Latest Internet & Cybersecurity News

📅April 25, 2026 at 1:00 PM
Major cybersecurity developments include pre-Stuxnet malware discovery, China-linked hacking warnings, AI theft allegations, new APTs, and FISA 702 reauthorization delays.
1

Researchers Uncover Pre-Stuxnet 'Fast16' Malware Targeting Iran's Nuclear Program

Cybersecurity researchers at SentinelOne discovered 'fast16', a Lua-based malware from 2005 designed to sabotage Iran's uranium enrichment centrifuges by tampering with high-precision calculations.Source 1 The malware, predating Stuxnet, uses a kernel driver for precision sabotage and links to NSA deconfliction signatures from a 2017 leak.Source 1 It aimed to produce inaccurate calculations across facilities when combined with propagation mechanisms.Source 1

2

Global Agencies Warn of China-Linked Covert Hacking Networks

Britain's NCSC and 15 international partners, including FBI, issued guidance on China-linked hackers using compromised routers and smart devices for covert attacks on critical infrastructure.Source 2 These networks hide origins, enable data theft, and maintain long-term access, with digital evidence disappearing quickly.Source 2 UK handles four major cyber incidents weekly, urging AI-powered defenses amid state actor threats from China, Iran, and Russia.Source 2

3

US State Dept Orders Global Warning on Chinese AI IP Theft by DeepSeek and Others

The US State Department sent a diplomatic cable urging attention to Chinese firms like DeepSeek stealing US AI intellectual property through model extraction and distillation.Source 3 This counters low-cost replication of advanced AI, amid US-China tech tensions before a Trump-Xi summit.Source 3 China denies the allegations.Source 3

4

China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks

ESET uncovered GopherWhisper, a China-based APT active since 2023, using Go-based backdoors like LaxGopher for C&C via Slack and data exfiltration in Mongolian government attacks.Source 4 It employed legitimate services, custom loaders, and injectors, infecting about 12 systems with dozens more likely targeted.Source 4 The group shows no ties to known APTs due to unique code and TTPs.Source 4

5

FISA Section 702 Reauthorization Stalls in US Congress

House Speaker Mike Johnson's five-year FISA 702 reauthorization failed on April 17, 2026, leading to a 10-day stop-gap expiring April 30.Source 5 New legislation proposes a three-year term with reforms like monthly Civil Liberties reviews and attorney approvals for US person queries.Source 5 It expands congressional access to FISA Court proceedings.Source 5

6

Pre-Stuxnet Sabotage Malware ‘Fast16’ Linked to US-Iran Cyber Tensions

The discovery of Fast16 highlights early US-Iran cyber conflicts, with the 2005 malware targeting nuclear facilities before Stuxnet.Source 4 It connects to leaked NSA tools, underscoring long history of state-sponsored sabotage.Source 1Source 4 Researchers detailed its stealthy payload in a comprehensive report.Source 1

7

Trump Administration Vows Crackdown on Chinese AI Model Exploitation

The Trump administration promises action against Chinese companies exploiting US-made AI models, aligning with State Dept warnings.Source 4 This escalates tech rivalry despite recent detente.Source 3Source 4 It precedes President Trump's Beijing visit with Xi Jinping.Source 3

8

US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor

A US federal agency's Cisco firewall was compromised by the 'Firestarter' backdoor, exposing vulnerabilities in critical infrastructure.Source 4 This incident underscores supply chain and hardware risks in government networks.Source 4 Details emerged in recent cybersecurity reports.Source 4

9

Bitwarden NPM Package Hit in Supply Chain Attack

A Bitwarden NPM package suffered a supply chain attack, potentially compromising developer credentials and software integrity.Source 4 Such attacks highlight risks in open-source ecosystems.Source 4 Immediate patches and alerts were issued.Source 4

10

Vulnerabilities Patched in CrowdStrike and Tenable Products

CrowdStrike and Tenable released patches for critical vulnerabilities exploitable by attackers.Source 4 Organizations urged to update to prevent potential breaches.Source 4 These fixes address recent security flaws in leading cybersecurity tools.Source 4

11

Locked Shields 2026: 41 Nations Strengthen Cyber Resilience

The world's largest cyber exercise, Locked Shields 2026, involved 41 nations enhancing defenses against advanced threats.Source 4 It focused on collaborative response to state-sponsored attacks.Source 4 Participants tested strategies amid rising global incidents.Source 4