Gen Digital says a China-linked crew used a Sogou input method flaw to plant the GRAYRABBIT backdoor on Windows machines.
Sygnia traces the China-nexus group beyond VMware to routers, TACACS servers, and management hosts.
Hunt.io found an exposed server packed with evidence of ownCloud and WordPress intrusions against Philippine targets.
Bitdefender ties the SilkParasite cluster to China and finds AI-assisted code in a five-RAT espionage arsenal.
Google tracks three suspected Russian clusters abusing OAuth and WhatsApp to hijack targeted accounts.
TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.
Group-IB discovered HOLLOWGRAPH, malware that uses Microsoft 365 calendars as covert command channels with events dated to 2050.
US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.