/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

John Hultquist

@johnhultquist
42 posts
2026-02-26
Google Threat Intelligence Group took down a massive, longterm intrusion campaign into global telcos and government. This PRC-nexus actor built a vast surveillance tool across 42 confirmed countries and another 20 suspected countries. 1/x [image]
2026-02-26 View on X
Reuters

Google disrupts Chinese-linked group UNC2814, which breached 53+ organizations across 42 countries and utilized Google Sheets to manage targeting and data theft

2026-02-25
Google Threat Intelligence Group took down a massive, longterm intrusion campaign into global telcos and government. This PRC-nexus actor built a vast surveillance tool across 42 confirmed countries and another 20 suspected countries. 1/x [image]
2026-02-25 View on X
Reuters

Google disrupts Chinese-linked group UNC2814, which breached 53+ organizations across 42 countries and utilized Google Sheets to manage targeting and data theft

2026-02-03
Notepad++ compromised in supply chain attack from June to December 2025 by “likely Chinese state-sponsored actor”. There has been a rash of supply chain incidents over the last couple of years as these guys try to leapfrog into hard targets. https://notepad-plus-plus.org/ ...
2026-02-03 View on X
BleepingComputer

Notepad++ and security researchers say Chinese state-sponsored threat actors were likely behind the hijacking of its update traffic from June to December 2025

Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year …

2026-02-02
Notepad++ compromised in supply chain attack from June to December 2025 by “likely Chinese state-sponsored actor”. There has been a rash of supply chain incidents over the last couple of years as these guys try to leapfrog into hard targets. https://notepad-plus-plus.org/ ...
2026-02-02 View on X
BleepingComputer

Notepad++ and security researchers say Chinese state-sponsored threat actors were likely behind the hijacking of its update traffic from June to December 2025

Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year …

2025-07-16
Should have tossed him in the brig for this unsat beret. All ate up.
2025-07-16 View on X
TechCrunch

The US DOJ says ex-Army soldier Cameron John Wagenius pled guilty to hacking 10+ companies and to extortion; in February, he admitted he hacked AT&T and Verizon

Former U.S. Army soldier Cameron John Wagenius pleaded guilty to hacking telecommunication companies and attempting to extort …

2025-07-11
Four UK arrests in Scattered Spider incidents. Suspects are 17 to 20 years old. https://therecord.media/...
2025-07-11 View on X
BBC

UK police arrest four people, a 20-year-old woman and three men aged 17 to 19, in connection to the M&S and Co-op hacks that began in mid-April and caused havoc

Dunno, not making a particular point, other than that I've been around for ages.  Don't cause havoc kids, at least not in these kinds of ways.  [embedded post] Eric Geller / @ericj...

2025-07-10
Four UK arrests in Scattered Spider incidents. Suspects are 17 to 20 years old. https://therecord.media/...
2025-07-10 View on X
BBC

UK police arrest four people, a 20-year-old woman and three men aged 17 to 19, in connection to the M&S and Co-op hacks that began in mid-April and caused havoc

Four people have been arrested by police investigating the cyber-attacks that have caused havoc at M&S and the Co-op.

2025-06-18
Predatory Sparrow, or Gonjeshke Darande, is taking credit for cyberattacks on Iranian banks. Despite appearances this actor is not all bluster. [image]
2025-06-18 View on X
CyberScoop

A cyberattack claimed by pro-Israel hacktivist group Predatory Sparrow has reportedly disrupted services at Iran's state-owned Bank Sepah, including its website

The attack introduces a clear cyber element with immediate consequences for the country's critical infrastructure amid a growing conflict between Israel and Iran.

2025-05-29
APT31 is an active threat to Europe and the US. They have persisted through efforts to shed light on their operations, and will likely continue to carry out cyber espionage against governments, media, tech, and other sectors.
2025-05-29 View on X
Financial Times

The Czech Republic says that the state-sponsored Chinese hacking group APT31 has targeted its foreign ministry's unclassified communications network since 2022

‘Malicious’ assault blamed on group known as APT31 that has been linked with Chinese state security ministry

2024-09-07
This announcement underscores the seriousness of some of these intrusions as well as the thin line between physical and cyber threat.
2024-09-07 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

There has been a lot of talk this week about Putin paying “useful idiots” to spread his propaganda. … X: @dojnatsec : Five Russian GRU Officers and One Civilian Charged for Conspir...

2024-09-06
This announcement underscores the seriousness of some of these intrusions as well as the thin line between physical and cyber threat.
2024-09-06 View on X
Wired

The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more

Unit 29155 of Russia's GRU military intelligence agency—a team responsible for coup attempts, assassinations, and bombings …

2024-04-17
Even if these are legit hacktivists acting independently under the CARR umbrella, they have latched on to a hacktivist group that Sandworm/APT44 substantially contributed to, or even created. Further, they are a stone's throw from the Kremlin's most aggressive capability. 3/x
2024-04-17 View on X
Wired

Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm

Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.

But without evidence of their involvement we had to allow for the possibility of other CARR affiliates acting outside of the direction of Sandworm/APT44. In that case what does Sandworm/APT44 have to do with it? 2/x
2024-04-17 View on X
Wired

Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm

Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.

The Russian cyberattacks on US water, Polish water, and a French dam are complicated. We had established that CARR was being used as a front for Sandworm/APT44 (Russian GRU) prior to the incidents and that they were even involved in creating some of CARR's online presence. 1/x
2024-04-17 View on X
Wired

Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm

Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.

Most importantly, we shouldn't stand for attacks on water and dams from foreign attackers. These incidents weren't terribly impactful, but they did demonstrate a vulnerability that we must address. US water is now being attacked on three fronts (China, Iran, and Russia). 4/x
2024-04-17 View on X
Wired

Mandiant links hacktivist group Cyber Army of Russia, which claimed to target utilities in France, the US, and Poland, to Russia-linked hacking group Sandworm

Cyber Army of Russia Reborn, a group with ties to the Kremlin's Sandworm unit, is crossing lines even that notorious cyberwarfare unit wouldn't dare to.

2024-02-08
CISA report on Volt Typhoon reveals focus on OT systems following compromise and access at least once. Given known targeting, the threat is pretty clear. Possible that they may be reluctant to traverse into the OT systems, seeing that as escalatory. https://www.cisa.gov/...
2024-02-08 View on X
Axios

US, UK, Australia, Canada, and New Zealand advisory: China-backed hacking group Volt Typhoon has had access to some major US infrastructure for over five years

Sam Sabin / Axios :

2024-02-03
Sanctions from Treasury on IRGC-CEC for global water attacks (Ireland was even hit). Like a lot of the things IRGC does, the point isn't the disruption, it's scaring us. Water is under enormous pressure from China, Iran, and Russia now. https://home.treasury.gov/...
2024-02-03 View on X
CyberScoop

The US Treasury sanctions six Iranian government officials for their role in targeting devices at a Pennsylvania water utility in November 2023

The Iranian attack targeted a device manufactured by an Israeli company.  —  The U.S. Treasury Department on Friday announced sanctions …

2023-11-13
Energy gets a lot of attention (and rightfully so) but logistics is the target that keeps me up late.
2023-11-13 View on X
ABC

DP World Australia, the country's second largest port operator, resumes operations after a cyberattack halted the movement of goods in and out of Australia

2023-11-12
Energy gets a lot of attention (and rightfully so) but logistics is the target that keeps me up late.
2023-11-12 View on X
ABC

DP World Australia, the country's second largest port operator, shuts down after a cyber attack, impacting the movement of goods in and out of the country

Australia's second largest port operator has shut down because of a cyber security incident, impacting the movement of goods in and out of the country.

2023-10-11
Beware claims that this highly secretive operation was coordinated with DDOS attacks.
2023-10-11 View on X
The Record

Amazon, Google, and Cloudflare say a DDoS attack hit 398M RPS in August 2023, ~8x larger than the prior record, due to a new flaw; Google mitigated the attack

Assigner: Mitre Published: 2023-10-10Updated: 2023-10-11 The HTTP/2 protocol allows … Bill Toulas / BleepingComputer : New ‘HTTP/2 Rapid Reset’ zero-day attack breaks DDoS records ...