Response to CISA Advisory (AA25-343A): Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure

CISA, the FBI, the NSA, and partner agencies released a joint Cybersecurity Advisory on December 9, 2025, warning that pro‑Russia hacktivist groups are exploiting minimally secured, internet‑facing VNC connections to access OT/ICS devices in critical infrastructure sectors including Water and Wastewater, Food and Agriculture, and Energy. The advisory names groups such…

Read More
Cybersecurity News | Daily Recap [10 Dec 2025]

Daily Recap, Microsoft released its December security updates addressing 56–57 flaws, including 3 zero-days and active exploits, while Adobe patched nearly 140 vulnerabilities and SAP and other vendors issued urgent fixes. Threat actors and incidents highlighted include North Korea-linked React2Shell operators exploiting to deploy new EtherRAT variants, CastleLoader/CastleRAT under GrayBravo expanding its infrastructure targeting logistics and transport, Storm-0249’s stealthy ransomware tactics, and high-profile breaches and investigations involving Coupang, HSE, and the Khashoggi spyware allegations. #EtherRAT #CastleLoader

Read More
DOJ, CISA warn of Russia-linked attacks targeting meat processing plants, nuclear regulatory entities and other critical infrastructure

U.S. agencies have issued warnings about cyberattacks against critical infrastructure by Russian-backed groups such as CARR and NoName057(16). These groups have targeted sectors like water, energy, and food, with some attacks causing physical damage and operational disruptions. #CARR #NoName057(16)…

Read More
Ukrainian hacker charged with helping Russian hacktivist groups

U.S. authorities have charged a Ukrainian hacker, Victoria Dubranova, for her involvement in cyberattacks supporting Russian hacktivist groups targeting critical U.S. infrastructure such as water systems, election sites, and nuclear facilities. These groups, notably CARR and NoName057(16), carried out damaging DDoS attacks, breaching vital systems and endangering public safety. #CARR #NoName057(16) #U.S.CriticalInfrastructure #RussianHacktivists

Read More
Why a secure software development life cycle is critical for manufacturers

The Jaguar Land Rover cyberattack highlighted the critical vulnerabilities in manufacturing supply chains, especially through compromised third-party software. Ensuring strict secure software development practices and certifications like IEC 62443-4-1 can help prevent similar catastrophic breaches. #JaguarLandRover #SupplyChainSecurity #SSDLCL #IEC62443

Read More
US extradites member of Russian hacktivist group involved in critical infrastructure attacks

A Ukrainian national was extradited to the U.S. and charged with involvement in Russian hacktivist groups CARR and NoName057(16), which are financially supported by the Russian government. The groups have launched DDoS attacks and cyber intrusions supporting Russia’s geopolitical interests, including tampering with public water systems. #CyberArmyofRussia_Reborn #NoName057(16) #RussianHackers #CriticalInfrastructureAttacks…

Read More
US Indicts Extradited Ukrainian on Charges of Aiding Russian Hacking Groups

A Ukrainian woman, Victoria Dubranova, faces charges in the US for her alleged involvement with pro-Russia hacktivist groups CARR and NoName057(16), responsible for numerous cyberattacks worldwide. These groups, linked to Russian military intelligence, targeted critical infrastructure and government entities, with US authorities offering substantial rewards for information. #CyberArmyofRussia_Reborn #NoName057(16) #GRU…

Read More

The U.S. Department of Justice has taken action against Russian cyber groups CARR and NoName057(16), accusing them of targeting critical infrastructure globally on Moscow’s behalf. Key figures like Ukrainian national Victoria Dubranova face charges, with ongoing trials and international law enforcement collaboration. #CARR #NoName057(16) #VictoriaDubranova…

Read More
APT PROFILE – GROUP 123

Group123 is a North Korean state-sponsored APT active since at least 2012 that conducts espionage across East and Southeast Asia, the Middle East, and beyond using spear‑phishing, malicious documents (including HWP), drive‑by exploits, and a large toolkit of loaders and implants to gain persistent access. Recent campaigns show intensified Windows-focused intrusions, advanced defense-evasion (DLL sideloading, hollowing, sandbox checks), cloud‑based C2, and a partial shift toward revenue generation including use of Maui ransomware. #Group123 #ROKRAT

Read More
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Rockwell, Schneider

Industrial leaders Siemens, Schneider Electric, Rockwell Automation, and Phoenix Contact release Patch Tuesday advisories revealing critical and high-severity vulnerabilities in their ICS/OT products. These flaws enable remote code execution, DoS, and man-in-the-middle attacks, threatening critical infrastructure security. #SiemensVulnerabilities #OTSecurity…

Read More
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure

U.S. and international agencies assess that pro‑Russia hacktivist groups—including Cyber Army of Russia Reborn (CARR), NoName057(16), Z‑Pentest, and Sector16—are conducting opportunistic intrusions against critical infrastructure by scanning for internet‑facing VNC services and exploiting default or weak credentials to access HMI/OT devices. These unsophisticated but impactful operations involve VPS‑based brute‑force attacks, GUI…

Read More
Initial access brokers involved in more attacks, including on critical infrastructure

The rise of initial access brokers has significantly expanded the cyberattack ecosystem, enabling both state-backed and criminal groups to conduct large-scale intrusion campaigns with greater ease and sophistication. This trend emphasizes the increasing importance of prioritizing identity security, supply chain protection, and operational technology hardening for national security and organizational resilience….

Read More