Multiple weekly cybersecurity roundups and newsletters highlighted a mix of policy, threat, and vulnerability developments rather than a single discrete incident. UK government messaging featured prominently, including a campaign urging businesses to “lock the door” against cyber criminals and publication of longitudinal survey results indicating most organizations continue to experience cyber incidents (with reported rates in the 70–80% range across businesses and charities). Separately, commentary from European security circles emphasized growing calls for offensive cyber capabilities (“strike back”) amid concerns about Russian aggression and sabotage activity across Europe, including references to cyber operations targeting critical infrastructure.
Threat reporting in the same period emphasized escalating nation-state and proxy activity against critical infrastructure and the defense industrial base, citing research that espionage groups (including those linked to China, Russia, and North Korea) have compromised organizations by exploiting zero-day vulnerabilities in edge devices (e.g., VPNs and gateways). Additional reporting pointed to newly identified OT-focused threat groups (e.g., Sylvanite, Azurite, Pyroxene) and a broad set of emerging technical risks and product/security changes, including discussion of an OpenSSL RCE risk, Foxit 0-days, and analysis of LockBit 5.0 ransomware techniques (e.g., ETW tampering, process hollowing, log clearing) alongside Android platform security changes (e.g., deprecating cleartext traffic defaults and adding HPKE support).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
A compromised npm token was reportedly used to publish a malicious command-line tool update, underscoring software supply-chain risk. The incident was cited in a roundup focused on current developer ecosystem threats.
Authorities took action against a 'laptop farm' operation that allegedly supported North Korean fraudulent IT worker activity. The case was highlighted as part of broader efforts to counter DPRK cyber-enabled revenue generation.
A suspected PRC-linked cluster tracked as UNC6201 was reported exploiting a Dell RecoverPoint zero-day and deploying multiple malware families. The disclosure added a new intrusion set and exploitation vector to current nation-state activity reporting.
Threat intelligence reporting described an alleged APT28 spearphishing campaign using macro-laced documents that spoofed Spanish government content. The activity was presented as part of ongoing nation-state operations across Europe.
UK government and NCSC messaging emphasized improving cyber hygiene for businesses, alongside survey findings that most UK organizations continue to experience cyber incidents. The statements were highlighted in a weekly government security summary.
Authorities in Poland detained an individual in connection with investigations into Phobos and 8Base cybercrime activity. The arrest was cited in multiple weekly roundups as a notable law-enforcement development.
Security reporting said critical remote code execution vulnerabilities in Ivanti Endpoint Manager Mobile were being actively exploited in the wild. Later roundup coverage also noted evidence that exploitation began before patches were released.
CISA added a GitLab server-side request forgery flaw to its Known Exploited Vulnerabilities catalog, signaling that defenders should prioritize remediation. The listing was noted as part of active exploitation and response activity.
Microsoft remediated a Copilot issue that allowed access to email content protected by data loss prevention labels. The fix was highlighted in a weekly security roundup as a notable platform security response.
European and NATO officials were reported to be increasingly calling for offensive cyber capabilities to 'strike back' at adversaries, driven largely by Russian aggression and sabotage activity across Europe. The discussion reflects a policy shift toward considering cyber retaliation as part of Europe’s response toolkit.
Reporting said Google and OpenAI are warning that 'distillation' or model-extraction attacks are being used to copy proprietary AI model behavior. The disclosures framed model theft as an emerging security and policy issue for major AI providers.
OpenAI said adversaries are attempting to steal proprietary model behavior through large-scale querying and that much of the activity appears to originate from China. It also named DeepSeek as trying to circumvent its countermeasures and called for U.S. government support to protect frontier AI firms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
ctoatncsc.substack.com
Open sourcetechtarget.com
Open sourcethehackernews.com
Open sourcenews.risky.biz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.