Topic ReportIndustry themeLast 14 days · Asia/Shanghai

Global High-Impact Cyber Attacks

Anthropic disrupts Russian APT GTG-20006 that weaponized Claude for malware evasion

578
Items scanned in 14 days · Yesterday 50
406.9%
Passed judgment / worth alerting · 93.1% noise filtered
35
New development cards · 5 items merged as supporting evidence
8
Sources with valid signal this period · Top The Hacker News

Key takeaways

AI narrative grounded in merged developments; each item links to sources
  1. Russian APT GTG-20006 abused Claude to rebuild malware post-detection; Anthropic confirmed the disruption.
  2. ALTERED SPIDER compromised 300+ software dependencies in a single-day supply-chain campaign.
  3. CISA confirmed active in-the-wild exploitation of Linux kernel, GitLab, Cisco, and Fortinet vulnerabilities.
  4. Coast Guard and FBI boarded two Gulf of Mexico tankers after confirmed cyber intrusion hit navigation systems.

What to watch next

  • Watch for further TanStack supply-chain victims as CrowdSec confirms the campaign's expanding blast radius.
  • Cisco FMC dual-CVE exploitation and Sandworm's Cyclops Blink revival suggest infrastructure targeting is intensifying.
  • Iranian Chosen Brick spyware may widen targets; NCSC–FBI–AIVD advisory signals coordinated multi-agency posture.

14-day pulse

Daily scan volume vs items that passed judgment
0
0
0
0
0
27
4
3
1
2
2
0
1
0
09/0909/1009/1109/1209/1309/1409/1509/1609/1709/1809/1909/2009/2109/22
Items scanned (background)Passed judgment (independent scale)

Storylines

4 themes · click to jump to the timeline

Supply-Chain Compromise Campaigns3

TanStack breach expanded to CrowdSec; ALTERED SPIDER hit 300+ dependencies; Sandworm chains Cisco flaws for Cyclops Blink botnet revival.

Active In-the-Wild Exploitation4

CISA KEV additions span Linux kernel TLS, GitLab Perfect-10, Artifactory, ScreenConnect, RouterOS, Cisco FMC, and Fortinet with confirmed exploitation.

Nation-State APT Campaigns3

Iranian Chosen Brick targets dissidents and journalists; Russian GTG-20006 weaponized Claude; Gulf tanker intrusion attributed to foreign actors.

Ransomware Impact on Critical Services2

MUIS payroll system (Avelogic) held for ransom in Singapore; Cedar County Memorial Hospital (MO) suffered full IT outage diverting trauma care.

Development timeline

12 items · newest first
September 21Monday · 1
Key Supply-Chain Compromise Campaigns 18:55 · SecurityWeek 1 evidence

CrowdSec Confirms Source-Code Theft, Attributes Breach to TanStack Supply-Chain Attack

CrowdSec confirmed its source code was stolen and assessed the breach as the result of the May 2026 TanStack supply-chain attack, naming CrowdSec as a further confirmed victim and extending the campaign's documented impact into a security-tooling codebase.

September 19Saturday · 2
Key Active In-the-Wild Exploitation 14:24 · The Hacker News 1 evidence

CISA confirms active in-the-wild exploitation of three Linux kernel vulnerabilities including critical TLS flaw (CVSS 9.8)

CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog Friday, citing evidence of active in-the-wild exploitation. CVE-2025-39682 (CVSS 9.8) is an improper check in the TLS receive path. The confirmed exploitation of these kernel-level flaws represents a mass-exploitation risk to Linux-based infrastructure globally.

CVE CVE-2025-39682CVSS 9.8Venue CISA Known Exploited Vulnerabilities
Key Supply-Chain Compromise Campaigns 03:30 · CrowdStrike 1 evidence

ALTERED SPIDER compromises 300+ software dependencies in single-day supply-chain campaign

ALTERED SPIDER conducted a supply-chain compromise campaign affecting over 300 software dependencies within a single day, establishing adversary access through trusted dependency channels to reach downstream organizations at scale. Threat hunters have documented the operation; the campaign represents active, mass-reach supply-chain exploitation rather than a single-victim incident.

Software supply chain attacks turn trusted dependencies into adversary access. 📦 ALTERED SPIDER compromised more than 300 software dependencies in a single day, creating a path to reach organizations at scale. See what threat hunters uncovered:— CrowdStrike · @CrowdStrike 于 X · Sep 19, 2026, 3:30 AM
Scale 300+ dependenciesTimeframe single day
September 17Thursday · 1
Key Nation-State APT Campaigns 02:46 · The Record 3 evidence

Coast Guard confirms malicious cyber activity on VL Prosperity; two Gulf of Mexico tankers en route to US coast affected, navigation and propulsion systems compromised, Iran attribution not confirmed

U.S. Coast Guard and FBI physically boarded two oil tankers in the Gulf of Mexico to ensure the integrity of the vessels' operational and information technology systems following a cyberattack by 'foreign cyber actors' (The Record, Sep 16). The Coast Guard confirmed evidence of malicious cyber activity specifically on the VL Prosperity and reported that two oil tankers were targeted in the incident; the agency explicitly stated it has not attributed the attack to Iran, narrowing the state-actor picture beyond the initial 'foreign cyber actors' characterization (SecurityWeek, Sep 17). The joint multi-agency physical response confirms an active, state-linked cyber operation against U.S. maritime infrastructure, with affected vessels taken offline for inspection. Newly confirmed: the network compromise interfered with at least one tanker's navigation and propulsion systems, demonstrating direct functional impact on vessel operability beyond IT-system intrusion, and the affected tankers were en route to the U.S. coast at the time of the incident.

September 16Wednesday · 1
Key Ransomware Impact on Critical Services 06:08 · DataBreaches.Net 1 evidence

Ransomware attack on MUIS payroll system supplied by Avelogic

MUIS confirmed its SmartHRMS payroll system (supplied by Singapore vendor Avelogic) was breached and held for ransom, with staff personal and financial details of mosques and madrasahs potentially compromised. Avelogic published a cybersecurity incident notice on its website.

September 15Tuesday · 3
Nation-State APT Campaigns 22:11 · NCSC UK 4 evidence

NCSC–FBI–AIVD Joint Advisory Confirms Iranian 'Chosen Brick' Spyware Campaign Targeting Dissidents, Activists, and Journalists

The UK NCSC, US FBI, and Dutch AIVD jointly published an advisory documenting an active Iranian state-sponsored APT espionage campaign. The campaign targets dissidents, activists, and journalists using spyware now specifically identified as 'Chosen Brick,' a platform designed for covert surveillance of targeted individuals. The tri-agency coordination confirms ongoing operational activity and elevates the threat picture from a single-vendor report to a multi-nation validated assessment with named tooling.

Today, the NCSC alongside the @FBI and the Dutch AIVD, has published an advisory exposing spyware used by Iranian state actors to target dissidents, activists, and journalists. 1/2— NCSC UK · @NCSC 于 X · Sep 15, 2026, 10:11 PM
Ransomware Impact on Critical Services 19:49 · DataBreaches.Net 1 evidence

Cedar County Memorial Hospital (MO) IT outage disrupts patient care; ransomware group claims attack

Cedar County Memorial Hospital (El Dorado Springs, MO) confirmed an IT network shutdown on Aug 14 that took offline its EHR, patient portal, and diagnostic imaging, forcing the ED to partially divert trauma and critical cases. A ransomware group has publicly claimed responsibility for the disruption. The incident is documented via DysruptionHub reporting; hospital-side confirmation of the ransomware vector and whether a demand or extortion has been issued remains unconfirmed.

Key Supply-Chain Compromise Campaigns 05:37 · Dark Reading 1 evidence

Sandworm Chaining Cisco Vulnerabilities for Upgraded Cyclops Blink Deployment

Russian GRU-linked APT Sandworm is actively chaining multiple Cisco vulnerabilities to deploy an upgraded variant of the Cyclops Blink botnet (originally disrupted by the FBI in 2022), indicating an ongoing supply-chain compromise campaign against network infrastructure.

September 14Monday · 1
Key Active In-the-Wild Exploitation 22:30 · The Register - Security 1 evidence

CISA confirms active exploitation of GitLab 'Perfect-10' bug

CISA confirmed active exploitation of the GitLab 'Perfect-10' vulnerability. watchTowr observed miscreants probing internet-facing servers in the days following the patch release, indicating an active exploitation window for unpatched deployments.

September 12Saturday · 1
Active In-the-Wild Exploitation 23:54 · The Hacker News 1 evidence

CISA flags active exploitation of Artifactory, ScreenConnect, and RouterOS flaws via KEV addition

CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. No specific victims, attacking groups, or operational-impact details are provided in this advisory; it serves as a patch-now directive for the three product families.

September 11Friday · 1
Nation-State APT Campaigns 22:10 · The Hacker News 1 evidence

Anthropic Confirms Disruption of Russian APT Group GTG-20006's AI-Powered Malware Reconstruction Espionage

Anthropic confirmed and disrupted a Russia state-sponsored cyber espionage operation (GTG-20006) that abused Claude to build AI-assisted workflows, using generative models to rapidly reconstruct malware payloads to evade detection after initial detection. The activity has been attributed to a spy group associated with the 'Midnight' threat cluster, representing a significant APT operational incident.

APT Group GTG-20006AI Tool Abused Claude
September 10Thursday · 1
Key Active In-the-Wild Exploitation 18:36 · The Hacker News 3 evidence

Cisco Talos confirms dual-CVE active exploitation in FMC by nation-state and ransomware actors; CISA Sept 12 patch deadline in effect

CISA added three actively exploited vulnerabilities affecting Cisco (CVE-2026-20079, CVSS 10.0, authentication bypass), Citrix, and Fortinet to its Known Exploited Vulnerabilities catalog, mandating FCEB agencies to patch by September 12, 2026. Cisco Talos has confirmed it is actively tracking exploitation of two separate vulnerabilities in Cisco Secure Firewall Management Center (FMC) software—CVE-2026-20079 and CVE-2026-20316—by both state-sponsored and financially-motivated (ransomware) actors. Because FMC is used for centrally managing multiple Cisco Secure Firewall devices across a network, successful exploitation extends control beyond a single appliance. The dual-CVE, dual-actor-type vendor confirmation escalates the incident from a single-patch KEV entry to a coordinated multi-vector threat against enterprise firewall-management infrastructure.

CVE CVE-2026-20079CVSS 10.0Patch Deadline Sept 12

Who provided signal

Ranked by items that passed judgment
The Hacker News11
Infosecurity Magazine9
The Register - Security4
Dark Reading3
SecurityWeek2
DataBreaches.Net2
NCSC UK2
TechCrunch — Security1

What this report watches

Focus scope and judgment criteria (read-only)

Focus

Confirmed ransomware attacks with named victimsRansomware with large blast radiusAPT and nation-state campaignsSupply-chain compromisesActive mass exploitationCERT advisories on ongoing attacksVendor threat-intel on active campaigns

Exclude

Routine CVE dumps without exploitationVendor marketing contentSecurity tips and best practicesUncorroborated rumors

Judgment criteria

Wake for confirmed ransomware incidents with named victims or wide operational impact, active APT or nation-state campaigns, supply-chain compromises, and documented mass exploitation. Include CERT advisories and vendor threat-intel only when they describe ongoing attacks or active exploitation. Drop routine CVE dumps without exploitation evidence, marketing content, generic security tips, and uncorroborated rumors. Create separate cards for distinct campaigns, victims, or exploitation events.