Find notable cyber news and cases, enriched with sources, timelines, and signals.

Russian-speaking threat actor campaign expands across multiple victims

Campaign
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

A Russian-speaking threat actor ran an AI-augmented campaign against FortiGate security appliances, using multiple commercial AI services to scale compromise attempts across a wide global target set. The operation mattered because it reached more than 600 appliances in at least 55 countries over five weeks, showing how commercial AI can amplify offensive tradecraft.

Related Happenings

Shadow-Aether-040 AI-augmented campaign against Mexican government entities

Campaign
First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The **Shadow-Aether-040** campaign used **AI agents** and custom tooling to compromise **six government entities in Mexico**, increasing the risk of follow-on intrusion and **data...

Prominent cybercrime threat actors AI-assisted zero-day exploitation campaign

Campaign
First: 11.05.2026 16:00 Last: 11.05.2026 16:00 Sources 1

About this happening: An **AI-assisted zero-day exploitation campaign** was planned by **prominent cybercrime threat actors**, but the effort was **disrupted before deployment** and did not reach its i...

China-nexus agentic tools attack campaign targeting Japanese technology and East Asian cybersecurity organizations

Campaign
First: 11.05.2026 16:00 Last: 11.05.2026 16:00 Sources 1

About this happening: A **China-nexus actor** used **agentic tools** in a targeted attack against a **Japanese technology firm** and an **East Asian cybersecurity platform**, showing how AI-driven orch...

Widespread exposure and misconfiguration in self-hosted AI infrastructure

Target Trend
First: 05.05.2026 13:30 Last: 05.05.2026 13:30 Sources 1

About this happening: A large-scale measurement found **self-hosted AI infrastructure** was being deployed with **widespread exposure and no authentication**, creating a broad risk of data theft, workf...

Zealot autonomous AI cloud intrusion proof of concept

Technical Analysis
First: 23.04.2026 13:09 Last: 23.04.2026 13:09 Sources 1

About this happening: **Palo Alto Networks Unit 42** built **Zealot**, an autonomous AI agent that successfully attacked an isolated **Google Cloud Platform** environment, showing that machine-speed ad...

Timeline

  1. 09.03.2026 01:35 2 articles · 2mo ago

    Russian-speaking threat actor campaign expands across multiple victims

    Initial Disclosure

    In **February**, the actor began using **commercial AI services** to plan and carry out compromise attempts against **FortiGate security appliances**. The first phase concentrated on finding **exposed management ports** and **weak credentials**, setting up a campaign that would spread across **55 countries**.

    Show sources