Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 63%
- Investor
- Investor 5%
Reality
- Evidence62
- Adoption30
- Hype gap+8
- Incentives
- Insufficient
- Confidence65
Huntress found the same one-megabyte PIF in two customer environments, pulled down by a link that promised a PNG. Everything after it is the 2024 DarkMe chain, down to the rundll32 /sta GUID from that campaign.
Reality
- Evidence72
- Adoption22
- Hype gap+14
- Incentives66
- Confidence68
BleepingComputer confirmed a defaced page and an uploaded file on Cl0p's infrastructure. Everything past that is a criminal crew's own inventory, and the route it describes runs through the content layer.
Reality
- Evidence40
- Adoption30
- Hype gap+15
- Incentives82
- Confidence45
The debate over AI risk has centred on models that rewrite their own code. Anthropic's latest misuse report spends 154 pages on nine months of intrusions and surveillance that have already happened.
Reality
- Evidence54
- Adoption61
- Hype gap+14
- Incentives71
- Confidence57
SentinelLABS says the two accounts OpenAI declined to name are 0Time and Nyx9. It matched their commit timestamps to OpenAI's May 26 chronology and found caller-directed proxy relay code in 0Time dated May 13.
Reality
- Evidence72
- Adoption30
- Hype gap+12
- Incentives60
- Confidence58
MayaBot only shows up in 2022, seven years into the operation, and one branch of the funnel ends in a phone call to a scam call centre. That leaves the search referral and the redirector domains as the constants worth detecting.
Reality
- Evidence46
- Adoption54
- Hype gap+20
- Incentives45
- Confidence63
Intel 471 found an unauthenticated panel called AppPanda running fake streaming lures behind paid Facebook ads, with affiliate tooling that re-signs the Android payload every hour and tracks ad spend the way a growth team would.
Reality
- Evidence64
- Adoption74
- Hype gap+15
- Incentives58
- Confidence56
German firms' own attribution of attacks to state services has moved from 7% to nearly 40% in two years. That puts nation-state tradecraft on the risk register of any mid-sized manufacturer with a supplier list.
Reality
- Evidence48
- Adoption55
- Hype gap+22
- Incentives68
- Confidence55
Positive Technologies says the East Asian group is injecting JavaScript into legitimate sites to push a bogus certificate that installs SquawkDoor and a reworked SparrowDoor. Four locations are confirmed.
Publishers:habr.com
Reality
- Evidence55
- Adoption34
- Hype gap+18
- Incentives72
- Confidence48
QUIRSO says a suspected China-nexus actor turned CVE-2026-59310 into a backdoor, a reverse SSH binary and Babuk-derived ransomware, with 361 victim IPs across 47 countries.
Reality
- Evidence60
- Adoption72
- Hype gap+12
- Incentives58
- Confidence57