July 24, 2026
- An exposed Alibaba Cloud directory blew the cover on a China-nexus operation, "JadeProx." Group-IB found bash history, toolkits, webshell paths and staged phishing kits on an operator server, tying simultaneous intrusions against a Vietnamese hospital's imaging system, Malaysia's foreign ministry and Hong Kong universities — and a new TriBack loader plus fake-Anthropic Claude phishing lures. Group-IB, The Hacker News. · Threat Activity