Recent Government Cyber Attacks

Page 2 of 4
Hidden Prompt Turns Copilot Docs Into a Worm

Hidden Prompt Turns Copilot Docs Into a Worm

A security researcher demonstrated that Microsoft Copilot for Word can be tricked by hidden text inside a Word document, causing Copilot to follow attacker instructions. The result is a self-propagating “AI worm” that silently modifies documents and embeds the same hidden prompt into new files,…

July 30, 2026
Half-Click OWA Emails Trigger Stealth Mailbox Takeover

Half-Click OWA Emails Trigger Stealth Mailbox Takeover

A Russia-aligned group (TA488) sent specially crafted emails that triggered malicious JavaScript simply by being viewed in Outlook Web Access (no link click or attachment needed). The implant (“OWAReaper”) can quietly change server-side mailbox permissions and abuse OAuth tokens, so attackers can…

July 30, 2026
“Half-Click” OWA Email Trap Spreads

“Half-Click” OWA Email Trap Spreads

Proofpoint reports a Russian-linked espionage group is using booby-trapped emails that infect users simply when they open the message in Outlook Web Access (OWA) on on‑premises Exchange. The attack runs malicious JavaScript inside the victim’s logged-in mail session and installs a stealthy…

July 30, 2026
“No-Action” Emails Trigger OWA Mailbox Takeover

“No-Action” Emails Trigger OWA Mailbox Takeover

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access (OWA) could trigger a hidden exploit. The campaign targeted government and multiple industries, then installed a stealthy browser-based implant…

July 30, 2026
Laundry Bear Uses “Half-Click” OWA Email Exploit

Laundry Bear Uses “Half-Click” OWA Email Exploit

UK and US cyber authorities and Proofpoint reported a real campaign where the Russian-linked group “Laundry Bear” (TA488) sent emails that could infect victims simply by being opened in Outlook Web Access. The email’s HTML triggers the server to run attacker code, installing a mailbox-stealing…

July 29, 2026
Telegram Dating Bot Used to Recruit Young Saboteurs

Telegram Dating Bot Used to Recruit Young Saboteurs

Russian authorities allege Telegram was used to recruit and pressure young people into real-world attacks, with “Ukrainian agents” posing as young women via a popular Telegram dating chatbot. The article describes a concrete manipulation workflow (romance/entrapment → coercion) that led to arrests…

July 29, 2026
TA488 Uses “Half-Click” OWA Emails to Persist

TA488 Uses “Half-Click” OWA Emails to Persist

Proofpoint reports a Russia-aligned espionage group (TA488) returned with a campaign that compromises on‑premises Outlook Web Access simply when a user opens an email in the reading pane. The attack uses a cross-site scripting flaw to run hidden JavaScript, install a browser-resident implant, and…

July 29, 2026
Dating Bot Used to Recruit Teens for Sabotage

Dating Bot Used to Recruit Teens for Sabotage

Russian authorities claim Ukrainian intelligence used Telegram, including a Tinder-like dating bot, to recruit Russians (including teenagers) for sabotage and arson inside Russia. The alleged approach involved operatives posing as young women online, building relationships, and then persuading or…

July 29, 2026
Telegram Dating Bot Used for Romance-to-Arson Scam

Telegram Dating Bot Used for Romance-to-Arson Scam

Russia’s FSB claims Ukrainian intelligence used a Telegram dating chatbot to deceive and psychologically pressure young Russians into sharing locations, clicking phishing links, and later carrying out arson or armed attacks. The alleged scheme started with romance-style outreach and payments via…

July 29, 2026
Fake Public Security App Spreads Android RAT

Fake Public Security App Spreads Android RAT

Researchers tied the Flying Eagle Android remote-access trojan to a fake “Public Security” service app aimed at Android users in China. The malicious app was reportedly distributed from a lookalike website and could steal payment credentials and remotely control infected phones. The tooling is…

July 29, 2026
PhantomEnigma Phishes via Hijacked .gov.br Sites

PhantomEnigma Phishes via Hijacked .gov.br Sites

Researchers describe a real phishing-driven malware operation ("PhantomEnigma") that abuses compromised Brazilian government websites and mailboxes to appear trustworthy. Victims are lured with fake law-enforcement style documents (e.g., “Ofício” summons or “Procuração Digital”) and pushed to…

July 28, 2026
QR-PDF Phishing Hits M365, MFA Bypass Surges

QR-PDF Phishing Hits M365, MFA Bypass Surges

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies,…

July 28, 2026
Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected…

July 28, 2026
Tax and SSA Phish Push Cruciferra Malware Loader

Tax and SSA Phish Push Cruciferra Malware Loader

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The campaigns used a “crypter” service called Cruciferra to hide malicious files and help malware run while avoiding detection. Targets included…

July 27, 2026
Zimbra Zero-Day Email: Preview Triggers Espionage

Zimbra Zero-Day Email: Preview Triggers Espionage

A Russia-aligned espionage group sent specially crafted HTML emails that could compromise vulnerable Zimbra webmail servers just by being opened or previewed, no link clicks or attachments needed. The exploit ran JavaScript inside the email body to steal mailbox data and credentials, then set up…

July 24, 2026
Fake Notepad++ Plugin Used in Ukraine Phish

Fake Notepad++ Plugin Used in Ukraine Phish

CERT-UA reports a real phishing campaign linked to Russia-aligned actor UAC-0099 targeting Ukrainian organizations. Victims receive an email with an image attachment that leads (via a link shortener) to a file-sharing download, where a disguised script installs a trojanized Notepad++ plugin and…

July 24, 2026
Laundry Bear Uses Zero-Click Zimbra Email Trap

Laundry Bear Uses Zero-Click Zimbra Email Trap

A newly identified Russia-linked threat actor (“Laundry Bear”) is targeting Western organisations with a zero-click technique that can compromise Zimbra webmail simply by viewing a malicious email. The campaign has reportedly stolen sensitive data across multiple sectors and may evolve to target…

July 24, 2026
Phishing Email Pushes Fake Notepad++ Plugin

Phishing Email Pushes Fake Notepad++ Plugin

CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP contains a script disguised as a PDF, which installs a malicious Notepad++ plugin and sets up an automated task that repeatedly runs malware…

July 24, 2026
TA488 “Half-Click” Emails Hack Zimbra Webmail

TA488 “Half-Click” Emails Hack Zimbra Webmail

A Russian-aligned group (TA488) used malicious emails to exploit a Zimbra webmail flaw so that simply opening or previewing a message triggered compromise, no link click or attachment required. The attackers then stole email data and set up persistent access to compromised mail servers, including…

July 23, 2026
Zero-Click Emails Hit Zimbra Users in Espionage Push

Zero-Click Emails Hit Zimbra Users in Espionage Push

Government agencies and security firms warn that Russia-aligned hackers are using “zero-click” phishing emails to compromise organizations using Zimbra webmail. The attack hides a malicious JavaScript payload inside an email so it runs when the message is opened, aiming to steal recent email,…

July 23, 2026
Try Mirage

Mirage simulates attacks like these against your own team, live and safely, so you can measure how your people actually respond.

Get a demo