Security news aggregator

Latest coverage for Russia

Stay updated on Russia's cyber activities. Get the latest news on Russian information security tactics, policies, and threats. Secure your digital world.

2347 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Russia is a nation often associated with a significant cyber presence and activity impacting global information security. In the world of cybersecurity, Russia is known for its sophisticated state-sponsored hacking operations, as well as the activities of independent Russian-speaking cybercriminal groups.

From a defensive perspective, Russia has instigated strict cyber laws and possesses substantial capabilities to protect its digital infrastructure. Conversely, from an offensive standpoint, Russia is alleged to engage in cyber espionage, misinformation campaigns, and cyber warfare, targeting foreign governments, critical infrastructure, and electoral processes.

In cybersecurity discussions, Russia's relevance typically revolves around its advanced persistent threat (APT) groups, cyber policy developments, and international cyber conflict implications. Security experts and analysts scrutinize Russian cyber tactics and strategies to understand global cyber threats better and devise adequate defenses.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 2347 Filtered view

Russia’s FSB claims foreign intelligence planted malware on senior officials’ phones to intercept calls and activate cameras. No technical evidence, no country named. On June 2, 2026, Russia’s Federal Security Service (FSB) published a statement claiming it had uncovered and documented a large-scale foreign intelligence operation targeting the mobile devices of senior Russian officials. The […]

GREYVIBE, a Russia-linked group active since 2025, targets Ukraine with AI-assisted malware and five attack chains. Researchers say it’s part spy op, part crime gang. Security firm WithSecure has been tracking a previously unknown Russian-linked APT group called GREYVIBE since at least August 2025. The group targets Ukraine and Ukrainian-related organizations across military, government, civilian, […]

Bank Info Security 6 days, 2 hours ago

Breach Roundup: US Troops Tracked With Cell Phone Data

Also, Kali365 Bypasses MFA, Silent Ransom Group Makes Office CallsThis week, active duty troops tracked, Kali365 bypassed MFA, Australian lawmakers phished on WhatsApp, Silent Ransom escalated IT scams, Lithuania and German hospitals disclosed breaches, pro-Russian infrastructure providers arrested, CISA warned of active LiteSpeed exploitation.

Suspected Russian Crime Group Built Resilient Command-and-Control InfrastructureIn a joint operation, CrowdStrike, Google and Shadowserver Foundation disrupted infrastructure used by the Glassworm cybercrime group, cutting off attackers from victims. The group has wielded a remote access Trojan to repeatedly target developers of widely used open-source software.

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequent staging ground for cyber mischief from Russia's intelligence agencies.

Dutch authorities arrested two suspects and seized 800 servers tied to Stark Industries, a hosting firm linked to cyberattacks and disinformation. Dutch financial crime investigators arrested two men and seized 800 servers connected to Stark Industries, a hosting provider accused of enabling cyberattacks, interference operations, and disinformation campaigns. Authorities said the suspects supported Russian and […]

A solo Russian-speaking threat actor ran a 5-year Telegram channel and, starting September 2025, used AI to automate its content, credential theft, and a cryptocurrency fraud scheme targeting American audiences.

Loading more headlines...