Desk live·
ForensicPost
Section

Nation-state

Espionage, pre-positioning, and the long eviction. Attribution here is a graded claim, never a headline: we name a government only when two independent sources and a reviewed artefact agree, and we say so when they do not.

Files in section91
Median dwell time211 days
Attributed with high confidence38%
Cases still open after 1 year9
Top of section26-0812 · Espionage · Sev 5

Lazarus Paired a Windows Zero-Day With Post-Quantum Encryption Against Defence Firms

Lazarus used a Windows kernel zero-day against defence and aerospace firms for about five weeks — and ran the command channel over ML-KEM, the post-quantum standard NIST finalised in 2024. Almost none of the organisations being targeted have deployed it.

13 min readConfidence: high
Filter
Sort

Polish Heat Plant Attackers Reached the PLCs Through a Private APN

A private network is still a network. Once anything inside it could reach anything else, the isolation was a route.

3 sources · 13 min read

FBI and CISA Warn Water Utilities to Protect Internet-Facing PLCs After Attacks

Post-incident guidance that leads with the exposed device rather than the adversary. For a utility with one engineer, that is the usable document.

2 sources · 8 min read

CI Fortify Guidance Tells Critical Infrastructure Operators to Plan for Isolation

New guidance asks operators to build and test plans for running vital systems disconnected. The assumption underneath it is the story.

2 sources · 9 min read

Attacks on Water Controllers Disrupt Operations Across 30 Minnesota Communities

More than 30 Minnesota communities disrupted through internet-facing controllers. Manual operation was the fallback, and it is a capability most utilities are losing.

3 sources · 14 min read

Three Quarters of the Year’s Stolen Crypto, One Government

76% of the year’s crypto theft value attributed to one state. On a public ledger, attribution is tractable in a way network telemetry never is.

3 sources · 12 min read

Salt Typhoon Campaign Reached More Than 600 Organisations Across 80 Countries

More than 600 organisations across 80 countries since 2019, including US carriers and the lawful-intercept systems they run. The metadata was always the point.

3 sources · 15 min read

Shared Airport IT Platforms Identified as a Sector-Wide Single Point of Failure

Common-use platforms are why terminals can flex, and why one supplier failure degrades four countries at once. Nobody in the contract chain prices that.

2 sources · 10 min read

DHS Information-Sharing Environment Intrusion Involved Deleted Logs

Unpatched vulnerability, persistent tooling, deleted logs. The deletion is a finding in itself — nobody spends that effort on a boring record.

1 source · 9 min read

Adversary Breakout Time Falls to 72 Minutes, Research Finds

Foothold to exfiltration in about 72 minutes. Every response process that assumes a human decides in time is now mistimed.

2 sources · 10 min read

Attacks on Logistics Are up Tenfold Since 2021

Up roughly tenfold since 2021 and projected to double again. The manual fallback that limits the damage is a wasting asset.

1 source · 10 min read

Tens of Thousands of Firewalls, and the Credentials Were Already Inside

Mass credential compromise across tens of thousands of firewalls. Patching fixes the device; it does not un-disclose the credentials.

2 sources · 10 min read

Five Years in a Grid Network, and Nothing Was Stolen

Five years of access with no exfiltration objective. Pre-positioning breaks every response method that starts by asking what the intruder wanted.

3 sources · 12 min read

The Record Attack Was Pointed at the Phone Network

Carriers are the target, the transit and the only party who can see an individual compromised device. The benefit of acting accrues to everyone else.

2 sources · 10 min read

The Secure Messenger the French State Built for Itself

73,500 accounts on the state’s own messenger. For an internal platform the graph is the intelligence, not the messages.

1 source · 9 min read

Post-quantum Migration Costed at $15 Billion Globally

The algorithms are free. The $15 billion is discovery, hardware replacement and re-certification — and small institutions will not be paying it.

2 sources · 10 min read

NIST Finalises Three Post-Quantum Standards With Migration Deadlines From September 2026

Three standards finalised, deadlines from September. The blocker is that nobody knows where their cryptography actually is.

3 sources · 11 min read

Two Hundred and Ninety-Two Million, and No Perimeter to Breach

A reported $292 million protocol exploit. No credential, no dwell time, no log — and no ability to disconnect while you investigate.

2 sources · 9 min read

The Second European Commission File This Year

A cloud flaw touching Commission web properties, internal systems untouched. The second such file this year, and the boundary held both times.

1 source · 8 min read

Cyber Incident Disrupted Check-in and Baggage at Major European Airports

Check-in, boarding and baggage degraded across four capitals through one shared platform. Manual fallback is what kept it to queues.

3 sources · 12 min read

Residential Proxy Networks Sell State-Grade Traffic Origination to Any Buyer

Originating traffic from a home connection in any country used to need a state service. It is now a subscription, and it breaks three controls at once.

2 sources · 11 min read
© 2026 ForensicPost Media · the desk · newsletter · correctionsGlossary