Niger's military government seized power in 2023 promising to reclaim the country from foreign influence. Three years later, it only survived a mutiny because a different foreign power's soldiers fought to keep it in charge.
The Telegraph's report that Iran-linked hackers took a small UK power generator offline for four days in July has since been independently reported by the BBC, The Guardian, and The Independent. UK authorities still haven't confirmed it. Five US agencies just confirmed the broader threat is real.
For three years, a woman in Arizona kept company laptops running in her spare bedroom for North Korean operators she'd never met. Three hundred and nine US companies hired the people on the other end. None of them noticed.
North Korea's hacking units funded roughly $2.84 billion of the regime's nuclear and missile programs through cryptocurrency theft between January 2024 and September 2025, according to the Multilateral Sanctions Monitoring Team, the eleven-nation coalition that took over UN sanctions monitoring after the original UN Panel of Experts was disbanded. No toolkit built for ordinary criminals has stopped it, and the broader losses Congress itself cites, billions lost to Americans annually through crypto scams, ransomware, and fraud, are real. Indictments against people who never see a US courtroom genuinely are losing that fight. Congress and the White House are now moving on separate tracks to close the gap by commissioning the private sector to hit back, and they're not alone.
Call this what it is: foreshadowing, not analysis. When a government publishes a legal case for striking something it hasn't struck yet, that's usually a sign of what comes next, not academic commentary.
Chinese firms distilling capability out of Western frontier models isn't news. It's happened at least three times this year. What's new this time is who is doing the arguing: for the first time, a named US government official made the accusation and opened a formal investigation, and China's government answered with an on-the-record retaliation threat, not researchers and company statements trading claims in the background.
Water pressure dropped and some plants flooded in Minnesota last week, when a coordinated attack cut operators off from the equipment that runs their own treatment systems. US investigators think Iran is probably behind it.
Chongqing Yanmei Technology, a Chinese company, challenged a small Ohio inventor's patent at the Patent Trial and Appeal Board, the venue that lets anyone challenge a US patent's validity without a jury trial. The patent covered a dissolvable magnesium alloy Terves LLC had developed to plug oil and gas wells during fracking. In August 2024, the board sided with Chongqing Yanmei and found key claims in Terves' patent unpatentable; Terves salvaged some protection only by amending its claims mid-proceeding. Whatever the merits of that specific case, the pattern behind it is what should worry other small patent holders: a challenge like this is cheap to file and expensive to defend, and the cost of defending one, win or lose, is often enough on its own to force a settlement or bankrupt a small inventor.
The Iran-linked campaign against US industrial control systems that surfaced this spring got worse on July 22. CISA (the federal cybersecurity agency), the FBI, and the EPA updated their joint advisory on Iran-affiliated hackers who have been breaking into the small industrial computers that run pumps, valves, and production lines, across water, energy, and government facilities, since at least March. Two things changed. The list of affected equipment grew to include Schneider Electric and Siemens controllers, on top of the vendors named in the spring, and some intrusions went further than disruption, modifying or deleting the controller logic itself and disabling safety shutoffs and alarms without alerting operators. NERC, the body that oversees grid reliability, said in the spring it was watching the grid closely, and nothing since suggests that's changed.
On July 15, the Treasury's sanctions office, OFAC, blacklisted seven people and companies for buying weapons on behalf of Iran's Revolutionary Guard, the branch of Iran's military that runs its operations abroad. It is the same force that killed US troops in Jordan this week, which is why the case surfaced when it did. The war connection is the reason it made the news. What makes it worth reading is how the network was built to look: nothing like Iran.
An investigation by OCCRP deserves a place on your security radar, because it lands on the single most sensitive tool most companies run: the password manager, the vault that holds the keys to everything else. This is not a story you will catch in your regular feeds.
On July 10, a Chinese rocket booster dropped out of the sky over the South China Sea and flew into a net. Four hooks on the booster snagged a net strung across a ship. It worked on the first try.
A study out this month put a number on a supply-chain dependency few companies think to check. Chinese firms own, finance, or operate 78 of Africa's 231 commercial ports, and the control does not stop at the water's edge. It reaches into the software, the automation, and the artificial-intelligence systems that actually run them.
Last month the government set the quantum deadline. This month the companies that run your systems moved it closer, and the money moving underneath tells you why.
The head of ASIO, Australia's domestic intelligence agency, used his annual threat assessment this month to describe a kind of breach that should change how you read the word. A foreign government's hackers had been inside an Australian critical infrastructure provider for months. They had not stolen data or sent a ransom note. They had taken the login credentials of the network's active users, including the IT staff guarding it, mapped the entire system, and quietly held on to their access. The purpose, ASIO concluded, was sabotage: "mapping out the network and maintaining access so they could cripple it at a time of their choosing."
In the time it takes to read this paragraph, a software company somewhere shipped an AI feature built on components nobody reviewed. The competitive pressure to add artificial intelligence to every product, every platform, and every internal tool has created a supply chain problem that most companies have not recognized yet, because it sits one layer below the product they actually bought.
The security hardware meant to keep attackers out, and the outside firm hired to run a company's technology, are the two places monitoring rarely reaches. They are also where a patient intruder settles in for a year or more.
On June 4, the Five Eyes intelligence alliance published its first-ever joint bulletin titled "Safeguarding Our Secrets," warning that China's military intelligence services are systematically impersonating headhunters on LinkedIn to recruit sources inside government, defense, media, and any organization with access to trade secrets or sensitive technology. The fake recruiters operate through front companies with storefronts in Singapore and New York. They offer cash for "articles" and "market insights," requests that sound like consulting work until the questions narrow to classified programs, proprietary processes, or deal timelines. Payments arrive through PayPal, Wise, Zelle, and cryptocurrency.
China was the last credible pressure point on Iran. Beijing buys Iranian crude. Beijing has diplomatic channels. Beijing has economic leverage. For eleven weeks, the assumption in Western capitals has been that China would eventually lean on Tehran because the Hormuz closure hurts Chinese energy imports too. OPEC (the oil exporters' cartel) already fractured when the UAE exited last month. China was supposed to be the remaining lever.
The Trump-Xi summit in Beijing closed May 15 with a verbal framework both sides described as "constructive, strategic, and stable." No formal joint statement was issued. No chip export relief was announced. No rare earth supply framework was agreed. Jensen Huang attended as one of seventeen CEOs in the delegation and left without a semiconductor deal.
China controls roughly 60 percent of global rare earth mining, 90 percent of processing, and a significant share of the base chemicals other countries need to do their own processing. The materials go into motors, batteries, medical devices, defense systems, and the electronics on every desk in your office. Diversifying away from Chinese rare earths runs into a Chinese dependency one layer down. On Wednesday, President Trump meets President Xi in Beijing for a two-day summit where rare earth supply commitments and semiconductor export controls are both on the table.
Poland's internal security agency warned in early May that Russian-linked hackers breached the control systems at five municipal water treatment facilities and gained the ability to change how the equipment operates. In April, Sweden attributed a cyberattack against a thermal power plant to actors connected to Russian intelligence. Two NATO members, two types of critical infrastructure, the same adversary, within weeks of each other.
Nearly a dozen governments and their intelligence agencies published a joint advisory on April 23 naming what they found inside consumer-grade network equipment worldwide. The answer was the Chinese military.
In March 2026, HMN Technologies (the successor to Huawei Marine, now owned by Hengtong Group) finished splicing 6,300 kilometers of new submarine cable across the Indian Ocean, extending the Pakistan-Egypt-Marseille PEACE system into Singapore. Three weeks later, on April 11, Chinese state-backed researchers tested a deep-water cable cutter rated to 3,500 meters. Same actor. Same body of water. Same month.
State of the Threat readers have followed this story all year. February 21: we covered the shift from fake LinkedIn profiles to stolen real identities. March 8: nearly every Fortune 500 CISO admitting they had unknowingly hired at least one DPRK IT worker. March 22: Treasury sanctions on the facilitators. This week, the prosecutions arrive.
Your security perimeter protects your network. The problem is how much of your business runs on infrastructure that isn't your network. Three stories this week exposed three versions of the same blind spot.
On March 31, the Islamic Revolutionary Guard Corps published a list of 18 companies it designated as "legitimate military targets." The list included the companies that run most of American business technology: Microsoft, Google, Apple, Meta, Nvidia, Intel, Cisco, Oracle, Dell, HP, IBM, and Palantir. It also included JPMorgan Chase, Tesla, General Electric, Boeing, Abu Dhabi AI firm G42, and Dubai cybersecurity firm Spire Solutions, broadening the threat beyond tech to American financial, industrial, and regional partners. Amazon was not on the list. Its data centers had already been hit. The IRGC gave an 8 PM Tehran time deadline and warned employees to evacuate immediately.
Chinese AI models now handle roughly 45% of workloads on major AI routing platforms, up from 1.2% in late 2024. In one week in February, they hit 61%. The reason is cost. DeepSeek charges roughly a tenth of what comparable American models cost. Alibaba's Qwen family has been downloaded 700 million times. Developers have created 180,000 derivative versions built on top of those models. This isn't a consumer app trend. It's a shift in the infrastructure layer that software companies build on.
On March 18, the Office of the Director of National Intelligence released the 2026 Annual Threat Assessment before the Senate Select Committee on Intelligence. Director of National Intelligence Tulsi Gabbard presented the findings. The document is the intelligence community's annual public accounting of who threatens the United States and how.
Last week we covered Handala's wiper attack on Stryker Corporation, the medical device manufacturer that initially reported 200,000 systems destroyed across 79 countries. This week, three separate forces closed in on the company at once.
On March 13, Brazilian President Luiz Inácio Lula da Silva revoked the visa of Darren Beattie, a State Department official serving as senior advisor for Brazil policy, after Beattie attempted to visit former Brazilian President Jair Bolsonaro in prison. Bolsonaro is serving a 27-year sentence for his role in a coup plot. The move was reciprocal. The Trump administration had denied a visa to Brazil's health minister weeks earlier. US-Brazil relations are at their lowest point in decades.
Last week we covered the opening salvo of Operation Epic Fury and Iran's unprecedented drone strikes on three AWS data centers. Two weeks in, the kinetic picture has shifted dramatically. The cyber picture has not.
On March 11, a group called Handala deployed wiper malware across Stryker Corporation's global network. Within hours, 200,000 systems, servers, and mobile devices were erased across 79 countries. Stryker's 56,000 employees were told to power down everything. Order processing, manufacturing, and shipping stopped. In its 8-K filing with the Securities and Exchange Commission, Stryker said it found "no indication of ransomware or malware" and believed the incident was contained, but acknowledged the timeline for full restoration is unknown and has not yet determined whether the incident is "reasonably likely to have a material impact."
On March 6, the White House released "President Trump's Cyber Strategy for America" alongside an executive order elevating cybercrime to the same priority level as nation-state threats. The document is four pages. It is worth reading in full.
Last week we said Iran's cyber restraint toward the US had ended. Seven days later, Israel collapsed Iran's internet to 4% in the opening salvo of a joint US-Israeli military campaign.
A leaked FSB document calls China "the enemy." A Chinese APT spent five months in a Russian defense contractor's build systems. Russia stayed quiet because it can't afford not to. Most businesses operating with Chinese partners are making the same calculation without realizing it.
North Korea stole $2 billion in crypto with 74% fewer attacks. That got the headlines. What didn't: nearly every Fortune 500 CISO admits to unknowingly hiring at least one North Korean IT worker.
Norway says it faces its worst security situation since World War II. Finland arrested a ship's crew for severing an undersea cable on New Year's Eve. Both Russia and China are involved.
While nuclear talks were live, Iran pointed its cyber arsenal at dissidents and neighbors, not the United States. The US and Israel just bombed Tehran.
A Greek court just proved what the industry has known for years. Governments are buying commercial spyware and pointing it at the people making decisions they want to influence.