的医疗机构以及教育、专业服务和金融行业的机构造成了严重影响。
thehackernews.com/2026/04/chin...
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
Storm-1175 exploits 16+ CVEs since 2023, including zero-days, enabling rapid Medusa ransomware attacks within 24 hours.
thehackernews.com
April 10, 2026 at 7:59 AM
Reposted by CyberCynical
A reported cyberattack on Crunchyroll on March 12, 2026, exposed nearly 100GB of user data via a third-party vendor, including emails, IPs, passwords, and some credit card info. #DataBreach #ThirdPartyRisk #USA
Alleged Cyberattack on Crunchyroll Exposes Risks in Outsourced Systems
Reports allege a March 12, 2026 data breach at Crunchyroll that exposed nearly 100GB of user data—including email addresses, IPs, passwords, and some credit card information—after an attacker gained access via a third‑party vendor. Crunchyroll has not confirmed the full scope, but the incident underscores risks from outsourced ticketing and support...
www.hendryadrian.com
March 24, 2026 at 12:00 PM
Check Point 最新研究显示,在美以对伊朗发动打击后不久,与中国有关的网络威胁行为者开始将部分攻击目标转向卡塔尔。

相关活动利用与地区冲突相关的诱饵内容,试图投递 PlugX 和 Cobalt Strike 等工具,显示出网络间谍行为者在地缘政治事件发生时能够迅速调整其行动重点。
#网络安全 #网络间谍活动 #地缘政治风险 #威胁情报
March 12, 2026 at 9:49 AM
600多台 Fortinet FortiGate 设备在全球被攻破。一次利用 AI 的攻击行动所使用的黑客平台由一名中国开发者打造,并与包括 Knownsec 在内的中国网络安全公司存在关联。
#网络安全 #AI网络攻击 #网络威胁 #Fortinet

thehackernews.com/2026/03/open...
Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries
AI-powered CyberStrikeAI linked to 600 FortiGate breaches in 55 countries, with 21 IPs tied to China-based infrastructure.
thehackernews.com
March 5, 2026 at 9:08 AM
Reposted by CyberCynical
Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks
Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks
The cybersecurity community recently witnessed the emergence of targeted malware campaigns linked to the Silver Fox threat group. This operation focuses heavily on Asia, targeting local organizations with carefully localized lures. By disguising attacks as routine business communications, actors successfully distributed the Winos 4.0 malware, known as ValleyRat, into corporate networks. To compromise victim systems, attackers leverage deceptive phishing emails containing malicious attachments or embedded links. These messages closely impersonate official government correspondence, such as tax audit notifications, software installers, and electronic invoice downloads. Tax-themed phishing (Source – Fortinet) When a user interacts with these files, they trigger a complex infection chain that operates quietly, minimizing the chances of immediate user suspicion. The final impact of a successful infection is severe, leading to widespread file encryption and extensive data theft that can fuel further cyberattacks. Attacker’s domain (Source – Fortinet) Fortinet researchers identified the malware and its infrastructure as highly volatile, utilizing a rotating network of cloud domains to host their payloads. This rapid shifting of resources makes traditional static domain blocking mostly ineffective as a primary defense measure against the ongoing Winos 4.0 operations. Advanced Detection Evasion Techniques Once inside a network, the Silver Fox group employs advanced detection evasion strategies to maintain access and control. The attackers deliver an archive containing a legitimate application that secretly sideloads a malicious dynamic link library into memory. The execution file and the malicious DLL file (Source – Fortinet) This stage sets the foundation for a “Bring Your Own Vulnerable Driver” attack. The malware loads a validity-signed Windows kernel-mode driver, named wsftprm.sys, to silently acquire elevated system privileges without alerting administrators. Archive contents with LNK and social-engineering decoys (Source – Fortinet) After securing kernel-level access, the malicious driver enters a continuous monitoring loop to identify and terminate active security processes. By targeting a vast array of popular antivirus and endpoint protection tools , the malware creates a completely blind environment. This allows Winos 4.0 to operate, escalate its privileges, and maintain remote communication with its command server unimpeded. To effectively defend against these highly sophisticated techniques, organizations must treat all unexpected documents and external links with extreme caution. Security teams should implement behavioral monitoring tools, continuously update endpoint protection signatures, and deploy strong email filtering solutions to proactively detect evasive phishing attempts before they occur. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks appeared first on Cyber Security News .
cybersecuritynews.com
February 23, 2026 at 8:02 AM
Reposted by CyberCynical
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft

Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that's being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillanc…
#hackernews #news
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft
Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that's being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillance on Android and iOS devices. "The developer runs dedicated channels for sales, customer support, and regular updates, giving buyers a single point of access to a fully operational spyware
thehackernews.com
February 17, 2026 at 5:24 AM
遭制裁的中国政府背景黑客组织,被曝利用谷歌AI聊天机器人Gemini自动分析漏洞,并策划针对美国机构的网络攻击。
#网络安全威胁 #AI安全 #网络攻防

www.theregister.com/2026/02/12/g...
Google: China's APT31 used Gemini to plan US cyberattacks
: Meanwhile, IP-stealing 'distillation attacks' on the rise
www.theregister.com
February 12, 2026 at 12:11 PM