Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecritical-infrastructure-threatperimeter-device-exposureactively-exploited-vulnerability

Weekly Cybersecurity Roundups Highlighting Government Campaigns, Nation-State Activity, and Emerging Vulnerabilities

Updated 3mo agoFirst seen Feb 21, 20264 sources

Multiple weekly cybersecurity roundups and newsletters highlighted a mix of policy, threat, and vulnerability developments rather than a single discrete incident. UK government messaging featured prominently, including a campaign urging businesses to “lock the door” against cyber criminals and publication of longitudinal survey results indicating most organizations continue to experience cyber incidents (with reported rates in the 70–80% range across businesses and charities). Separately, commentary from European security circles emphasized growing calls for offensive cyber capabilities (“strike back”) amid concerns about Russian aggression and sabotage activity across Europe, including references to cyber operations targeting critical infrastructure.

Threat reporting in the same period emphasized escalating nation-state and proxy activity against critical infrastructure and the defense industrial base, citing research that espionage groups (including those linked to China, Russia, and North Korea) have compromised organizations by exploiting zero-day vulnerabilities in edge devices (e.g., VPNs and gateways). Additional reporting pointed to newly identified OT-focused threat groups (e.g., Sylvanite, Azurite, Pyroxene) and a broad set of emerging technical risks and product/security changes, including discussion of an OpenSSL RCE risk, Foxit 0-days, and analysis of LockBit 5.0 ransomware techniques (e.g., ETW tampering, process hollowing, log clearing) alongside Android platform security changes (e.g., deprecating cleartext traffic defaults and adding HPKE support).

Share:
Weekly Cybersecurity Roundups Highlighting Government Campaigns, Nation-State Activity, and Emerging Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Feb 21, 20264mo ago

npm token compromise used to ship malicious CLI update

A compromised npm token was reportedly used to publish a malicious command-line tool update, underscoring software supply-chain risk. The incident was cited in a roundup focused on current developer ecosystem threats.

U.S. law enforcement disrupts North Korea-linked laptop farm scheme

Authorities took action against a 'laptop farm' operation that allegedly supported North Korean fraudulent IT worker activity. The case was highlighted as part of broader efforts to counter DPRK cyber-enabled revenue generation.

UNC6201 reportedly exploits Dell RecoverPoint zero-day

A suspected PRC-linked cluster tracked as UNC6201 was reported exploiting a Dell RecoverPoint zero-day and deploying multiple malware families. The disclosure added a new intrusion set and exploitation vector to current nation-state activity reporting.

Researchers link APT28 to spearphishing using spoofed Spanish government lures

Threat intelligence reporting described an alleged APT28 spearphishing campaign using macro-laced documents that spoofed Spanish government content. The activity was presented as part of ongoing nation-state operations across Europe.

UK officials reiterate need for stronger business cyber hygiene

UK government and NCSC messaging emphasized improving cyber hygiene for businesses, alongside survey findings that most UK organizations continue to experience cyber incidents. The statements were highlighted in a weekly government security summary.

Feb 19, 20264mo ago

Poland detains suspect tied to Phobos and 8Base investigations

Authorities in Poland detained an individual in connection with investigations into Phobos and 8Base cybercrime activity. The arrest was cited in multiple weekly roundups as a notable law-enforcement development.

Researchers report active exploitation of critical Ivanti EPMM flaws

Security reporting said critical remote code execution vulnerabilities in Ivanti Endpoint Manager Mobile were being actively exploited in the wild. Later roundup coverage also noted evidence that exploitation began before patches were released.

CISA adds GitLab SSRF vulnerability to KEV catalog

CISA added a GitLab server-side request forgery flaw to its Known Exploited Vulnerabilities catalog, signaling that defenders should prioritize remediation. The listing was noted as part of active exploitation and response activity.

Microsoft fixes Copilot bug that exposed DLP-protected email content

Microsoft remediated a Copilot issue that allowed access to email content protected by data loss prevention labels. The fix was highlighted in a weekly security roundup as a notable platform security response.

European and NATO officials push for more offensive cyber retaliation

European and NATO officials were reported to be increasingly calling for offensive cyber capabilities to 'strike back' at adversaries, driven largely by Russian aggression and sabotage activity across Europe. The discussion reflects a policy shift toward considering cyber retaliation as part of Europe’s response toolkit.

Google and OpenAI highlight growing concern over AI distillation attacks

Reporting said Google and OpenAI are warning that 'distillation' or model-extraction attacks are being used to copy proprietary AI model behavior. The disclosures framed model theft as an emerging security and policy issue for major AI providers.

OpenAI warns of AI model extraction attempts linked largely to China

OpenAI said adversaries are attempting to steal proprietary model behavior through large-scale querying and that much of the activity appears to originate from China. It also named DeepSeek as trying to circumvent its countermeasures and called for U.S. government support to protect frontier AI firms.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

158 LINKEDOpen in app
Affected products
24 linked
Claude CodeNotepad++ScreenconnectBitwardenDashlaneZoomMicrosoft Entra IdBitlockerGoogle MeetMetamaskAndroidAndroidTelegramDocusignDropbox SignMacosOpensslGitlabGoogle SearchIosOpensslMicrosoft 365 CopilotIosMacos
Organizations
78 linked
GoogleDeepseekGitLabSilverfortIntegoTP-LinkKasperskyIvantiOpenaiMicrosoft CorporationLogmeinDattoNotepad++DashlaneSocketLAB52Samsung ElectronicsSpecterOpsLastPassAnthropicZoom CommunicationsRecorded FutureDatadogHudson RockTikTokTrustedsecMeta PlatformsWIREDCellebriteProofpointConnectwiseBitwardenBitsightUniversal StudiosLRQAGraphikaConpetRunRevealRayzone GroupSony Group CorporationAppleTrend MicroApryseWells FargoGreyNoiseOpenSSL Software FoundationAcronisAtlassianFidelity InvestmentsPalo Alto NetworksSOCRadarHunt.ioCloudflareSekoiaDropboxDocuSignAISLEPenterarunZeroBridewellBooking.comFoxit SoftwareNameCheapPayPalHuntressTelegramMorphisecDragosUsaaMetamaskCitibankPoint WildIrregularOwnRegistrarINKYNovee SecurityAnzu RoboticsNavy Federal Credit Union
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.