Index live· 1,284 files · 148 editions
ForensicPost

Search the index

11 results
Try
Results for “Espionage”Newest first
26-0812
File

Lazarus Paired a Windows Zero-Day With Post-Quantum Encryption Against Defence Firms

Adopting ML-KEM cost the attacker one library. It costs a defence contractor its entire estate.

Lazarus GroupCVE-2026-68820 — Windows AFD.sysDefenceEspionage
Sev 5TargetDefence, aerospace and aviation firmsActorLazarus GroupNot established
26-0215
File

South Korea's National Diplomatic Academy Intrusion Ran Ten Months

Ten months in a diplomatic academy’s education platform, touching 360 serving diplomats. The coursework was never the point; the roster was.

UnattributedUnder reviewPublic sectorEspionage
Sev 3TargetNational Diplomatic Academy (KR)ActorUnattributedSouth Korea
26-0207
File

Thirteen Letters About Selling Americans’ Data Abroad

Espionage acquires data covertly at cost and risk. The same categories are purchasable, leaving no incident for anyone to file.

UnattributedRegulatoryMultipleData brokers
Sev 3TargetUS data broker marketActorUnattributedUSA
26-0130
File

Pawn Storm Opened 2026 With an Office Zero-Day Against Ukraine and Partners

An Office zero-day opening the year against Ukraine and its partners. The unchanged target list matters more than the exploit.

Pawn StormOffice zero-dayPublic sectorEspionage
Sev 4TargetGovernment, defence and aid bodiesActorPawn StormUkraine
25-1213
File

Chinese Espionage Campaigns Targeted Southeast Asia Across Four Sectors in 2025

A newsroom holds source contacts and the record of who spoke to whom. Where that carries risk, it is not a data-protection matter.

Chinese state-linked actorsVariousMultipleEspionage
Sev 4TargetSoutheast Asian organisationsActorChinese state-linked actorsTaiwan
25-1129
File

Lazarus Group Took $30.4 Million From Upbit, South Korean Authorities Say

Espionage-grade capability applied to straightforward theft, against a target with no reversal and no deterrent.

Lazarus GroupFinanceGeopolitics
Sev 4TargetUpbitActorLazarus GroupSouth Korea
25-0731
File

Sustained Campaigns Against Energy, Aerospace and Government

A state-linked group running ransomware collapses the distinction the corpus is organised around — and from a defender’s position it is unresolvable in the moment.

Iranian state-linked setsVariousEnergyEspionage
Sev 4TargetGulf energy and governmentActorIranian state-linked sets
24-1126
File

RomCom Chained Firefox and Windows Zero-Days Into a Zero-Click Backdoor

Two flaws individually rated manageable, combining into compromise with no interaction at all.

RomComCVE-2024-9680 chained with CVE-2024-49039MultipleEspionage
Sev 5TargetFirefox and Windows usersActorRomComNot established
24-0911
File

Sophos Found Three Chinese State-Linked Clusters Inside One Southeast Asian Government

Three teams building parallel access rather than contesting it. An operation planning to survive being found.

Clusters Alpha, Bravo, CharlieGovernmentEspionage
Sev 4TargetUnnamed Southeast Asian government bodyActorClusters Alpha, Bravo, CharlieNot established
23-0919
File

International Criminal Court Says September Breach Was Espionage

Espionage succeeds by producing no artefact. The ones in this corpus are the ones that failed at the last step.

UnattributedGovernmentStatecraft
Sev 5TargetInternational Criminal CourtActorUnattributedNetherlands
23-0711
File

Storm-0558 Forged Tokens With a Stolen Microsoft Key to Read Government Email

A token signed with a trusted key is not a forgery the platform can detect. It is a valid token.

Storm-0558Forged authentication tokensPublic sectorEspionage
Sev 5TargetExchange Online tenantsActorStorm-0558
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging