Daily Briefing

CyberGeoDigest

Geopolitical cyber intelligence in 5 minutes
Wednesday, March 18, 2026 · 20 stories
Share this digest:

North Korea's Konni Group Hijacks KakaoTalk to Spread EndRAT Malware (1 minute read)

Konni actors used spear-phishing to compromise victims, then leveraged their KakaoTalk accounts to push malware to contacts.

The Hacker News · 21h ago · Read full article →

Iran Signals Escalating Cyberattacks After Med-Tech Firm Breach (1 minute read)

Iran-linked actors hit a medical technology firm in what analysts call a preview of more aggressive cyber operations as regional conflict intensifies.

The Register Security · just now · Read full article →

China Funds Nine Tajik Border Posts After Attacks on Nationals (1 minute read)

Beijing grants Tajikistan $61M to build nine border posts as attacks on Chinese nationals escalate.

The Diplomat · 19h ago · Read full article →

Iran's Wiper Attack on Stryker, AI Insider Threats Dominate Week (3 minute read)

Iran deployed an Intune-based wiper against medical device maker Stryker; Qihoo 360's AI leaked its own TLS private key.

Risky Business · 4h ago · Read full article →

Xi's Military Purges Reshape China's Appetite and Capacity for War (3 minute read)

Xi Jinping has removed five of six Central Military Commission generals since 2022, including top general Zhang Youxia.

War on the Rocks · just now · Read full article →

Israel Strikes Tehran, Targets Iran's Top Security Official (2 minute read)

Israel struck Tehran and reportedly targeted Ali Larijani, Secretary of Iran's Supreme National Security Council. The strike marks a dramatic escalation in direct Israeli military action inside Iran.

Just Security · 19h ago · Read full article →

Iran War Risk Threatens Central Asia's Only Sea Access Routes (1 minute read)

Central Asian states rely heavily on Iranian transit corridors as their primary path to global maritime trade.

The Diplomat · 16h ago · Read full article →

Russia Deploys Hybrid Threats to Derail Armenia's Pro-West Election (1 minute read)

Russia is running hybrid operations to destabilize Armenia ahead of elections and block its westward shift. U.S. and EU support is deemed critical to Armenia holding a free democratic vote.

Just Security · 18h ago · Read full article →

Russia's $14T 'Peace' Package Is a Sanctions Relief Trap (3 minute read)

Russia's proposed 'Dmitriev package' offers economic reintegration in exchange for sanctions relief and financial system access.

War on the Rocks · just now · Read full article →

China's Two Sessions Signal Priorities Through 2030 Five-Year Plan (3 minute read)

China's annual Two Sessions meeting unveiled the 15th Five-Year Plan, outlining economic and political direction to 2030.

War on the Rocks · 15h ago · Read full article →

China Faces Oil Supply Crisis as Hormuz Tensions Rise (1 minute read)

Beijing risks a severe oil crunch if Iran-linked Hormuz disruptions materialize amid fragile US-China diplomacy. China's energy dependency on Gulf routes is a critical geopolitical vulnerability.

Foreign Policy · 12h ago · Read full article →

CISA Acting Director: Relationships Over Bureaucracy in Sector Defense (1 minute read)

CISA acting director Nick Andersen says interagency relationships, not formal lead-agency designations, should drive critical infrastructure protection.

CyberScoop · 10h ago · Read full article →

Japan Authorizes Offensive Cyber Operations Starting October 2025 (1 minute read)

Japan's government approved Self-Defense Force offensive cyber operations effective October 1st, a historic shift from purely defensive posture.

The Register Security · 4h ago · Read full article →

EU Sanctions Iranian Front Company for Election Meddling, Charlie Hebdo Hack (1 minute read)

The EU sanctioned Emennet Pasargad, an Iranian state-linked front company, for cyberattacks including election interference and the Charlie Hebdo breach.

The Register Security · 15h ago · Read full article →

EU Hits Chinese and Iranian Entities With Cyberattack Sanctions (1 minute read)

The EU Council sanctioned three entities and two individuals linked to cyberattacks on European critical infrastructure.

BleepingComputer · 13h ago · Read full article →

North Korea's Lazarus Group Steals 18,500 Bitrefill Purchase Records (1 minute read)

Lazarus group hackers breached crypto e-commerce platform Bitrefill, exfiltrating emails, crypto addresses, and IP metadata on 18,500 customers.

The Record · 5h ago · Read full article →

๐Ÿ‡ฐ๐Ÿ‡ต Lazarus ยท North Korea

Medusa Ransomware Knocks Mississippi's Biggest Hospital Offline Nine Days (1 minute read)

Medusa ransomware gang claims attacks on Mississippi's largest hospital and a New Jersey county, causing nine days of outage. Critical healthcare infrastructure remains a prime ransomware target.

The Record · 11h ago · Read full article →

LeakNet Ransomware Deploys ClickFix and Deno for Stealthy Intrusions (1 minute read)

LeakNet ransomware gang uses ClickFix social engineering for initial access and a Deno-based loader to evade detection.

BleepingComputer · 19h ago · Read full article →

Researchers Find DNS-Based Data Exfiltration in Amazon Bedrock AI (1 minute read)

BeyondTrust researchers found Amazon Bedrock AgentCore, LangSmith, and SGLang allow DNS-based data exfiltration and remote code execution.

The Hacker News · 15h ago · Read full article →

Siemens SICAM SIAPP SDK Flaws Enable DoS and Data Corruption (3 minute read)

CISA warns multiple vulnerabilities in Siemens SICAM SIAPP SDK allow denial of service, data corruption, and simulation environment exploitation.

CISA Alerts · 19h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now