China-Nexus Actor Spy on US Researchers Undetected for a Year
2026-06-15T20:51:45Z•66e56b0edf2072c40d2cd5aaa107502c47031779009824a83124ab908f809c34
CISACVE-2025-8088ai-enabled-attackscredential-theftdata-exfiltrationedr-evasionespionagenation-statephishingpolicyprompt-injectionransomwaresoftware-supply-chainsupply-chainvulnerabilitieszero-day
What happened
A surge of high-impact activity across nation‑state espionage, software supply‑chain compromise, and active zero‑day exploitation is featured. Google disrupted a China‑linked campaign that stole RedCAP credentials to spy on U.S. researchers, while multiple groups (China‑linked, North Korean, Russian) and cybercrime affiliates have been exploiting zero‑days and supply‑chain implants (Oracle, Ivanti, Check Point VPN, WinRAR/CVE-2025-8088, Miasma, IronWorm, Hades). Attack techniques are evolving with AI-assisted phishing, automated EDR‑evasion testing, prompt‑injection risks in large models, and警
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 66e56b0edf2072c40d2cd5aaa107502c47031779009824a83124ab908f809c34
- Enrichment time
- 2026-06-15T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.