UNCLASSIFIED // FOR PUBLIC RELEASE▸ INTELLIGENCE BRIEFING ACTIVESPYWITNESS NEWS
INTELLIGENCE REPORT
SPYWITNESS
NEWS & ANALYSIS
ESTABLISHED 2023
▌ LIVE INTELLIGENCE FEED
▌ OPERATIONAL SECTOR

Cyber and Information Warfare

37 BRIEFS FILED
▌ INTELLIGENCE BRIEF

AI Agent Breaches South Korean Banks, Exposing 68,000 Customers

An open-source Chinese-developed AI agent, Artex, was reportedly used to breach South Korean financial institutions, indicating that autonomous intrusion capability once limited to well-resourced actors is now freely available.

◆ MODERATECyber and Information Warfare
▌ INTELLIGENCE BRIEF

Russian Spy Cluster Weaponized AI to Automate Espionage Operations

Anthropic's September 2026 threat intelligence report reveals that a Russian state-nexus espionage cluster, GTG-20006, built AI-driven workflows around Claude to automate reconnaissance, phishing, and exfiltration against more than twenty Ukrainian, European, and diplomatic targets, marking a qualitative shift in how state intelligence services conduct cyber operations.

◆ HIGH CONFIDENCECyber and Information Warfare
▌ INTELLIGENCE BRIEF

Fire Ant Turns Routers Into Silent Spy Platforms

A China-linked espionage cluster tracked as Fire Ant has hijacked Cisco IOS XR routers and authentication servers to establish covert, log-evading access across enterprise networks, with reconnaissance activity extending toward U.S. critical infrastructure.

◆ MODERATECyber and Information Warfare
▌ INTELLIGENCE BRIEF

AI-Generated Exploits Breach US Water Utilities as Iran Tests UK Grid

A joint US federal advisory confirms adversaries are using AI-generated exploit code against Siemens industrial controllers in the first operationally confirmed AI-assisted intrusion campaign against US critical infrastructure, coinciding with an Iran-linked strike on UK power generation.

◆ HIGH CONFIDENCECyber and Information Warfare
▌ INTELLIGENCE BRIEF

ShinyHunters FBI Breach Claim Exposes Bureau Personnel to Counterintelligence Targeting

ShinyHunters' claimed breach of FBI personnel systems, partially corroborated by Reuters and 404 Media, would place home addresses and family details of Bureau staff within reach of foreign intelligence services, turning a criminal grudge into a counterintelligence liability.

◆ MODERATECyber and Information Warfare24 SEPT 2026
▌ INTELLIGENCE BRIEF

Moscow's AI-Automated Espionage Machine Targets European Defense Networks

Russian intelligence-linked hackers operationalized Anthropic's Claude to autonomously detect, rebuild, and redeploy malware faster than defenders could respond, compromising more than twenty government, diplomatic, and defense-sector targets across Ukraine, Europe, the Middle East, and Asia.

◆ HIGH CONFIDENCECyber and Information Warfare18 SEPT 2026
▌ INTELLIGENCE BRIEF

Iran-Linked Hackers Breach Water Systems Across Twelve US States

Iran-linked hackers, assessed to include the IRGC-backed CyberAv3ngers, have breached water-utility control systems across at least twelve U.S. states, briefly disabling a Georgia pump station in the broadest documented targeting of U.S. water infrastructure since 2023.

◆ MODERATECyber and Information Warfare18 SEPT 2026
▌ INTELLIGENCE BRIEF

Norway's Digital Identity Backbone Struck by Third DDoS Wave in Ten Weeks

A sustained distributed denial-of-service campaign disabled Norway's national digital identity gateway ID-porten for more than 30 hours starting 24 August, the third and largest such strike on the country's shared government infrastructure since June, with attribution still unconfirmed.

◆ MODERATECyber and Information Warfare26 AUG 2026
▌ INTELLIGENCE BRIEF

Iranian Hackers Force Four-Day Shutdown of UK Power Plant

Iran-linked hackers achieved the first confirmed physical shutdown of UK energy infrastructure in July 2026, a four-day outage that officials and analysts assess as a demonstrated capability rather than an attempt at wider grid disruption.

◆ MODERATECyber and Information Warfare26 AUG 2026
▌ INTELLIGENCE BRIEF

AI Agents Ran Autonomous Cyberattack on Taiwan's Government

Suspected China-linked operators used a fully autonomous, open-source AI agent framework to breach Taiwan's government networks and nuclear safety agency over four days in July, marking the first documented end-to-end AI-orchestrated cyberattack against a state.

◆ MODERATECyber and Information Warfare24 AUG 2026
▌ INTELLIGENCE BRIEF

China-Nexus 'SilkParasite' Campaign Deploys AI-Built Malware Across Central Asia

Bitdefender researchers assessed with medium confidence that a China-nexus threat actor ran a nearly year-long cyberespionage campaign, SilkParasite, deploying five newly documented AI-assisted RATs against government bodies in six Central Asian states as Beijing moves to fill the vacuum left by receding Russian influence in the region.

◆ MODERATECyber and Information Warfare24 AUG 2026
▌ INTELLIGENCE BRIEF

Trump Memorandum Deputizes Private Firms for Offensive Cyber Ops

President Trump has signed a National Security Presidential Memorandum authorizing vetted private companies to conduct offensive hacking operations against foreign criminal networks under federal contract, resting the entire program on an untested reading of a 1986 law-enforcement exemption rather than new congressional authority.

◆ MODERATECyber and Information Warfare20 AUG 2026
▌ INTELLIGENCE BRIEF

Washington Deputizes Private Firms for Offensive Cyber Operations

Washington has authorized a formal federal program permitting vetted private American companies to conduct offensive cyber surveillance and disruption operations against foreign criminal networks, ending a decades-long prohibition on private hack-back activity.

◆ HIGH CONFIDENCECyber and Information Warfare20 AUG 2026
▌ INTELLIGENCE BRIEF

Iran-Linked Hackers Breach 30+ Minnesota Water Systems

Iran-linked hackers using the CyberAv3ngers persona breached more than thirty Minnesota water utilities in a coordinated weekend intrusion, exposing the fragility of America's operational-technology-dependent critical infrastructure amid unresolved US-Iran hostilities.

◆ MODERATECyber and Information Warfare4 AUG 2026
▌ INTELLIGENCE BRIEF

Russian Hackers Weaponize European Security Cameras Against NATO Logistics

Dutch intelligence services have confirmed that Russian state hackers hijacked civilian-owned internet-connected security cameras across the Netherlands and other NATO states to track weapons shipments to Ukraine and, in Ukraine itself, to help target military personnel.

◆ HIGH CONFIDENCECyber and Information Warfare4 AUG 2026
▌ INTELLIGENCE BRIEF

GoSerpent Backdoor Targets Southeast Asian Governments, Diplomats

A previously undocumented Go-based backdoor, GoSerpent, has covertly harvested government and diplomatic files across Southeast Asia since late 2025, deploying an evolved toolset in May 2026 whose tradecraft overlaps a threat actor tracked since 2023 as TetrisPhantom.

◆ MODERATECyber and Information Warfare21 JUL 2026
▌ INTELLIGENCE BRIEF

Russia Turns Europe's Doorbell Cameras Into a Spy Network

Russian state-sponsored hackers have converted poorly secured civilian IP cameras across the Netherlands and wider Europe into a distributed surveillance network trained on NATO logistics corridors carrying weapons to Ukraine.

◆ HIGH CONFIDENCECyber and Information Warfare18 JUL 2026
▌ INTELLIGENCE BRIEF

EU and UK Sanction GRU Unit 29155 Over Infrastructure Sabotage

The European Union and United Kingdom issued a first-ever joint cyber sanctions package on 13 July against Russian GRU officers, an FSB unit, and a support company tied to a decade-long infrastructure sabotage and espionage campaign across Europe, including a foiled attack on Poland's energy grid.

◆ HIGH CONFIDENCECyber and Information Warfare17 JUL 2026
▌ INTELLIGENCE BRIEF

EU and UK Sanction Russian GRU Network Over Grid Sabotage

The EU and UK have jointly sanctioned Russian GRU and FSB officers and front companies for a sixteen-year cyber sabotage campaign against European power grids and rail networks, formalizing what officials describe as an active hybrid war against the continent's critical infrastructure.

◆ HIGH CONFIDENCECyber and Information Warfare14 JUL 2026
▌ INTELLIGENCE BRIEF

China's UAT-7810 Expands Covert Router Proxy Network With LONGLEASH

Cisco Talos has documented China-linked actor UAT-7810 actively expanding the LapDogs Operational Relay Box network with new LONGLEASH, DOGLEASH, and JARLEASH malware, hijacking unpatched Ruckus and ASUS routers to build covert proxy infrastructure later used by secondary actors against Taiwanese critical infrastructure.

◆ HIGH CONFIDENCECyber and Information Warfare10 JUL 2026