Visualização normal

Ontem — 7 de Setembro de 2026Firewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • US Puts $10 Million Bounty on Alleged Iranian Cyber Chief Samiksha Jain
    The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers
     

US Puts $10 Million Bounty on Alleged Iranian Cyber Chief

7 de Setembro de 2026, 02:51

$10 Million Reward for Amir Yaryab

The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers, Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN). U.S. officials accuse these groups of using malware and conducting cyber and cyber-enabled information operations against civilian infrastructure worldwide.

$10 Million Reward for Amir Yaryab

The $10 million reward for Amir Yaryab seeks information leading to his identification or location. The offer applies to individuals acting at the direction or under the control of a foreign government who participate in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act. [caption id="attachment_113961" align="aligncenter" width="600"]$10 million reward for Amir Yaryab Image Source: https://rewardsforjustice.net/[/caption] Yaryab is also accused of directing Shahid Hemmat and Shahid Shushtari, two groups linked to cyberattacks against U.S. organizations. The sectors allegedly targeted include defense, news, shipping, travel, energy, financial services and telecommunications. The six Iranian officials named in the advisory are linked to Iran's Islamic Revolutionary Guard Corps and its Cyber-Electronic Command.

Iranian Cyberattacks Target PLCs

The allegations also involve attacks against programmable logic controllers (PLCs), highlighting concerns around Iranian cyberattacks targeting industrial systems rather than focusing only on data theft. U.S. officials said Iranian-linked hackers compromised industrial control systems, specifically targeting the Vision series of PLCs manufactured by Israel-based Unitronics. These devices are used across water and wastewater, energy, food and beverage, manufacturing and healthcare sectors. The attackers exploited default credentials on the devices and left anti-Israel messages. Some of the compromises reportedly rendered the PLCs inoperative. The CyberAv3ngers group, which is linked to the IRGC-CEC, claimed responsibility for attacks against Unitronics Vision PLCs in October 2023. Beginning in November 2023, the group compromised default credentials in PLCs across the United States and left messages on the devices' digital screens.

CyberAv3ngers Attacks Critical Infrastructure

CyberAv3ngers has also claimed responsibility for attacks affecting other infrastructure. In October 2023, the group claimed it had breached ORPAK Systems, a provider of gas station solutions in Israel. The group said it had obtained the company's database and intended to publish it through its Telegram channel. The attack was reported to have disconnected 200 gasoline pumps from the system in the occupied Palestinian territories. In December 2023, CyberAv3ngers also claimed to possess and sell 1TB of data allegedly linked to Israel's electricity infrastructure. The group advertised the dataset for 5 Bitcoin, with an initial 100GB portion also offered at the same price.

U.S. Agencies Warn of PLC Cyberattacks

Concerns over critical infrastructure attacks involving PLCs continued into 2026. A joint advisory issued on April 7 by the FBI, CISA, NSA and other agencies warned that Iran-linked threat actors were actively exploiting internet-facing PLCs. The advisory said several organizations had experienced operational disruptions and financial losses after attackers interfered with industrial processes. The developments come amid broader U.S. actions against Iranian-linked cyber activity. The Justice Department accused Iran-connected hackers of breaching employee email accounts associated with the Department of Labor, the Federal Energy Regulatory Commission and multiple United Nations organizations. The Treasury Department also sanctioned Iranian nationals over cyberattacks targeting critical infrastructure. The State Department's reward offer places Amir Yaryab and the alleged activities of IRGC-CEC-linked groups at the center of the U.S. effort to identify individuals responsible for malicious cyber activity targeting critical infrastructure.
Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed Samiksha Jain
    A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised. The Amsterdam-based retailer confirmed that customers can continue placing on
     

Amsterdam’s De Bijenkorf Hit by Logistics Cyberattack, Orders Delayed

De Bijenkorf cyberattack

A De Bijenkorf cyberattack involving one of the retailer's external logistics partners has disrupted order processing, returns, and refunds while raising concerns over potential customer data exposure. The Dutch luxury department store chain said the security incident occurred within the systems of a third-party logistics provider, adding that there is currently no evidence that its own infrastructure was compromised.

The Amsterdam-based retailer confirmed that customers can continue placing online orders and stores remain open. However, deliveries, returns, and refunds are expected to take longer than usual as the investigation continues.

De Bijenkorf Confirms Third-Party Security Incident

According to De Bijenkorf, unauthorized individuals gained access to part of its logistics partner's systems. The logistics provider responded by immediately blocking the unauthorized access and implementing additional security measures.

An external investigation is now underway to determine the cause of the incident, its scope, and whether customer information was affected.

As a precaution, De Bijenkorf has informed customers about the incident and submitted a report to the Dutch Data Protection Authority while awaiting the investigation's findings.

What Customer Data Could Be Affected in De Bijenkorf Cyberattack?

The retailer said investigators are still determining whether any personal information has been compromised.

Based on the information currently available, data that may be involved includes:

  • Customer names and contact details, including email addresses, postal addresses, and phone numbers.
  • Information related to online purchases, such as ordered products, pricing, discounts, delivery details, and the payment method used.
  • For business customers, company names and VAT numbers stored in My Account may also be involved.

De Bijenkorf emphasized that sensitive financial information is not part of the incident. The company said payment details, bank account numbers, credit card information, usernames, and passwords were not accessed.

Investigation Continues as Customers Await Confirmation

The retailer said it is still investigating whether individual customers have been affected. Customers whose information is confirmed to be involved will receive direct communication via email from info@debijenkorf.nl.

For those who have not yet received a notification, the company said it cannot currently rule out the possibility that their information was included in the incident until the investigation is completed.

De Bijenkorf also stressed that no login credentials were compromised, meaning unauthorized individuals cannot access customer accounts using stolen usernames or passwords.

Retailer Warns Customers About Phishing Risk

Although the investigation remains ongoing, De Bijenkorf warned customers to stay alert for a possible phishing risk if personal information is ultimately found to have been exposed.

The retailer advised customers not to click on suspicious links or open unexpected attachments. It also reminded customers never to share passwords, payment information, or personal details through email or phone calls.

The company said it will never request credit card details, gift card information, or other sensitive information via email.

Logistics Cyberattacks Continue to Disrupt Supply Chains

The incident adds to a growing list of attacks targeting organizations that support retail operations rather than retailers directly. A logistics cyberattack can interrupt deliveries, returns, and customer service even when the affected retailer's own systems remain operational.

In July 2026, a ransomware attack on Japan's largest refrigerated logistics company disrupted food deliveries across the country, causing supply shortages for restaurant chains, including Kentucky Fried Chicken. The incident demonstrated how cyberattacks on logistics providers can quickly impact downstream retail operations and customer services.

For now, De Bijenkorf said its stores remain open, online ordering continues to operate, and there are no indications that its own systems have been compromised. The retailer said it will provide additional updates as the external investigation establishes whether customer data was affected and the full extent of the incident.

The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats

The Cyber Express weekly Roundup July 2026 new

This weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses.  The latest developments show that cyber risks are expanding beyond traditional network attacks. Threat actors are targeting identities, trusted platforms, software supply chains, and operational technology environments. Organizations must strengthen security controls, improve monitoring capabilities, and adopt proactive measures to protect sensitive data and critical services. 

The Cyber Express Weekly Roundup 

Four Men Admit to $2.2 Million Medicaid Fraud Scheme Using AI 

Four Minnesota men have pleaded guilty in connection with a Medicaid fraud scheme that allegedly generated approximately $2.2 million through fraudulent claims for housing-related services. Prosecutors stated that artificial intelligence tools, including ChatGPT, were used to create false documentation supporting fraudulent billing activity. Read more... 

Tribeca Data Leak Exposes Celebrity-Linked Information 

A reported data leak connected to the Tribeca Film Festival exposed nearly 666,000 records containing personal information associated with attendees, contacts, and individuals linked to the entertainment industry. The exposed data reportedly included names, email addresses, phone numbers, and limited device-related information. Read more... 

Origin Energy Data Breach Impacts Around 900,000 Customers 

Australian energy company Origin Energy confirmed a data breach affecting approximately 900,000 current and former customers. The exposed information may include customer names, contact details, dates of birth, and partial account information. The company is investigating the incident and has advised customers to remain alert for possible scams or suspicious communications. Read more... 

Joyfill npm Packages Found Distributing DEV#POPPER Malware 

Security researchers discovered that two beta versions of Joyfill npm packages were distributing DEV#POPPER, a remote access trojan (RAT) capable of stealing information, executing commands, and compromising developer environments. Read more... 

Student Accused of IIT Website Breaches Offered Technical Assessment 

A student accused of breaching parts of the IIT Kanpur and IIT Madras websites after being rejected from IIT Kanpur’s cybersecurity program will undergo a technical skills assessment rather than facing immediate legal action. The institute stated that admissions for the current session are closed but indicated that future opportunities may be considered if the student demonstrates strong cybersecurity abilities. Read more... 

FBI Warns of PLC Cyberattacks Targeting U.S. Water Utilities 

The FBI and the U.S. Environmental Protection Agency warned that cyberattacks targeting internet-connected programmable logic controllers (PLCs) have disrupted water utilities across multiple U.S. states. Attackers reportedly manipulated PLC settings, affecting monitoring and operational processes. Read more... 

Weekly Cybersecurity Takeaway

This week’s incidents demonstrate how cyber threats continue to evolve across multiple domains, including artificial intelligence abuse, personal data exposure, software supply chain attacks, and critical infrastructure targeting.  A common theme across these events is the exploitation of trust. Attackers are abusing trusted technologies, legitimate software ecosystems, customer databases, and connected infrastructure to achieve their objectives.  Organizations must focus on building cyber resilience through stronger identity protection, secure development practices, continuous monitoring, and effective incident response planning.  As emerging technologies such as artificial intelligence and connected industrial systems become more widespread, cybersecurity strategies must evolve alongside them. Protecting digital assets requires not only stronger technical defenses but also responsible for technology use, awareness, and proactive risk management. 
  • ✇Firewall Daily – The Cyber Express
  • Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA Samiksha Jain
    Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States. Accordin
     

Ukraine Makes History With First $8.3M Seized Crypto Transfer to ARMA

Seized Crypto Assets

Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States.

According to Ukrainian authorities, the transferred cryptocurrency is valued at more than 372 million hryvnias and represents a milestone in the country's efforts to manage digital assets linked to criminal investigations.

Seized Crypto Assets Moved to ARMA After Court Order

The State Bureau of Investigation said the transfer was completed as part of an ongoing criminal investigation conducted in cooperation with the DVB of the National Police and U.S. law enforcement agencies.

Investigators determined that the virtual assets were stored in crypto wallets controlled by a member of the organized hacking group. Following a court order, more than 8.3 million USDT was transferred to ARMA's official crypto wallet.

Authorities said this is the first practical case in Ukraine where seized digital assets have been transferred to ARMA for management, demonstrating the country's ability to handle new categories of assets within the legal system.

Investigation Links Cryptocurrency to International Hacking Group

According to investigators, members of the international hacking group carried out large-scale cyberattacks against individuals and companies in Europe and the United States.

The investigation alleges the group stole confidential information, demanded ransom payments, and laundered criminal proceeds in Ukraine through the purchase of residential properties, vehicles, and other high-value assets.

Authorities estimate that the criminal group's activities caused losses exceeding $100 million.

As part of the pre-trial investigation, four members of the group, including its alleged organizer, were detained and placed in custody.

More Than $11 Million in Assets Seized

The investigation resulted in the cryptocurrency seizure and the confiscation of additional assets with a combined value exceeding $11.1 million.

According to the State Bureau of Investigation, the seized property includes residential buildings, apartments, vehicles, approximately $1 million in cash, and digital assets equivalent to more than $8.3 million.

The Office of the Prosecutor General is providing procedural oversight for the criminal proceedings.

Authorities Plan to Convert Crypto Into Military Bonds

The State Bureau of Investigation said that after converting the cryptocurrency into fiat currency, authorities plan to purchase military bonds.

According to the agency, the initiative is intended to support Ukraine's economy during martial law while ensuring that assets obtained through criminal activity are redirected for state purposes.

Officials described countering transnational cybercrime and ensuring effective mechanisms for the seizure and management of criminal assets as key priorities.

ARMA Expands Digital Asset Management

ARMA said receiving the cryptocurrency marks an important step in the evolution of Ukraine's asset management system.

The agency stated that the successful transfer reflects coordinated efforts between the State Bureau of Investigation and the Office of the Prosecutor General, enabling the execution of the court's decision and preserving the value of the seized assets.

ARMA added that it is continuing to develop mechanisms for managing all categories of seized property, including real estate, corporate rights, and virtual assets, to ensure their preservation in the interests of the state and society.

The agency said the case demonstrates that as cybercriminals increasingly use digital technologies to conceal illicit proceeds, authorities must also strengthen their ability to manage and preserve cryptocurrency and other digital assets seized during criminal investigations.

  • ✇Firewall Daily – The Cyber Express
  • US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks Ashish Khaitan
    The U.S. telecom sector is strengthening its cybersecurity coordination efforts with the launch of a new private ISAC designed to help major communications companies respond more effectively to AI-powered cyberattacks, state-backed espionage campaigns, and emerging threats targeting national communications infrastructure.  The Communications Cybersecurity Information Sharing and Analysis Center, known as the C2 ISAC, was created by some of the country’s largest telecommunications providers to
     

US Telecom Giants Launch Private ISAC to Counter AI-Powered Cyberattacks

private ISAC

The U.S. telecom sector is strengthening its cybersecurity coordination efforts with the launch of a new private ISAC designed to help major communications companies respond more effectively to AI-powered cyberattacks, state-backed espionage campaigns, and emerging threats targeting national communications infrastructure.  The Communications Cybersecurity Information Sharing and Analysis Center, known as the C2 ISAC, was created by some of the country’s largest telecommunications providers to establish a more confidential environment for exchanging cybersecurity intelligence. The founding members include AT&T, Charter, Comcast, Cox, Lumen, T-Mobile, Verizon, and Zayo. The chief information security officers from these companies will serve on the organization’s board.  The newly formed private ISAC will be led by Valerie Moon, a former senior official with both the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI’s Cyber Division, who has been appointed executive director.  According to Mark Clancy, chief security officer at T-Mobile and a board member of the C2 ISAC, the evolving threat landscape was a major factor behind the creation of the private ISAC.  “The main driver for us is our recognition that the threat environment has evolved, and we as a sector and private entities need to evolve and really keep up with the pace and velocity [at which] that’s happening,” Clancy said in an interview with Cybersecurity Dive.  Clancy explained that telecom companies recognized the need for more direct collaboration during the industry’s response to Salt Typhoon. “The need for us to collaborate on a private-to-private basis really became amplified,” he added. 

Telecom Sector Pushes for Faster Intelligence

Although the telecom sector already participates in information-sharing initiatives through the Communications ISAC, also referred to as the National Coordinating Center for Communications, that organization differs from most ISACs because it operates within the federal government under CISA rather than as an independent private entity.  According to Clancy, that government affiliation created hesitation among some telecom companies when it came to sharing sensitive cybersecurity intelligence.  “There’s been concerns and hesitations about it,” he said.  The new private ISAC aims to address those concerns by limiting participation to industry members and excluding government agencies from its internal discussion channels. Organizers believe this structure will encourage companies to exchange threat intelligence more openly and at earlier stages of investigations.  “When you have public-sector entities involved, there’s more review and deliberation about what gets put into that channel,” Clancy explained, adding that the new arrangement allows companies to be “a little more raw and early in sharing information.”  Over time, telecom providers realized they had become overly cautious in the information they shared through the existing Communications ISAC. Clancy acknowledged that companies often withheld lower-level threat indicators that later turned out to be connected to broader malicious campaigns.  “We were being too restrictive in what we were sharing,” he said, noting that some seemingly isolated activities were “actually tethered to bigger activity.”  Moon emphasized that the private ISAC is not intended to replace the existing Communications ISAC. Instead, both organizations are expected to operate alongside each other, with the older structure continuing to focus on broader operational concerns such as physical infrastructure threats.  “We really see this as a complementary effort,” Moon said. “When you think about each of these companies and their adherence to ensuring that the privacy of their data is very much at the forefront of their minds, they see this as a trusted space.” 

Private ISAC May Expand Beyond Threat Sharing

Information-sharing efforts within the telecom sector have already proven valuable in combating cybercrime and network abuse. One example involved the detection of SIM boxes — devices commonly used by cybercriminals to generate large volumes of difficult-to-block spam calls and text messages.  After T-Mobile identified indicators connected to SIM box activity, the company shared those findings with other telecom providers, enabling them to locate and block similar operations on their own networks.  Clancy noted that addressing such threats requires coordinated action because malicious infrastructure often spans multiple providers. “In order to figure out what’s happening, you’ve got to look at both sides,” he said.  Beyond direct threat intelligence, telecom companies have also exchanged operational strategies and defensive techniques through existing partnerships. Clancy recalled learning an effective method for handling residential proxy networks from another telecom operator.  “I learned a technique for dealing with some of the residential proxy networks from another operator that was really clever,” he said. “And I’m, like, ‘Yeah, we’re going to go do that.’”  While the immediate focus of the private ISAC is improving information sharing related to AI-powered cyberattacks and network threats, its leaders are also considering broader future capabilities. Clancy suggested the group could eventually develop shared automation platforms and collaborative technologies that would be easier to coordinate privately than through government-led regulatory frameworks.  The organization may also explore involvement in coordinated cybersecurity operations such as botnet disruptions, though Moon said those discussions are still in early stages.  “It just depends on what the operation is and where the authorities lie and what we are trying to accomplish,” she said.  Moon described the private ISAC as being “in its nascent stages,” adding that several long-term objectives remain under discussion.  Membership expansion is another unresolved issue. Although the current founding members represent some of the largest companies in the telecom sector, Clancy acknowledged that broader participation will be necessary for maximum effectiveness.  “There are more than eight companies in the communications sector, and so we won’t be fully effective until we increase that membership base,” he said.  The launch of the private ISAC also coincides with significant uncertainty surrounding federal cybersecurity programs. Budget reductions, staffing cuts, and shifting priorities across government agencies have forced many private-sector organizations to reconsider how they coordinate cybersecurity defense efforts.  “Obviously, what’s happening in the public sector informs what we need to do,” Clancy said, referencing challenges involving government funding, agencies, and legislative processes.  He also encouraged the Department of Homeland Security to accelerate efforts to replace the now-defunct Critical Infrastructure Partnership Advisory Council framework, which previously supported confidential discussions between industry and government stakeholders. Despite operating independently, the private ISAC still plans to maintain communication with federal agencies. According to Clancy, the group intends to share relevant intelligence either directly with government partners or through the existing Communications ISAC framework. “We could have a more freewheeling private-to-private conversation [and] we could distill the useful, important bits and push them … over to the government side,” he said.
  • ✇Firewall Daily – The Cyber Express
  • AI Cyberattacks Are Escalating Across the Americas. This Webinar Explains Why Samiksha Jain
    The Americas cyber threat landscape saw a significant rise in AI-powered cyberattacks, ransomware campaigns, and critical infrastructure targeting during the first quarter of 2026, reflecting how rapidly cyber threats are evolving across the region. Security researchers observed that threat actors increasingly used generative AI to automate phishing campaigns, create convincing deepfakes, and accelerate exploitation techniques. At the same time, ransomware groups, hacktivists, and nation-stat
     

AI Cyberattacks Are Escalating Across the Americas. This Webinar Explains Why

Americas cyber threat landscape

The Americas cyber threat landscape saw a significant rise in AI-powered cyberattacks, ransomware campaigns, and critical infrastructure targeting during the first quarter of 2026, reflecting how rapidly cyber threats are evolving across the region. Security researchers observed that threat actors increasingly used generative AI to automate phishing campaigns, create convincing deepfakes, and accelerate exploitation techniques. At the same time, ransomware groups, hacktivists, and nation-state actors intensified attacks against organizations operating in healthcare, manufacturing, utilities, energy, and government sectors across North and Latin America. To help cybersecurity professionals better understand these evolving risks, Cyble will host a live webinar on May 28, 2026, focused on the key cyber threats, adversary tactics, and emerging attack trends shaping the Americas cyber threat landscape in Q1 2026. Americas cyber threat landscape

AI-Powered Cyber Threats Continue to Grow

One of the most notable developments during Q1 2026 was the increasing use of artificial intelligence by cybercriminals and advanced threat groups. Threat actors are now leveraging generative AI to produce highly targeted phishing emails, fake identities, deepfake content, and automated social engineering campaigns at scale. Security analysts warn that these AI-driven techniques are making attacks more difficult to identify and increasing the success rate of phishing and credential theft operations. Researchers also observed that attackers are using AI to accelerate reconnaissance and exploitation activities, enabling cybercriminals to move faster and target larger numbers of victims simultaneously. As AI-powered attacks become more sophisticated, organizations are facing growing pressure to strengthen detection capabilities and improve incident response readiness.

Critical Infrastructure Remains a Primary Target

The Americas cyber threat landscape also highlighted the continued targeting of critical infrastructure sectors during Q1 2026. Healthcare providers, energy operators, utilities, manufacturing organizations, and public sector institutions experienced persistent cyber threats from ransomware operators, hacktivist groups, and nation-state actors. Security researchers noted increasing concerns around operational technology environments and attacks designed to disrupt essential services. Supply chain vulnerabilities and third-party risks also remained major challenges for organizations responsible for maintaining critical infrastructure. Experts believe these attacks are no longer solely focused on financial extortion. Many campaigns are increasingly linked to geopolitical tensions, intelligence gathering, and disruption-focused objectives targeting national infrastructure and strategic industries. Cybersecurity professionals looking for deeper insights into infrastructure threats and AI-driven attack trends can register for the upcoming webinar hosted by Cyble.
Register Here

Nation-State Cyber Operations Intensify

Threat intelligence findings from Q1 2026 also revealed growing activity from nation-state groups associated with China, Russia, Iran, and North Korea. These groups continued targeting organizations across the Americas through espionage campaigns, vulnerability exploitation, credential theft, and malware deployment. Researchers observed that government entities, infrastructure operators, and large enterprises remained among the primary targets of these advanced cyber operations. Security experts warn that geopolitical developments continue to influence cyber activity, increasing the need for organizations to monitor emerging risks and strengthen resilience against sophisticated attacks.

Ransomware and Dark Web Activity Continue

Despite the growing attention around AI-driven threats, ransomware remained one of the most disruptive elements of the Americas cyber threat landscape in Q1 2026. Threat actors continued targeting organizations across multiple industries using double extortion tactics, data theft, and operational disruption strategies. Researchers also identified ongoing activity across dark web marketplaces and underground forums supporting cybercriminal operations through the sale of stolen credentials, access data, and attack tools. Hacktivist groups also remained active during the quarter, particularly in campaigns linked to political and regional conflicts. Security teams are increasingly prioritizing real-time threat intelligence and attack surface visibility to identify risks earlier and respond more effectively to emerging threats. The upcoming webinar will feature insights from Kaustubh Medhe, Head of Research & Intelligence at Cyble, Brian Osterman, Senior Solutions Engineer for the US region, and moderator Mihir Bagwe. The session will explore ransomware trends, AI-powered attacks, nation-state cyber operations, and practical recommendations for strengthening cyber resilience in 2026. Registered attendees will also receive a complimentary copy of the Americas Threat Landscape Report – Q1 2026. Webinar Details Date: Wednesday, May 28, 2026 Time: 1:00 PM ET Duration: 45 Minutes

Registration Link: Click Here

CISA Launches CI Fortify to Defend Critical Infrastructure From Nation-State Cyber Threats

CI Fortify

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new initiative called “CI Fortify” aimed at helping critical infrastructure operators prepare for disruptive cyberattacks linked to geopolitical conflicts. The initiative comes amid growing concerns over nation-state cyber threats targeting operational technology (OT) systems that support essential services across the United States. The CI Fortify initiative focuses on improving critical infrastructure resilience through two key objectives: isolation and recovery. CISA said the effort is designed to help operators maintain essential operations even if adversaries compromise telecommunications networks, internet services, or industrial control systems. According to the agency, nation-state actors are no longer limiting their activities to espionage. Instead, threat groups have increasingly been pre-positioning themselves inside critical infrastructure environments to potentially disrupt or destroy systems during future geopolitical conflicts.

CI Fortify Initiative Focuses on Isolation and Recovery

Under the CI Fortify initiative, CISA is urging critical infrastructure organizations to assume that third-party communications and service providers may become unreliable during a crisis. Operators are also being asked to plan under the assumption that threat actors may already have some level of access to OT networks. Nick Andersen, Acting Director at CISA, emphasized the need for organizations to prepare for worst-case operational scenarios. “In a geopolitical crisis, the critical infrastructure organizations Americans rely on must be able to continue delivering, at a minimum, crucial services,” Andersen said. “They must be able to isolate vital systems from harm, continue operating in that isolated state, and quickly recover any systems that an adversary may successfully compromise.” The isolation strategy outlined under CI Fortify involves proactively disconnecting operational technology systems from external business networks and third-party connections. CISA said this approach is intended to prevent cyber impacts from spreading into OT environments while allowing organizations to continue delivering essential services in a degraded communications environment. The agency advised operators to identify critical customers, including military infrastructure and other lifeline services, and determine the minimum operational capabilities needed to support them during emergencies. CISA also recommended updating engineering processes and business continuity plans to support safe operations for extended periods while systems remain isolated.

Recovery Planning Central to Critical Infrastructure Resilience

Alongside isolation, the CI Fortify initiative places strong emphasis on recovery planning. CISA urged operators to maintain updated system documentation, create secure backups of critical files, and regularly practice system replacement or manual operational transitions. The agency noted that organizations should also identify communications dependencies that could complicate recovery efforts, such as licensing servers, remote vendor access, or upstream network connections. CISA encouraged operators to work closely with managed service providers, system integrators, and vendors to understand potential failure points and establish alternative recovery pathways. The initiative also highlights broader benefits of emergency planning beyond cybersecurity incidents. According to CISA, the same planning processes can help organizations maintain operations during weather-related disruptions, equipment failures, and safety emergencies. The agency said isolation planning can help cut off command-and-control access to compromised systems, while strong recovery preparation can reduce incident response costs and shorten recovery timelines.

Security Vendors and Service Providers Asked to Support CI Fortify

The CI Fortify initiative extends beyond infrastructure operators and calls on cybersecurity vendors, industrial automation suppliers, and managed service providers to support resilience planning efforts. Industrial control system vendors are being encouraged to identify barriers that could interfere with isolation and recovery procedures, including licensing restrictions and server dependency issues. Managed service providers and integrators are expected to assist organizations in engineering updates, local backup collection, and recovery documentation planning. Meanwhile, security vendors are being asked to support threat monitoring and provide intelligence if nation-state actors shift from espionage-focused activity to destructive cyber operations. CISA also requested vendors share information related to tactics that could undermine recovery or bypass isolation protections, including malicious firmware updates and vulnerabilities affecting software-based data diodes.

Volt Typhoon Cyberattacks Continue to Shape U.S. Cybersecurity Strategy

The launch of CI Fortify is closely tied to ongoing concerns surrounding the Volt Typhoon cyberattacks, which U.S. officials have linked to Chinese state-sponsored threat actors. CISA’s initiative specifically references the Volt Typhoon campaign as an example of how adversaries have attempted to establish long-term access inside U.S. critical infrastructure systems to potentially support disruptive actions during military conflicts. The Volt Typhoon operation first became public in 2023, when U.S. authorities revealed that Chinese hackers had infiltrated multiple sectors of American critical infrastructure. Former CISA Director Jen Easterly stated in 2024 that the agency had identified and removed Volt Typhoon intrusions across several sectors. She later reiterated in 2025 that efforts continued to focus on identifying and evicting Chinese cyber actors from critical infrastructure environments. Despite these operations, cybersecurity researchers and some government officials have warned that Chinese threat actors may still retain access to portions of critical infrastructure networks. Several experts have argued that nation-state groups remain deeply embedded in certain environments despite years of remediation efforts. With the CI Fortify initiative, CISA appears to be shifting focus toward operational resilience, recognizing that prevention alone may not be sufficient against sophisticated nation-state cyber threats targeting U.S. critical infrastructure.
  • ✇Firewall Daily – The Cyber Express
  • CERT-In Warns of AI-Driven Cyber Threat Surge, MSMEs at Highest Risk Ashish Khaitan
    India’s cybersecurity watchdog, CERT-In, has raised concerns of the nature of modern cyber threats, particularly those driven by artificial intelligence. In its latest advisory, the cybersecurity watchdog has highlighted how frontier AI technologies are reshaping the threat landscape, making cyberattacks faster, more scalable, and far more accessible, even to less skilled attackers. The warning places a special emphasis on Micro, Small, and Medium Enterprises (MSMEs), which are becoming prim
     

CERT-In Warns of AI-Driven Cyber Threat Surge, MSMEs at Highest Risk

CERT-In advisory

India’s cybersecurity watchdog, CERT-In, has raised concerns of the nature of modern cyber threats, particularly those driven by artificial intelligence. In its latest advisory, the cybersecurity watchdog has highlighted how frontier AI technologies are reshaping the threat landscape, making cyberattacks faster, more scalable, and far more accessible, even to less skilled attackers. The warning places a special emphasis on Micro, Small, and Medium Enterprises (MSMEs), which are becoming prime targets due to their comparatively weaker security frameworks.  According to CERT-In, the rise of AI-powered tools marks a significant turning point in how cyberattacks are conceived and executed. What once required advanced technical expertise and hours of manual effort can now be accomplished in a fraction of the time through automation. The cybersecurity watchdog noted that modern AI systems are capable of independently scanning large volumes of source code, identifying deeply embedded vulnerabilities, and even launching coordinated, multi-stage cyberattacks. This shift has introduced what the agency describes as an era of “automation and scale” in cybercrime. 

From Manual Intrusion to AI-led Cyberattacks 

CERT-In’s advisory explains that traditional hacking methods involve painstaking manual processes and highly specialized knowledge. Attackers would typically spend hours, if not days, probing systems for weaknesses before exploiting them. However, AI has fundamentally altered this dynamic. Frontier AI systems can now detect “zero-day” vulnerabilities, previously unknown flaws, in mere seconds.  More concerning is the ability of these systems to “chain” multiple vulnerabilities together. By linking weaknesses across different applications or platforms, attackers can orchestrate comprehensive attacks that compromise entire networks from end to end. This level of sophistication was once limited to highly skilled professionals or state-sponsored actors. Today, however, the cybersecurity watchdog warns that such capabilities are accessible, effectively lowering the barrier to entry for cybercriminals. 

MSMEs Under Heightened Risk 

The advisory stresses that MSMEs are particularly vulnerable in this new threat environment. Unlike large enterprises, MSMEs often operate with limited budgets and lack dedicated cybersecurity teams or advanced monitoring systems. This makes it easier for attackers to leverage AI-driven tools.  CERT-In has pointed out that because AI simplifies and automates many aspects of cyberattacks, even individuals with minimal technical expertise can now carry out highly precise and damaging operations. As a result, MSMEs face a disproportionate level of risk. A successful breach could lead to severe consequences, including data theft, operational disruptions, or ransomware attacks that many smaller businesses are ill-prepared to manage.  The cybersecurity watchdog has cautioned that without immediate and meaningful improvements in their security posture, MSMEs could suffer significant financial and reputational damage. The growing accessibility of AI-powered attack tools means that the threat is no longer hypothetical but immediate and widespread. 

Recommended Security Measures 

In response to these emerging risks, CERT-In has outlined several critical steps that organizations, especially MSMEs, should take to strengthen their defenses. One of the primary recommendations is the deployment of robust threat detection systems combined with continuous network monitoring. These measures can help identify unusual activity early and prevent attacks from escalating.  Another key focus area highlighted by the cybersecurity watchdog is patch management. As AI tools enable attackers to quickly identify and exploit unpatched vulnerabilities, delays in updating software can create significant security gaps. CERT-In stresses that the timely application of patches is essential to minimizing exposure.  Additionally, maintaining comprehensive system logs is strongly advised. Detailed logs play a crucial role in forensic investigations, helping organizations understand how an attack occurred and what vulnerabilities were exploited. This information is vital for preventing future incidents and strengthening overall cybersecurity resilience. 

The Cyber Express Weekly Roundup: Data Breaches, Malware Campaigns, and Cyber Fraud Investigations

weekly roundup TCE cybersecurity news

In this week’s edition of The Cyber Express weekly roundup, we explore the latest developments in the world of cybersecurity, focusing on high-profile data breaches, growing malware campaigns, and law enforcement actions against cybercriminals.   As the digital threat landscape continues to evolve, attackers are targeting sensitive personal and organizational data, from health records to financial credentials. Meanwhile, government regulators are ramping efforts to protect minors and combat harmful content on social platforms, while cybercriminals continue to exploit vulnerabilities in both public and private sectors.  This weekly roundup highlights how various industries, from healthcare and social media to finance and government, are grappling with rising threats, making it clear that the intersection of data security, regulation, and cybercrime is more critical than ever.  

The Cyber Express Weekly Roundup 

UK Biobank Data Breach Triggers Urgent Review of Data Security Measures 

A significant data breach at the UK Biobank has raised major concerns over the security of health-related data used in scientific research. In April 2026, de-identified participant information was discovered being sold on a Chinese consumer platform, sparking widespread alarm among the research community. Read more... 

Vercel CEO Reveals Expansion of Malware Campaign Affecting Multiple Targets 

Vercel's CEO, Guillermo Rauch, confirmed that the recent breach involving Context.ai was part of a much larger malware campaign affecting multiple targets. Following a review of network logs, Vercel’s security team uncovered evidence of malware distribution that compromised several customer accounts, including access to valuable Vercel account keys. Read more... 

Ofcom Investigates Telegram and Teen Platforms 

In the UK, Ofcom has launched an investigation into Telegram and several popular teen chat platforms, such as Teen Chat and Chat Avenue, after reports surfaced of online grooming and child sexual abuse material (CSAM) on these services. Under the Online Safety Act, platforms are required to take proactive steps to prevent harmful content and protect minors from exploitation. Read more... 

Personal Data Exposed in Breach of France’s ANTS Portal 

A recent breach of France’s ANTS (Agence Nationale des Titres Sécurisés) portal has compromised personal data, including names, email addresses, and birthdates, although no documents or sensitive attachments were affected. The breach, which occurred on April 15, 2026, raises significant concerns about identity theft and phishing risks, as the exposed data could be used to target individuals. Read more... 

Bluesky Faces Coordinated DDoS Attack 

Bluesky, the rapidly expanding social media platform, suffered a major disruption on April 15, 2026, when it was targeted by a sophisticated distributed denial-of-service (DDoS) attack. The attack caused widespread outages, impacting core platform functions such as user feeds, notifications, and search capabilities. Read more... 

Indian Authorities Arrest Key SIM Card Supplier in Cyber Fraud Crackdown 

India’s Central Bureau of Investigation (CBI) has arrested a key conspirator in a major cyber fraud operation as part of Operation Chakra-V. The suspect, arrested in Guwahati, is accused of supplying fraudulent SIM cards used in various cybercrime schemes, including extortion and fake loan scams. The SIM cards were acquired using fake identities and distributed to cybercriminal networks. Read more... 

Weekly Takeaway 

This week’s roundup highlights the diverse and evolving nature of cyber threats. From the exposure of sensitive health data and sophisticated malware campaigns to DDoS attacks and SIM card fraud schemes, the cybersecurity landscape remains fraught with challenges. Regulatory bodies and companies alike continue to grapple with emerging risks, particularly in sectors like public health data, social media platforms, and digital content safety. As these incidents unfold, it’s clear that both technical vulnerabilities and human factors, such as social engineering, continue to be central targets for attackers.  With regulatory frameworks like the Online Safety Act and increased investigative efforts in places like India and France, the pressure on platforms and authorities to act quickly and decisively is higher than ever. As the cyber threat landscape becomes more interconnected, the need for enhanced security protocols, improved monitoring, and greater accountability in digital spaces remains critical. 
❌
❌