A sophisticated supply chain attack targeting the popular Notepad++ editor, attributed to the Chinese APT group Lotus Blossom, has been uncovered, selectively deploying malware to users in Southeast Asia. Concurrently, the Russian-backed APT28 is actively exploiting a new Microsoft Office zero-day vulnerability (CVE-2026-21509) to target entities in Eastern Europe. Ransomware remains a dominant threat, with the Qilin group claiming an attack on Tulsa International Airport and other groups targeting US law firms and manufacturing. These events highlight a landscape of escalating state-sponsored espionage and persistent criminal activity targeting critical infrastructure and corporate entities.
Help others stay informed about cybersecurity threats