The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
Team82 identified two critical vulnerabilities in Vertiv's Liebert IS-UNITY-DP network cards, both rated 9.8 on the CVSSv3 scale. The vulnerabilities, CVE-2025-46412 and CVE-2025-41426, allow for authentication bypass…
Chinese state-sponsored actors have utilized Brickworm malware to breach critical US infrastructure, targeting government and IT networks globally. The malware specifically exploits vulnerabilities in VMware vSphere and…
Chinese state-sponsored hackers have maintained long-term access to critical US networks, utilizing Brickstorm malware for data theft and infiltration. The campaign, which has affected at least eight government services…
The Google Threat Intelligence Group (GTIG) has identified a new operational phase of AI abuse, where adversaries are deploying AI-enabled malware in live operations. This shift indicates that threat actors are moving…
Chinese authorities have instructed domestic firms to cease using cybersecurity software from over a dozen U.S. and Israeli companies due to national security concerns. Affected vendors include VMware, Palo Alto…
The U.S. Cybersecurity and Infrastructure Security Agency, the National Security Agency, and the Canadian Centre for Cyber Security have released an updated Malware Analysis Report on the Brickstorm backdoor. This…
CISA, in collaboration with the NSA and Canada's Cyber Security Centre, has issued a warning about Chinese hackers using BrickStorm malware to backdoor VMware vSphere servers. The attacks primarily affect government and…
CISA has disclosed details about the BRICKSTORM backdoor, which is linked to Chinese state-sponsored threat actors. This backdoor targets VMware vSphere environments within government and technology sectors, enabling…
On December 4, 2025, US and Canadian cybersecurity agencies reported that Chinese-linked hackers utilized sophisticated malware to gain long-term access to unnamed government and IT entities. This operation is part of a…