ThreatPaperBeta

State-Sponsored

5 cases

A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.

Supply Chain AttackState-Sponsored

The cyber espionage landscape has evolved toward an industrialized 'quartermaster' model of network obfuscation and reconnaissance. On August 26, 2026, the United States Department of Justice (DOJ)...

State-Sponsored

CISA, NSA, and FBI confirmed that PRC state-sponsored actor Volt Typhoon maintained undetected access to multiple US critical infrastructure networks for at least five years, extracting NTDS.dit databases and pre-positioning for potential OT disruption.

State-Sponsored

Russian state-sponsored group Midnight Blizzard (APT29) breached Microsoft's corporate environment via password spray against a legacy non-production test tenant, accessed executive and security team email, and exfiltrated OAuth tokens and source code — demonstrating sophisticated identity-based tradecraft without malware.

State-SponsoredData Breach

In January 2024, multiple Chinese APT clusters (UNC5221, UNC5325) exploited two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances — CVE-2024-21893 (SAML authentication bypass) and CVE-2024-21887 (command injection) — compromising 1,700+ organizations globally in one of the largest VPN appliance exploitation campaigns to date.

State-SponsoredSupply Chain Attack