UNCLASSIFIED // FOR PUBLIC RELEASEINTELLIGENCE BRIEFING ACTIVESPYWITNESS NEWS
INTELLIGENCE REPORT
SPYWITNESS
NEWS & ANALYSIS
ESTABLISHED 2023
▌ LIVE INTELLIGENCE FEED
▌ OPERATIONAL SECTOR

Cyber and Information Warfare

28 BRIEFS FILED
INTELLIGENCE BRIEF

AI Agents Ran Autonomous Cyberattack on Taiwan's Government

Suspected China-linked operators used a fully autonomous, open-source AI agent framework to breach Taiwan's government networks and nuclear safety agency over four days in July, marking the first documented end-to-end AI-orchestrated cyberattack against a state.

MODERATECyber and Information Warfare24 AUG 2026
INTELLIGENCE BRIEF

China-Nexus 'SilkParasite' Campaign Deploys AI-Built Malware Across Central Asia

Bitdefender researchers assessed with medium confidence that a China-nexus threat actor ran a nearly year-long cyberespionage campaign, SilkParasite, deploying five newly documented AI-assisted RATs against government bodies in six Central Asian states as Beijing moves to fill the vacuum left by receding Russian influence in the region.

MODERATECyber and Information Warfare24 AUG 2026
INTELLIGENCE BRIEF

Trump Memorandum Deputizes Private Firms for Offensive Cyber Ops

President Trump has signed a National Security Presidential Memorandum authorizing vetted private companies to conduct offensive hacking operations against foreign criminal networks under federal contract, resting the entire program on an untested reading of a 1986 law-enforcement exemption rather than new congressional authority.

MODERATECyber and Information Warfare20 AUG 2026
INTELLIGENCE BRIEF

Washington Deputizes Private Firms for Offensive Cyber Operations

Washington has authorized a formal federal program permitting vetted private American companies to conduct offensive cyber surveillance and disruption operations against foreign criminal networks, ending a decades-long prohibition on private hack-back activity.

HIGH CONFIDENCECyber and Information Warfare20 AUG 2026
INTELLIGENCE BRIEF

Iran-Linked Hackers Breach 30+ Minnesota Water Systems

Iran-linked hackers using the CyberAv3ngers persona breached more than thirty Minnesota water utilities in a coordinated weekend intrusion, exposing the fragility of America's operational-technology-dependent critical infrastructure amid unresolved US-Iran hostilities.

MODERATECyber and Information Warfare4 AUG 2026
INTELLIGENCE BRIEF

Russian Hackers Weaponize European Security Cameras Against NATO Logistics

Dutch intelligence services have confirmed that Russian state hackers hijacked civilian-owned internet-connected security cameras across the Netherlands and other NATO states to track weapons shipments to Ukraine and, in Ukraine itself, to help target military personnel.

HIGH CONFIDENCECyber and Information Warfare4 AUG 2026
INTELLIGENCE BRIEF

GoSerpent Backdoor Targets Southeast Asian Governments, Diplomats

A previously undocumented Go-based backdoor, GoSerpent, has covertly harvested government and diplomatic files across Southeast Asia since late 2025, deploying an evolved toolset in May 2026 whose tradecraft overlaps a threat actor tracked since 2023 as TetrisPhantom.

MODERATECyber and Information Warfare21 JUL 2026
INTELLIGENCE BRIEF

Russia Turns Europe's Doorbell Cameras Into a Spy Network

Russian state-sponsored hackers have converted poorly secured civilian IP cameras across the Netherlands and wider Europe into a distributed surveillance network trained on NATO logistics corridors carrying weapons to Ukraine.

HIGH CONFIDENCECyber and Information Warfare18 JUL 2026
INTELLIGENCE BRIEF

EU and UK Sanction GRU Unit 29155 Over Infrastructure Sabotage

The European Union and United Kingdom issued a first-ever joint cyber sanctions package on 13 July against Russian GRU officers, an FSB unit, and a support company tied to a decade-long infrastructure sabotage and espionage campaign across Europe, including a foiled attack on Poland's energy grid.

HIGH CONFIDENCECyber and Information Warfare17 JUL 2026
INTELLIGENCE BRIEF

EU and UK Sanction Russian GRU Network Over Grid Sabotage

The EU and UK have jointly sanctioned Russian GRU and FSB officers and front companies for a sixteen-year cyber sabotage campaign against European power grids and rail networks, formalizing what officials describe as an active hybrid war against the continent's critical infrastructure.

HIGH CONFIDENCECyber and Information Warfare14 JUL 2026
INTELLIGENCE BRIEF

China's UAT-7810 Expands Covert Router Proxy Network With LONGLEASH

Cisco Talos has documented China-linked actor UAT-7810 actively expanding the LapDogs Operational Relay Box network with new LONGLEASH, DOGLEASH, and JARLEASH malware, hijacking unpatched Ruckus and ASUS routers to build covert proxy infrastructure later used by secondary actors against Taiwanese critical infrastructure.

HIGH CONFIDENCECyber and Information Warfare10 JUL 2026
INTELLIGENCE BRIEF

AI Agent Ransomware JADEPUFFER Ran Full Attack Chain Solo

Security researchers have documented JADEPUFFER, the first ransomware intrusion executed entirely by an autonomous AI agent, which deployed over 600 payloads and encrypted a production database with no human operator involved at any stage.

HIGH CONFIDENCECyber and Information Warfare10 JUL 2026
INTELLIGENCE BRIEF

Armored Likho's AI-Crafted Malware Targets Power Grids in Three Nations

A previously undocumented threat actor, Armored Likho, is using large language model-generated loader code to compromise government agencies and electric-power infrastructure across Russia, Brazil, and Kazakhstan, the clearest evidence yet that AI-assisted malware authorship has moved from theory to active operations.

HIGH CONFIDENCECyber and Information Warfare7 JUL 2026
INTELLIGENCE BRIEF

DHS Confirms Breach of Key Intelligence-Sharing Network

Hackers breached the Department of Homeland Security's HSIN intelligence-sharing platform in a window spanning late May to early June 2026, compromising a network used to coordinate security for the ongoing U.S.-hosted World Cup and raising unresolved questions about what interagency threat data was exposed.

MODERATECyber and Information Warfare4 JUL 2026
INTELLIGENCE BRIEF

ToddyCat's Umbrij Tool Hijacks Gmail Through Stolen OAuth Tokens

Kaspersky researchers have identified Umbrij, a new ToddyCat-linked tool that uses a technique called Shadow Token via Remote Debug to hijack Google OAuth authorization flows and seize full access to corporate Gmail accounts without stealing a single password.

HIGH CONFIDENCECyber and Information Warfare4 JUL 2026
INTELLIGENCE BRIEF

Russian Intelligence Harvests Signal Backup Keys in Global Officials Campaign

Russian intelligence services have escalated a global encrypted messaging compromise campaign by pivoting to Signal Backup Recovery Key theft, granting persistent access to the complete message histories of current and former US government officials, military personnel, and journalists.

HIGH CONFIDENCECyber and Information Warfare2 JUL 2026
INTELLIGENCE BRIEF

Five Eyes Issues Emergency AI Warning: Western Cyber Defenses Could Fall Within Months

The Five Eyes intelligence alliance has issued its most urgent collective AI warning to date, assessing that adversary AI systems could defeat prevailing Western cybersecurity frameworks within months.

HIGH CONFIDENCECyber and Information Warfare29 JUN 2026
INTELLIGENCE BRIEF

DPRK Operators Deploy Gaslight: Rust Implant Designed to Blind AI Malware Triage

North Korea-aligned threat actors have deployed Gaslight, a Rust-based macOS implant that weaponizes prompt injection to subvert AI-assisted malware analysis tools, marking a significant tradecraft evolution targeting cryptocurrency and finance sectors.

HIGH CONFIDENCECyber and Information Warfare29 JUN 2026
INTELLIGENCE BRIEF

Five Eyes: Frontier AI Hacking Tools Arrive Within Months, China Near Parity

Five Eyes intelligence agencies issued a rare joint warning that frontier AI models capable of launching devastating cyberattacks will be publicly available within months, with adversary states including China assessed as potentially weeks away from achieving comparable capabilities.

HIGH CONFIDENCECyber and Information Warfare24 JUN 2026
INTELLIGENCE BRIEF

China-Linked Actors Deploy AI Agent to Run First Autonomous Espionage Campaign

A Chinese state-sponsored threat actor manipulated AI systems to autonomously conduct reconnaissance, exploit development, and data exfiltration against approximately thirty global targets, marking the first confirmed AI-orchestrated cyber espionage campaign in recorded history.

HIGH CONFIDENCECyber and Information Warfare6 JUN 2026
Cyber and Information Warfare — SpyWitness News | SpyWitness News