operational

Operational

Campaigns, agency operations, sector-wide intrusion sets, and advisories

US-FED·Defensive Operations·criticalCONF 78
USlow · 10US (general)

F5 discloses nation-state intrusion into product development and engineering systems

Bottom line: F5 disclosed long-term access by a nation-state actor to systems holding BIG-IP source code and undisclosed vulnerability information, and United States officials warned of risk to federal networks. Vendor build environments are now part of every agency's threat model.

Automated analysis from cited open sources.

Federal Civilian GovernmentOct 15, 2025Reuters (opens in new tab) Details
#F5#Supply chain#Nation state
PRIVSEC·Incidents & Breaches·criticalCONF 57

Google Threat Intelligence Group and Mandiant document Oracle E-Business Suite zero-day extortion

Bottom line: an extortion campaign linked to the CL0P ecosystem exploited an Oracle E-Business Suite zero-day for mass data theft across dozens of customers. Enterprise resource planning platforms are now a primary mass-exploitation target, not a back-office concern.

Automated analysis from cited open sources.

#CL0P#Oracle E-Business Suite#Extortion
PRIVSEC·Vulnerabilities & CVEs·criticalCONF 78

Microsoft attributes on-premises SharePoint exploitation to Chinese state actors

Bottom line: Microsoft tied active exploitation of on-premises SharePoint flaws to Linen Typhoon, Violet Typhoon and Storm-2603, with post-exploitation key theft enabling persistent access. Rotate machine keys after patching, because patching alone does not evict the actor.

Automated analysis from cited open sources.

#SharePoint#Linen Typhoon#Storm-2603
CI-COMMS·Threat Intelligence·highCONF 57
USlow · 33Treasury / OFACUS (general)

Recorded Future Insikt Group: RedMike (Salt Typhoon) exploits unpatched Cisco devices at telecom providers

Bottom line: between December 2024 and January 2025 Insikt Group observed continued exploitation of known Cisco IOS XE flaws against telecommunications providers, including United States affiliates. Sanctions did not change the operational tempo, so patching edge devices is the only working control.

Automated analysis from cited open sources.

Critical Infra: CommunicationsFeb 13, 2025Recorded Future Insikt Group (opens in new tab) Details
#RedMike#Cisco IOS XE#Insikt Group
DOD·Offensive Operations·highCONF 57
USmedium · 35FBI / DOJUS (general)

Court-authorized operation disrupts the Raptor Train botnet used by People's Republic of China actors

Bottom line: the Federal Bureau of Investigation removed malware from roughly 260,000 consumer routers, cameras and storage devices used as attack relay infrastructure by Flax Typhoon. Consumer devices inside United States address space are strategic terrain and are being cleaned by court order.

Automated analysis from cited open sources.

Defense / MilitarySep 18, 2024US Department of Justice (opens in new tab) Details
#Flax Typhoon#Botnet takedown#Raptor Train

AI Daily Briefing

ICD 203 · Briefing for today

Automated analysis, generated from cited open sources using a methodology designed by a United States Intelligence Community veteran.

CI-WATER·Critical Infrastructure·criticalCONF 57
USlow · 11US (general)

Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure

Bottom line: authoring agencies assessed that Chinese state actors are pre-positioned on communications, energy, transportation and water networks to enable disruption, not espionage. Hunt for living-off-the-land activity on edge appliances rather than waiting on malware signatures.

Automated analysis from cited open sources.

#Volt Typhoon#Living off the land#Pre-positioning
ADV-IR·Threat Intelligence·highCONF 57

Advisory AA23-335A: CyberAv3ngers exploit Unitronics controllers at water utilities

Bottom line: Iranian Government Islamic Revolutionary Guard Corps affiliated actors defaced and disrupted programmable logic controllers at small water systems using default credentials on internet-exposed devices. Change default passwords and remove operational technology from the public internet as the first control.

Automated analysis from cited open sources.

#CyberAv3ngers#Unitronics#Water sector