APTPavel Durov charged in Russia: Telegram accused of facilitating terrorism
Russian FSB charged Telegram CEO Pavel Durov for facilitating terrorism via malicious chatbots, causing mass arrests and an almost total app block.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
APTRussian FSB charged Telegram CEO Pavel Durov for facilitating terrorism via malicious chatbots, causing mass arrests and an almost total app block.
MalwareTengu, a new Mirai-based Linux botnet, abuses hardware watchdogs and multi-layered persistence to remain nearly impossible to eradicate from devices.
APTExplore 2026 recommendations for securing critical infrastructure, OT, and AI. Learn about Zero Trust, ATG vulnerabilities, and AI supply chain risks.
MalwareMedusaHVNC is a MaaS trojan exploiting HVNC to hijack authenticated browser sessions on hidden Windows desktops, stealing cookies and credentials stealthily.
RansomwareA ransomware attack by the Anubis group targeted Coca-Cola's Fairlife subsidiary, stealing 1 TB of data and forcing temporary production shutdowns.
APTUAC-0099 APT targets Ukraine via a trojanized Notepad++ plugin delivering LUNCHPOKE and BURNYBEAR payloads for espionage and cyber sabotage.
MalwareExplore this week's top cyber threats: AI infostealer, Siemens ROX II zero-days, 432 Linux kernel CVEs, and Zimbra APT exploits.
MalwareFBI and partners seized hundreds of NetNut proxy domains and dismantled the Popa botnet, disrupting a massive white-label criminal proxy ecosystem.
MalwareAn investigation revealed widespread residential proxy SDK abuse in Smart TVs. LG bans apps using hidden proxies to protect users from security risks.
APTAn AI agent named Hermes in YOLO mode automated a cyberattack on the Thai Ministry of Finance, using custom tools and exposing internal vulnerabilities.
APTDiscover how cybercriminals compromise hotel Wi-Fi gateways via DNS hijacking to steal Microsoft 365 credentials and bypass MFA using OAuth tokens.
RansomwareEuropol dismantled "The Com", a nihilist network targeting minors with CSAM and businesses with ransomware in a major transnational EU operation.