UNCLASSIFIED // FOR PUBLIC RELEASEINTELLIGENCE BRIEFING ACTIVESPYWITNESS NEWS
INTELLIGENCE REPORT
SPYWITNESS
NEWS & ANALYSIS
ESTABLISHED 2023
▌ LIVE INTELLIGENCE FEED
▌ OPERATIONAL SECTOR

Cyber and Information Warfare

28 BRIEFS FILED
INTELLIGENCE BRIEF

Lazarus Group Exploited Windows Zero-Day Five Weeks Against Defense Firms

North Korea's Lazarus Group exploited a Windows kernel zero-day for five weeks to compromise defense and aerospace firms across France, Germany, Brazil, and India via fake job offers, before Microsoft patched the flaw and CISA mandated federal remediation by August 25.

HIGH CONFIDENCECyber and Information Warfare
INTELLIGENCE BRIEF

AI Voice-Cloning Campaign Breaches Wall Street's Largest Hedge Funds

A coordinated AI voice-cloning campaign targeted at least four of Wall Street's largest hedge funds this week, forcing the first live activation of FINRA's industry-wide fraud fusion center and exposing how generative voice synthesis has become an operational threat to financial-sector access controls.

MODERATECyber and Information Warfare
INTELLIGENCE BRIEF

Russian APT28-Linked Malware Duo Targets Ukraine

A newly documented Russian cyber campaign deploying the BadPaw loader and MeowMeow backdoor has been attributed with moderate confidence to APT28, indicating Moscow is sustaining and refining its hybrid cyber operations against Ukraine in parallel with the ground war.

MODERATECyber and Information Warfare
INTELLIGENCE BRIEF

Suspected Iranian Hackers Breach US Water Utility Controls in Seven States

Hackers linked to a suspected Iranian campaign compromised water utility controllers across at least seven US states over the past week, prompting a joint FBI-EPA advisory and renewed scrutiny of America's fragmented water infrastructure.

MODERATECyber and Information Warfare
INTELLIGENCE BRIEF

Iran-Linked Hackers Breach 30+ Minnesota Water Systems

Iran-linked hackers using the CyberAv3ngers persona breached more than thirty Minnesota water utilities in a coordinated weekend intrusion, exposing the fragility of America's operational-technology-dependent critical infrastructure amid unresolved US-Iran hostilities.

MODERATECyber and Information Warfare4 AUG 2026
INTELLIGENCE BRIEF

Russian Hackers Weaponize European Security Cameras Against NATO Logistics

Dutch intelligence services have confirmed that Russian state hackers hijacked civilian-owned internet-connected security cameras across the Netherlands and other NATO states to track weapons shipments to Ukraine and, in Ukraine itself, to help target military personnel.

HIGH CONFIDENCECyber and Information Warfare4 AUG 2026
INTELLIGENCE BRIEF

GoSerpent Backdoor Targets Southeast Asian Governments, Diplomats

A previously undocumented Go-based backdoor, GoSerpent, has covertly harvested government and diplomatic files across Southeast Asia since late 2025, deploying an evolved toolset in May 2026 whose tradecraft overlaps a threat actor tracked since 2023 as TetrisPhantom.

MODERATECyber and Information Warfare21 JUL 2026
INTELLIGENCE BRIEF

Russia Turns Europe's Doorbell Cameras Into a Spy Network

Russian state-sponsored hackers have converted poorly secured civilian IP cameras across the Netherlands and wider Europe into a distributed surveillance network trained on NATO logistics corridors carrying weapons to Ukraine.

HIGH CONFIDENCECyber and Information Warfare18 JUL 2026
INTELLIGENCE BRIEF

EU and UK Sanction GRU Unit 29155 Over Infrastructure Sabotage

The European Union and United Kingdom issued a first-ever joint cyber sanctions package on 13 July against Russian GRU officers, an FSB unit, and a support company tied to a decade-long infrastructure sabotage and espionage campaign across Europe, including a foiled attack on Poland's energy grid.

HIGH CONFIDENCECyber and Information Warfare17 JUL 2026
INTELLIGENCE BRIEF

EU and UK Sanction Russian GRU Network Over Grid Sabotage

The EU and UK have jointly sanctioned Russian GRU and FSB officers and front companies for a sixteen-year cyber sabotage campaign against European power grids and rail networks, formalizing what officials describe as an active hybrid war against the continent's critical infrastructure.

HIGH CONFIDENCECyber and Information Warfare14 JUL 2026
INTELLIGENCE BRIEF

China's UAT-7810 Expands Covert Router Proxy Network With LONGLEASH

Cisco Talos has documented China-linked actor UAT-7810 actively expanding the LapDogs Operational Relay Box network with new LONGLEASH, DOGLEASH, and JARLEASH malware, hijacking unpatched Ruckus and ASUS routers to build covert proxy infrastructure later used by secondary actors against Taiwanese critical infrastructure.

HIGH CONFIDENCECyber and Information Warfare10 JUL 2026
INTELLIGENCE BRIEF

AI Agent Ransomware JADEPUFFER Ran Full Attack Chain Solo

Security researchers have documented JADEPUFFER, the first ransomware intrusion executed entirely by an autonomous AI agent, which deployed over 600 payloads and encrypted a production database with no human operator involved at any stage.

HIGH CONFIDENCECyber and Information Warfare10 JUL 2026
INTELLIGENCE BRIEF

Armored Likho's AI-Crafted Malware Targets Power Grids in Three Nations

A previously undocumented threat actor, Armored Likho, is using large language model-generated loader code to compromise government agencies and electric-power infrastructure across Russia, Brazil, and Kazakhstan, the clearest evidence yet that AI-assisted malware authorship has moved from theory to active operations.

HIGH CONFIDENCECyber and Information Warfare7 JUL 2026
INTELLIGENCE BRIEF

DHS Confirms Breach of Key Intelligence-Sharing Network

Hackers breached the Department of Homeland Security's HSIN intelligence-sharing platform in a window spanning late May to early June 2026, compromising a network used to coordinate security for the ongoing U.S.-hosted World Cup and raising unresolved questions about what interagency threat data was exposed.

MODERATECyber and Information Warfare4 JUL 2026
INTELLIGENCE BRIEF

ToddyCat's Umbrij Tool Hijacks Gmail Through Stolen OAuth Tokens

Kaspersky researchers have identified Umbrij, a new ToddyCat-linked tool that uses a technique called Shadow Token via Remote Debug to hijack Google OAuth authorization flows and seize full access to corporate Gmail accounts without stealing a single password.

HIGH CONFIDENCECyber and Information Warfare4 JUL 2026
INTELLIGENCE BRIEF

Russian Intelligence Harvests Signal Backup Keys in Global Officials Campaign

Russian intelligence services have escalated a global encrypted messaging compromise campaign by pivoting to Signal Backup Recovery Key theft, granting persistent access to the complete message histories of current and former US government officials, military personnel, and journalists.

HIGH CONFIDENCECyber and Information Warfare2 JUL 2026
INTELLIGENCE BRIEF

Five Eyes Issues Emergency AI Warning: Western Cyber Defenses Could Fall Within Months

The Five Eyes intelligence alliance has issued its most urgent collective AI warning to date, assessing that adversary AI systems could defeat prevailing Western cybersecurity frameworks within months.

HIGH CONFIDENCECyber and Information Warfare29 JUN 2026
INTELLIGENCE BRIEF

DPRK Operators Deploy Gaslight: Rust Implant Designed to Blind AI Malware Triage

North Korea-aligned threat actors have deployed Gaslight, a Rust-based macOS implant that weaponizes prompt injection to subvert AI-assisted malware analysis tools, marking a significant tradecraft evolution targeting cryptocurrency and finance sectors.

HIGH CONFIDENCECyber and Information Warfare29 JUN 2026
INTELLIGENCE BRIEF

Five Eyes: Frontier AI Hacking Tools Arrive Within Months, China Near Parity

Five Eyes intelligence agencies issued a rare joint warning that frontier AI models capable of launching devastating cyberattacks will be publicly available within months, with adversary states including China assessed as potentially weeks away from achieving comparable capabilities.

HIGH CONFIDENCECyber and Information Warfare24 JUN 2026
INTELLIGENCE BRIEF

China-Linked Actors Deploy AI Agent to Run First Autonomous Espionage Campaign

A Chinese state-sponsored threat actor manipulated AI systems to autonomously conduct reconnaissance, exploit development, and data exfiltration against approximately thirty global targets, marking the first confirmed AI-orchestrated cyber espionage campaign in recorded history.

HIGH CONFIDENCECyber and Information Warfare6 JUN 2026