CuraSec

tag: Nation-State · 6 items

2026-08-28 · The Hacker News · source ↗ #owncloud#cve-2023-49105#nation-state
  • Engineer — Act: CVE-2023-49105 (CVSS 9.8) is CISA KEV-listed with a public GitHub PoC and confirmed active exploitation; patch ownCloud to a non-vulnerable version immediately and audit file-access logs for anomalous activity since the PoC has been public.
  • SOC/IR — Act: A Chinese-speaking threat actor is actively weaponizing this flaw for targeted data theft — hunt for unusual ownCloud authentication events and large data transfers in your estate, and correlate against any published IOCs from this campaign.
  • Leader — Plan: Confirm whether ownCloud is present in your environment and verify engineering has applied the patch; the CISA KEV listing and nation-state targeting of critical-infrastructure research bodies makes this worth a direct question to your team this week.
  • Signals: CVE-2023-49105 — CISA KEV: listed, EPSS 0.41, public PoC on GitHub
2026-08-27 · The Hacker News · source ↗ #nation-state#china-apt#infrastructure
  • Engineer — Learn: No specific exploited software, CVEs, or patches associated with QTFY’s platforms are named, so there is no concrete remediation action; file as context on Chinese state-sponsored tooling targeting critical infrastructure.
  • SOC/IR — Plan: Research published TTPs and any emerging IOCs tied to QScan and QTRouter, then build or tune hunt queries targeting behaviors associated with QTFY activity before the actor pivots to new infrastructure post-disruption.
  • Leader — Learn: Useful background for board or leadership briefings on nation-state threat trends; no specific vendor breach or near-term regulatory action is indicated, so no immediate escalation is warranted.
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A concrete example of nation-state actors using commercial AI tools to run multi-platform influence operations; useful context when developing AI acceptable-use policies or briefing leadership on AI-enabled social engineering threats, but no immediate organizational action required.
2026-08-20 · BleepingComputer · source ↗ #threat-actor#nation-state#ip-theft
  • Engineer — Skip
  • SOC/IR — Learn: Mabna Institute TTPs focused on credential-based intrusions targeting research and academic institutions; useful for contextualizing Iranian threat actor tradecraft but no new IOCs or detections surface from this indictment alone.
  • Leader — Learn: Attribution and scale of Iranian hacking-for-hire operations are useful framing for board-level risk conversations about nation-state IP theft, but no immediate action is required without corroborating exposure signals.
2026-08-18 · The Hacker News · source ↗ #c2-framework#nation-state#dns-tunneling
  • Engineer — Learn: The technique of tunneling C2 traffic through DNS and Google Apps Script highlights the risk of assuming cloud-provider traffic is benign; worth reviewing egress controls and whether Google Apps Script domains are in a blanket allow-list on your proxy.
  • SOC/IR — Plan: Build or tune detections for anomalous DNS query volumes and unexpected Google Apps Script callouts from non-developer endpoints; the covert channel technique is novel enough to warrant adding hunt logic this quarter, though no specific IOCs are surfaced in this report.
  • Leader — Learn: Iranian nation-state actor using legitimate cloud services to mask C2 is relevant threat-landscape context, particularly for organizations with Israeli business ties, but no immediate leadership action is required.
2026-07-20 · The Hacker News · source ↗ #nation-state#ip-cameras#surveillance
  • Engineer — Plan: Internet-facing IP cameras are the explicit attack surface; audit your estate for publicly reachable cameras, segment them off the internet behind a VPN or zero-trust proxy, and verify firmware is current — no specific CVE is named but the campaign exploits pervasive misconfiguration.
  • SOC/IR — Act: The AIVD/MIVD advisory (July 10) describes an active Russian intelligence collection campaign — pull that advisory for IOCs and TTPs, then sweep camera management traffic and authentication logs for signs of unauthorized access to physical security infrastructure since at least early 2026.
  • Leader — Plan: Credible Dutch intelligence agencies have named an active Russian campaign targeting physical security cameras near logistics and military routes; if your organization operates in logistics, defense contracting, or has European facilities, assess whether your camera deployments expose operationally sensitive areas and add physical-security infrastructure to your vendor risk review cycle.