Security news aggregator

Latest coverage for Russia

Stay updated on Russia's cyber activities. Get the latest news on Russian information security tactics, policies, and threats. Secure your digital world.

18 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Russia is a nation often associated with a significant cyber presence and activity impacting global information security. In the world of cybersecurity, Russia is known for its sophisticated state-sponsored hacking operations, as well as the activities of independent Russian-speaking cybercriminal groups.

From a defensive perspective, Russia has instigated strict cyber laws and possesses substantial capabilities to protect its digital infrastructure. Conversely, from an offensive standpoint, Russia is alleged to engage in cyber espionage, misinformation campaigns, and cyber warfare, targeting foreign governments, critical infrastructure, and electoral processes.

In cybersecurity discussions, Russia's relevance typically revolves around its advanced persistent threat (APT) groups, cyber policy developments, and international cyber conflict implications. Security experts and analysts scrutinize Russian cyber tactics and strategies to understand global cyber threats better and devise adequate defenses.

Volume over time

Weekly headline count for the current query.

Showing 18 most recent headlines Filtered view

The Russia-linked state-sponsored threat actor known as APT28 (aka UAC-0001) has been attributed to attacks exploiting a newly disclosed security flaw in Microsoft Office as part of a campaign codenamed Operation Neusploit

Google on Tuesday revealed that multiple threat actors, including nation-state adversaries and financially motivated groups, are exploiting a now-patched critical security flaw in RARLAB WinRAR to establish initial access and deploy a diverse array of payloads

Bank Info Security 9 months, 3 weeks ago

Russian Hackers Exploit WinRAR Zero-Day

RomCom Group Deployed SnipBot, RustyClaw and Mythic Agent VariantsA Russian speaking hacking group is exploiting a zero-day flaw in WinRAR, a sign of the group's growing sophistication and evolution from a cybercrime outfit into a cyberespionage operation. The campaign exploited a vulnerability now tracked as CVE-2025-8088, a path traversal vulnerability.

Researchers have released a report detailing how a recent WinRAR path traversal vulnerability tracked as CVE-2025-8088 was exploited in zero-day attacks by the Russian 'RomCom' hacking group to drop different malware payloads. [...]

Trend Micro Research, News and Perspectives 1 year, 2 months ago

A Deep Dive into Water Gamayun’s Arsenal and Infrastructure

Trend Research discusses the delivery methods, custom payloads, and techniques used by Water Gamayun, the suspected Russian threat actor abusing a zero-day vulnerability in the Microsoft Management Console framework (CVE-2025-26633) to execute malicious code on infected machines.

Google has released out-of-band fixes to address a high-severity security flaw in its Chrome browser for Windows that it said has been exploited in the wild as part of attacks targeting organizations in Russia.  The vulnerability, tracked as CVE-2025-2783, has been described as a case of "incorrect handle provided in unspecified circumstances in Mojo on Windows." Mojo refers to a

Trend Micro Research, News and Perspectives 1 year, 2 months ago

CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin

Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code and exfiltrate data.

Microsoft's Threat Intelligence team issued a warning earlier today about the Russian state-sponsored actor APT28 (aka "Fancybear" or "Strontium") actively exploiting the CVE-2023-23397 Outlook flaw to hijack Microsoft Exchange accounts and steal sensitive information. [...]

Ukraine's Computer Emergency Response Team (CERT) is warning that the Russian hacking group Sandworm may be exploiting Follina, a remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT) currently tracked as CVE-2022-30190. [...]