← Back
Nation-StateThe Record·4 hours ago

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

China's Fire Ant campaign exploited compromised Cisco routers not merely as endpoints but as trusted network infrastructure to launch further attacks, effectively corrupting the foundational trust mechanisms that organizations rely on. By weaponizing networking hardware at the core of enterprise environments, the attackers gained a position to conduct secondary operations with minimal detection risk.

Read full article at The Record

Related Articles

Nation-StateSecurity Affairs·14 hours ago

North Korea-linked IT Workers Are Getting Hired Inside Western Companies

Huntress has documented five confirmed cases in 2026 where North Korea-linked IT workers successfully infiltrated Western companies by posing as legitimate remote employees, leveraging fake identities and remote-access tools to gain internal network access. The investigation reveals a pattern of these DPRK-aligned actors, tracked under the name FAMOUS, using proxy infrastructure to disguise their true location and origin. This threat demonstrates a significant supply-chain risk as organizations continue to inadvertently hire these operatives for remote positions without adequate identity verification.

Nation-StateThe Hacker News·17 hours ago

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Russia-aligned threat actor UAC-0099 has employed a technique called GuardBreaker to inject nuclear weapon-related prompts into malware targeting Ukrainian organizations, designed to trigger safety mechanisms in large language models and obstruct AI-assisted threat analysis. This approach represents a deliberate effort to circumvent automated security detection and analysis tools that rely on LLM technology. The technique highlights an emerging adversarial strategy where threat actors actively work to disable AI-powered defensive capabilities.

Nation-StateThe Hacker News·1 day ago

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

North Korean threat actors are expanding their job fraud operations beyond IT roles to target positions in healthcare and sales sectors. These suspected workers, identified through recent investigations, represent an evolving insider threat strategy as part of broader employment-based infiltration campaigns attributed to the DPRK.