State Department offers $10 million for information on the whereabouts of Zhang Yu, a Shanghai company director charged in the Hafnium hacking campaign. The bounty keeps the US case against two named men moving years after June 2021, when the indictment says the charged intrusions ended.
Perspective Coverage
6 publishers
- Builder
- Builder 14%
- Operator
- Operator 81%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives55
- Confidence70
US, UK and allied governments on October 8 described sanctioned Integrity Technology Group as a tool and infrastructure supplier that enabled Flax Typhoon. Its technique list centers on email theft and names the files and clients operators left on victim systems.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Palo Alto's Unit 42 says an Iranian state-aligned actor it tracks as CL-STA-1178 posed as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Its report ties attacks other vendors reported one at a time into one campaign that hit Iraqi critical infrastructure in March 2026.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence45
buildOne report1 publisher Proofpoint says China-aligned TA419 has phished US AI policy experts since April 2025 with a proxy that captures Microsoft session cookies and bypasses MFA. Its fix is passkeys plus out-of-band checks on unsolicited expert outreach.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 63%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption30
- Hype gap+8
- Incentives
- Insufficient
- Confidence65
Securelist says the newest CoolClient deploys a signed kernel-mode driver as a Windows service to hide its process, files and registry keys. It was seen in Pakistan, Mongolia and Myanmar.
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives35
- Confidence60
Google's threat intelligence team ties three suspected Russian clusters to abuse of Google OAuth, app passwords and device linking. MFA completes normally, so consent telemetry is the control.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Prosecutors added eight names to a 2018 indictment over 31.5 terabytes of stolen academic work. The target set has not changed: professors' mailboxes and university libraries.
Perspective Coverage
7 publishers
- Builder
- Builder 13%
- Operator
- Operator 69%
- Investor
- Investor 18%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence70
The new backdoor, HOOKEDGE, is a Windows batch script that beacons to a free webhook.site endpoint. Insikt Group calls the BlueDelta attribution moderate confidence, resting on overlap with the older HEADLACE implant.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 68%
- Investor
- Investor 5%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence60
Rapid7 says the ted backdoor is built into the victim's existing HAProxy 2.8.12 and hooks its filter API, so the load balancer keeps balancing normally while it logs cookies and injects scripts for selected clients.
Perspective Coverage
5 publishers
- Builder
- Builder 42%
- Operator
- Operator 53%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption10
- Hype gap+20
- Incentives35
- Confidence66
Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives55
- Confidence60
Zscaler ThreatLabz traced August 2026 attacks on Indian and Afghan government and defense targets to a new Rust backdoor that takes orders from private GitHub repositories. Its encryption key is a hash of a token sitting in cleartext in the sample.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence64
A week of takedowns removed people and froze assets across five separate actions, while the kit that manufactures the stolen Microsoft 365 sessions those crews depend on still sells on Telegram for $320 a month.
Reality
- Evidence28
- Adoption52
- Hype gap+30
- Incentives58
- Confidence36
A Chinese state-linked group let Claude Code do 80 to 90 percent of the hands-on work against roughly thirty organisations. The tradecraft was loud, and that was the point.
Reality
- Evidence48
- Adoption32
- Hype gap+22
- Incentives62
- Confidence46