<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cyberwarfare | Byte Watchr</title><link>https://bytewatchr.com/category/cyberwarfare/</link><description>State-linked operations, critical infrastructure and the security of connected societies.</description><language>en-us</language><lastBuildDate>Sun, 04 Oct 2026 02:16:47 GMT</lastBuildDate><atom:link href="https://bytewatchr.com/feeds/cyberwarfare.xml" rel="self" type="application/rss+xml"/><item><title>Warlock’s attacks on water and telecom operators expose the path from SharePoint to widespread ransomware</title><link>https://bytewatchr.com/articles/warlock-sharepoint-water-telecom-ransomware/</link><guid isPermaLink="true">https://bytewatchr.com/articles/warlock-sharepoint-water-telecom-ransomware/</guid><description>New research traces how an exposed collaboration server can become a route to disabled defenses and ransomware across a domain. The warning reaches beyond the initial patch.</description><pubDate>Sun, 04 Oct 2026 02:16:47 GMT</pubDate><category>Cyberwarfare</category></item><item><title>MI5’s research-funding alert makes the source behind a collaboration part of security review</title><link>https://bytewatchr.com/articles/mi5-cgtri-research-funding-espionage-alert/</link><guid isPermaLink="true">https://bytewatchr.com/articles/mi5-cgtri-research-funding-espionage-alert/</guid><description>MI5 says a research-funding body supports Chinese intelligence capabilities. Its alert asks institutions to examine funding relationships without assuming every contributor knew their source.</description><pubDate>Sun, 04 Oct 2026 02:16:47 GMT</pubDate><category>Cyberwarfare</category></item><item><title>Antino’s Microsoft 365 command channel challenges simple cloud allowlists</title><link>https://bytewatchr.com/articles/antino-microsoft-365-command-channel-espionage/</link><guid isPermaLink="true">https://bytewatchr.com/articles/antino-microsoft-365-command-channel-espionage/</guid><description>Cisco Talos describes a Windows backdoor using Outlook and OneDrive for command traffic. The report makes endpoint context essential to interpreting trusted cloud destinations.</description><pubDate>Sun, 04 Oct 2026 02:16:47 GMT</pubDate><category>Cyberwarfare</category></item><item><title>The QTFY disruption targeted the machinery behind concealed cyber operations</title><link>https://bytewatchr.com/articles/fbi-qtfy-botnet-disruption/</link><guid isPermaLink="true">https://bytewatchr.com/articles/fbi-qtfy-botnet-disruption/</guid><description>The FBI&#39;s August announcement offers a case for examining infrastructure disruption as an intervention with measurable, limited goals.</description><pubDate>Fri, 02 Oct 2026 07:58:57 GMT</pubDate><category>Cyberwarfare</category></item><item><title>The Salt Typhoon lessons begin in the network management plane</title><link>https://bytewatchr.com/articles/telecom-security-salt-typhoon-lessons/</link><guid isPermaLink="true">https://bytewatchr.com/articles/telecom-security-salt-typhoon-lessons/</guid><description>A historical look at the December 2024 communications-security guidance, and the operational questions it still raises.</description><pubDate>Fri, 02 Oct 2026 07:58:57 GMT</pubDate><category>Cyberwarfare</category></item><item><title>Cyberattack attribution is a chain of judgments</title><link>https://bytewatchr.com/articles/cyberattack-attribution-evidence/</link><guid isPermaLink="true">https://bytewatchr.com/articles/cyberattack-attribution-evidence/</guid><description>An infrastructure match, an activity cluster, and a judgment about state sponsorship answer different questions.</description><pubDate>Fri, 02 Oct 2026 07:58:57 GMT</pubDate><category>Cyberwarfare</category></item><item><title>What the 2024 Volt Typhoon warning taught infrastructure defenders</title><link>https://bytewatchr.com/articles/critical-infrastructure-volt-typhoon-lessons/</link><guid isPermaLink="true">https://bytewatchr.com/articles/critical-infrastructure-volt-typhoon-lessons/</guid><description>The joint advisory made persistent access and the paths toward operational systems central concerns. Its enduring lesson is to examine what an intruder could eventually reach.</description><pubDate>Fri, 02 Oct 2026 07:58:57 GMT</pubDate><category>Cyberwarfare</category></item><item><title>In operational technology, a security change is an engineering decision</title><link>https://bytewatchr.com/articles/operational-technology-security-safety/</link><guid isPermaLink="true">https://bytewatchr.com/articles/operational-technology-security-safety/</guid><description>Cybersecurity controls have to fit the physical process, its failure modes, and the people responsible for keeping it safe.</description><pubDate>Fri, 02 Oct 2026 07:58:57 GMT</pubDate><category>Cyberwarfare</category></item></channel></rss>