daily cyber × ai intelligence

index

tagged

[midnight-blizzard]

2 editions · 2 items

September 13, 2026

  • Anthropic's 154-page report gains actor-level detail. The Russian state-sponsored cluster it calls GTG-20006 — sharing tradecraft with Midnight Blizzard/APT29 — built an AI-assisted workflow to rebuild malware after detection, in a campaign against more than 20 government, intelligence, diplomatic and defence organisations (The Hacker News, The Record). GTG-50014 (aka MeowSHA), a French-speaking suspected ShinyHunters affiliate, ran 10 AWS EC2 workers that pulled 1.8 million distinct Android APKs, scanned them with TruffleHog and pushed verified secrets to Telegram; a second ShinyHunters affiliate hit SaaS vendors to reach roughly 50 downstream organisations and maintained an autonomous vulnerability-research programme producing working exploits for unknown flaws in network and security appliances (The Hacker News, earlier coverage). Anthropic also describes users in Houthi-held Yemen attempting weapons development, including a failed guided-rocket test, without fielding an operational device (SecurityWeek). Worth reading the caveats: @cyb3rops notes the "sandbox escape" was internet access enabled by a misconfiguration, not a VM or container escape, and the "safety monitor" was another LLM reviewing transcripts after the fact. · AI-Enabled Threat Activity

in Artifactory Chains Give Attackers Admin in Under Five Minutes

August 2, 2026

  • Microsoft attributes worldwide hotel Wi-Fi hijacking to Midnight Blizzard (Storm-2945). In its CaptiveCrunch report, Microsoft ties the Russian SVR actor to manipulation of captive-portal management infrastructure since May 2026, redirecting guest traffic through actor infrastructure to push fake OS updates and steal credentials — an evolution of the hotel-network abuse tracked earlier (earlier coverage). Since February the group has also run AI-augmented device-code and OAuth phishing leading to rogue Entra device registration and M365 data theft (Microsoft, The Hacker News). · Cloud & Identity

in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves