
Weekly Intelligence Snapshot – Week 48
China-nexus group uses new Malware families to infect USBs for Espionage.
Explore our comprehensive archive organized by taxonomy. Discover a wealth of information categorized by subject, theme, or type to enhance your research and understanding.

China-nexus group uses new Malware families to infect USBs for Espionage.

Our tracking of the Mustang Panda group reveals a different DLL sideloading technique from those seen this year.

Pro-Russia hacktivist group From Russia With Love has been deploying Somnia Ransomware in Ukraine since spring 2022. But the #Malware

In our latest Weekly #Intelligence Summary: ASEC Analysis Team has seen LockBit 3.0 Ransomware deployed through Amadey Bot, an Infostealer

Microsoft reports the RaspberryRobin worm is now part of a malware ecosystem and one of the largest active malware distribution

The US publishes its new #NationalSecurity Strategy focussed on China and Russia and emphasizing the key role of the Indo-Pacific

This week the Microsoft Threat Intelligence Center reports on ransomware, “Prestige”, which targets transportation and logistics sectors in Poland and

A CISA advisory reveals vulnerabilities exploited by China-sponsored groups. PatchTuesday: Microsoft fixes 84 #vulnerabilities (inc two 0-day).

This week, we analyze new espionage-driven campaigns related to the Lazarus/ZINC activity cluster.

We are closely following increased geopolitical tensions after the potential sabotage attacks to Nordstream pipelines in the Baltic sea.
Try searching our blog

AI Coding Agents Publish Internal Screenshots from Over 300 Organizations to Public GitHub Repositories | Denmark Says Russia Has Conducted Sabotage Attacks Against Its Defense Firms
ECSO interviewed Marco Riccardi after QuoIntelligence won the ECSO STARtup Award 2026 as Europe’s Most Promising Cybersecurity Start-up.

AI-Driven Cyberattack on Dutch Institute for Vulnerability Disclosure (DIVD) Automates Exploitation and Post-Compromise Activity | European Trade Unions and Civil Society Groups Tell European Governments To End All Contract With Palantir

New Android Trojan RemControl Targets Retail Bank Customers in Europe and Canada | Poland Suspects Fire at Starlink Station Was Act of Sabotage