DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The U.S. Department of Justice issued a correction to clarify that several federal agencies, including NASA, the Federal Reserve, the Department of Energy, and the DoJ itself, were targeted rather than victimized by Chinese threat actors. This revision followed an earlier press statement that had incorrectly characterized the nature and scope of the attacks. The distinction between being targeted versus successfully compromised carries significant implications for understanding the actual impact of the Chinese cyber operations.
Russian state-aligned hackers from UAC-0099 are embedding malicious prompts in malware to deliberately trigger AI safety guardrails and disrupt AI-assisted malware analysis tools, a technique ESET has dubbed GuardBreaker. The group, which conducts initial-access operations for the GRU-linked Sandworm, uses VBS scripts containing provocative prompts designed to overwhelm AI safety mechanisms and prevent proper analysis of their malicious code. This represents a new adversarial approach where threat actors actively work to subvert the security tools being used to detect their operations.
The China-linked Fire Ant group has expanded its espionage campaign to target Cisco IOS XR routers, TACACS servers, and Linux management hosts used for network routing and authentication. By compromising these infrastructure components, the actor gains the ability to steal credentials and disable security logging, allowing persistent access to high-value networks. This represents a significant escalation from the group's previous focus on VMware hypervisors.
A suspected Chinese-speaking threat actor breached Philippine nuclear and naval targets by exploiting known vulnerabilities in internet-facing ownCloud and WordPress systems. The campaign affected a Philippine nuclear research body and a marine engineering company supporting the Philippine Navy, resulting in the theft of sensitive data. The intrusion was discovered by Hunt.io after identifying exposed infrastructure associated with the activity.
Russian APT BlueDelta leverages webhook.site and Microsoft Edge to conceal command-and-control communications for HOOKEDGE espionage operations targeting European government defense and diplomatic entities. The group, linked to Russia's GRU and overlapping with APT28, exploits the legitimate webhook testing service to hide malicious traffic from detection. Recorded Future's Insikt Group documented the campaign, revealing how the threat actor abuses developer tools to conduct sustained espionage against European government infrastructure.