Italy thwarts Russian-linked cyber intrusions aimed at foreign ministry and Winter Olympics sites
Read Our Expert Analysis
Create an account or login for free to unlock our expert analysis and key takeaways for this development.
By continuing, you agree to receive marketing communications and our weekly newsletter. You can opt-out at any time.
Recommended for you

Russian-linked strike cripples control hardware across Polish energy sites
A cyber operation attributed to Russian-aligned actors disrupted communications and supervisory equipment at about 30 Polish distributed energy locations, permanently damaging some field controllers. While no widespread outages occurred thanks to local protections, the campaign exposed critical vulnerabilities in remote telemetry and raises recovery, supply-chain, and resilience concerns for distributed energy systems.

Italy probes suspected sabotage of northern rail network as Winter Games begin
Deliberate disruptions to rail infrastructure in northern Italy — including a track fire, a burned switch and severed power cables with a crude explosive device found nearby — forced temporary closures and delays as the Winter Olympics opened. Authorities also disclosed contemporaneous cyber intrusions against diplomatic and Games‑related online services, prompting a combined criminal and cybersecurity response as investigators probe whether the incidents were coordinated.
Global cyber-espionage campaign breaches sensitive targets in 37 countries
A coordinated, long-duration hacking campaign has established persistent access to high-value government and diplomatic networks in 37 countries, prioritizing intelligence collection over immediate disruption. The operation leverages polymorphic tooling, credential harvesting and social-engineering techniques that complicate detection and raise urgent needs for identity-focused defenses and cross-border incident coordination.

Russia-linked military-intelligence parcel sabotage across Europe
Investigators say a Russia-linked military‑intelligence network orchestrated parcel attacks that detonated in the UK, Germany and Poland; 22 suspects have been identified and two cases forwarded to court. Cross‑border probes and recent related incidents — including a deliberate rail disruption on a Warsaw–Ukraine corridor and arrests linked to attempted port sabotage in Hamburg — show a wider hybrid campaign blending low‑tech physical attacks, cyber probes and disposable operatives paid in cryptocurrency.

Italian leaders rebuff US immigration agents slated for Olympic security
Italian officials and former leaders have publicly opposed the planned deployment of US immigration agents to assist security at the Milan–Cortina Winter Olympics, citing recent lethal incidents involving the agency at home and concerns about jurisdiction and tactics. The US Department of Homeland Security says the personnel will support security roles but not conduct immigration enforcement on Italian soil, creating a diplomatic rift ahead of the Games.
India targeted by Pakistan‑linked APT36 in coordinated three‑pronged RAT campaign
A Pakistan‑linked actor tracked as APT36 is conducting coordinated espionage against Indian government and defense networks using three distinct RAT families across Windows and Linux hosts, emphasizing stealthy persistence and in‑memory execution. The tradecraft mirrors broader long‑duration intrusion campaigns—including session orchestration and social‑engineering techniques—so defenders should prioritize cross‑domain telemetry, identity‑first controls, and rapid session protections to detect and disrupt access.
U.S. Cyber Command Secretly Targeted Russian Influence Network Ahead of 2024 Vote
In the run-up to the 2024 election, U.S. military cyber teams conducted clandestine operations against at least two Russian-linked companies that were running covert disinformation campaigns aimed at swing-state voters. Those strikes temporarily disrupted infrastructure and personnel, but broader cuts to federal election-security programs have left local election officials more exposed to future foreign manipulation.

CISA Strained as Iran-Linked Cyber Threats Surge
CISA readiness has weakened amid staff reductions and leadership churn just as Iran-linked actors have increased disruptive operations against regional and U.S. targets. The staffing shortfall, canceled assessments, and a spike in reported disruptions amplify risk to banks and critical infrastructure.