Find notable cyber news and cases, enriched with sources, timelines, and signals.

Flax Typhoon critical infrastructure intrusion and credential-harvesting campaign

Campaign
First reported
Last updated
Happening score
H score 89
1 unique sources, 1 articles

Summary

Hide ▲

A Flax Typhoon campaign has been using scanning, intrusion, and credential-harvesting methods against U.S. and foreign critical infrastructure, increasing the risk of unauthorized access to victim networks and cloud services. The operation has relied on Python- and Go-based tools, XSS, and account-targeting utilities to reach Microsoft 365 Cloud environments and harvest credentials. The long-running activity shows coordinated targeting rather than a one-off intrusion. It also raises the likelihood of follow-on access to mailboxes, files, and other sensitive systems.

Related Happenings

ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion

Threat Actor Meta
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...

Silk Typhoon / Hafnium coordinated intelligence-gathering campaign

Campaign
H score59 First: 27.04.2026 22:56 Last: 27.04.2026 22:56 Sources 1

About this happening: The Silk Typhoon / Hafnium operation is tied to a coordinated intelligence-gathering campaign spanning February 2020 to June 2021, underscoring a sustained espionage e...

Latest development: 28.04.2026 15:30

US officials described Silk Typhoon/Hafnium activity from February 2020 to June 2021 as a coordinated intelligence-gathering campaign that targeted US universities and COVID-19 researchers, including a Texas university network, and later expanded into Microsoft Exchange Server vulnerability exploitation. The operation reportedly used stolen mailbox access to search for vaccines, treatments, and testing research, and the FBI said the campaign affected more than 12,700 US organizations.

GopherWhisper China-aligned APT campaign targeting Mongolian government institutions

Campaign
H score30 First: 23.04.2026 12:04 Last: 23.04.2026 12:04 Sources 1

About this happening: The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...

Timeline

  1. 09.10.2026 09:39 2 articles · 2h ago

    Flax Typhoon critical infrastructure intrusion and credential-harvesting campaign

    Initial Disclosure

    By mid-January 2021, the operation was already breaking into victim networks and cloud services with Python- and Go-based utilities. Early access methods included XSS credential harvesting and follow-on account targeting in Microsoft 365 Cloud environments.

    Show sources