The Latest Addition to Turla’s Intelligence Gathering Apparatus

https://storage.googleapis.com/gweb-cloudblog-publish/images/03_ThreatIntelligenceWebsiteBannerIdeas_BA.max-2600x2600.png

Written by: Jordan Jones


Introduction

Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla. The group has a long history of targeting a wide range of industries, with a particular focus on western Ministries of Foreign Affairs, and defense organizations within the context of heightened political tensions.

Turla, and specifically their longstanding Snake implant, has been publicly attributedby the United States Cybersecurity and Infrastructure Security Agency (CISA) to Center 16 of Russia’s...

Copyright of this story solely belongs to google.com. To see the full text click HERE

Read more

https://www.itvoice.in/wp-content/uploads/2026/08/Copy-of-Redington-2026-08-01T145026.428.jpg

Anthropic Discloses Security Misconfiguration as Claude AI Models Access Live Systems During Cybersecurity Evaluation

AI safety firm Anthropic revealed that three of its Claude AI models accidentally accessed real-world corporate systems during offensive cybersecurity testing. The incidents occurred after a misconfiguration in third-party testing infrastructure left the evaluation environment connected to the live internet rather than being fully isolated. Cause and Specific Incidents Following