DIFF.BLOG
New Following Discover Jobs
More
Top Writers Suggest a blog Upvotes plugin
Report bug Contact About
Sign up
Topics
Follow your own topics →
Menu
New Following Discover Jobs Top Writers
More
Suggest a blog Upvotes plugin Report bug Contact About
Sign up
The home for great developer writing.
We surface the best developer writing from thousands of independent blogs, updated daily.
Join Diff.blog
TOPICS

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

· Blog Talosintelligence · Aug. 20, 2026, 12:22 p.m.
AI Threat Spotlight Cybersecurity Cybercrime AI in cybersecurity Web Server Vulnerabilities
Summary
The blog post discusses a cybercrime group known as UAT-10147 that speaks Chinese and has integrated agentic AI into their operations to target vulnerable web servers. It covers affected countries, the impact of BadIIS infections, and the attack chain and post-compromise tactics used by the group.
Read full post on blog.talosintelligence.com →
MORE POSTS LIKE THIS
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
Troy Hunt · Aug 25, 2026
Have I Been Pwned data breaches
Weekly Wire #4: Justice and Negligence
andreafortuna · Aug 9, 2026
Security dfir
The Good, the Bad and the Ugly in Cybersecurity – Week 29
Sentinelone · Jul 17, 2026
Company Weekly
Operation Endgame 4.0 - 153,527 breached accounts
Haveibeenpwned · Jun 18, 2026
Cybersecurity malware
AsyncRAT AI Lures Target Users Hunting AI Skills
Securityonline · Jun 18, 2026
AutoHotkey malware
Hypotheses, telemetry, and human judgment: Inside Cisco Talos Threat Hunting
Blog Talosintelligence · Jun 4, 2026
Top Story Landing Page Top Story
Discover more posts →
AUTHOR
BLOG POST FEATURED ON

Placeholder image
r/blueteamsec

5 points

Add this plugin to your blog
RECENT POSTS FROM THE AUTHOR
Choose how you want to continue.
Continue with GitHub Continue with Google