There is a point in every conflict where the rules begin to change. Nobody announces it, there is no formal declaration that a threshold has been crossed, and no new doctrine suddenly appears explaining what is now permissible. The change becomes visible in the targeting, in the systems placed at risk, and in the willingness [ ]
Russian Information-Confrontation Doctrine and Observed APT Operations Report date: 16 July 2026Intelligence confidence: Moderate to highScope: Russian state-directed cyber operations, electronic warfare, information operations, and their relationship to Sergey Makarenko’s 2017 monographPrimary document: Sergey I. Makarenko, Information Confrontation and Electronic Warfare in the Network-Centric…
Assessment date: 6 July 2026 Executive Assessment Hacktivism is no longer just online vandalism or nuisance activity. In a geopolitical crisis, it works as an amplifier. Even when individual actors are not technically advanced, they can still create real pressure by moving fast, choosing symbolic targets, making public claims, and rallying others around a political [ ]
Executive Summary: Since Russia’s full-scale invasion of Ukraine on February 24, 2022, cyberattacks against critical infrastructure have become more visible, more frequent, and more closely tied to state power. These attacks are no longer just about stealing data or causing short-term disruption. In many cases, they are being used to weaken an opponent, prepare for [ ]
Date: June 25, 2026 TLP: CLEAR Executive Summary Russian dairy and food-sector organizations have experienced a series of cyber disruptions affecting logistics, accounting, shipment documentation, electronic veterinary certification, product labeling, public-facing websites, and consumer-trust surfaces. The most recent reported incident affected Ufagormolzavod, a large dairy producer in Ufa,…
TLP:CLEAR Analytic confidence: High for the strategic pattern, high for Russia-state linkage, medium for some specific cluster-level attribution, especially the Poland 2025 energy incident. Executive Judgment Russia has used Ukraine for more than a decade as the downrange target of an evolving cyber-warfare program. The campaign began as destabilization and coercion against Ukrainian state…
Executive Assessment APT10 is a long-running China-nexus cyber-espionage actor associated in public U.S. government attribution with China’s Ministry of State Security, specifically the Tianjin State Security Bureau, and with contractors at Huaying Haitai Science and Technology Development Company. Public reporting places APT10 activity as active from at least 2006 or 2009, depending on the source…
Executive Summary North Korean cyber operations have evolved from relatively discrete espionage and financially motivated campaigns into a highly interconnected operational ecosystem in which access generation, insider compromise, cryptocurrency theft, supply-chain intrusion, and intelligence collection reinforce one another as components of a broader state-directed strategy. Traditional…