Cyber frontlines: nations shift from digital defense to active retaliation amid hybrid warfare surge

The Hacker News ↗

The gist

Cyber warfare has gone from shadowy sabotage to open retaliation, with nations now fighting hybrid battles where digital strikes and real-world attacks are inseparable.

What to know

  • By early 2026, state-backed groups like China’s Volt Typhoon have stealthily embedded in 10 of 16 U.S. critical infrastructure sectors, setting the stage for potential destructive attacks.
  • NATO and the EU are moving from deterrence to active punishment—imposing sanctions, technology bans, and even targeting supply chains in response to Russian and Chinese cyber aggression.
  • AI-driven threats and zero-day exploits now blend cyber and physical warfare, while countries like Denmark and the U.S. ramp up offensive cyber capabilities and quantum-resistant defenses.

Cybersecurity as Geopolitical Power

Nations are weaponizing digital infrastructure and decoupling from adversaries, making cyber operations a core tool of statecraft and real-world influence.

By early 2026, cybersecurity had firmly established itself as a cornerstone of national sovereignty and global power, marking a pivotal shift from a purely technical concern to a central element of geopolitical strategy. This evolution is epitomized by the phenomenon of strategic decoupling—nations increasingly severing digital and economic ties with adversaries, as seen in responses to incidents like the Kyowon breach and Microsoft’s takedown operations. Recorded Future’s 2026 State of Security Report highlights(https://www.prnewswire.com/news-releases/recorded-future-2026-state-of-security-report-warns-cyber-operations-have-become-a-core-tool-of-global-power-302686566.html) as the inflection point when cyber operations became inseparable from real-world geopolitical outcomes, underscoring that 'security is sovereignty' in the digital age.

Cyber operations have transcended their preparatory role to become active instruments of conflict and coercion, integrating seamlessly with physical warfare and economic pressure. Dr. Christopher Ahlberg’s assertion that 'cyber operations are no longer preparation for conflict — they are part of conflict' reflects this paradigm shift, where nation-states leverage cyber access at network edges and critical connectivity infrastructure as strategic levers during crises. This persistent layer of competition is further intensified by AI-driven deception and identity abuse, which Levi Gundert notes erode trust within decision-making processes faster than institutions can respond, fueling continuous instability.

The geopolitical landscape of cybersecurity is complicated by the dual-use nature of offensive cyber tools and the increasing prominence of state-backed operations among major powers. Reports that Russian intelligence repurposed iPhone hacking tools originally developed by U.S. defense contractor L3Harris illustrate how cyber capabilities can leak and be weaponized by adversaries, raising critical questions about control and accountability. Concurrently, European intelligence warnings about hybrid warfare—combining cyber espionage, influence operations, and economic intelligence gathering by China and Russia—highlight the convergence of digital and physical domains in contemporary conflict.

Strategic decoupling extends beyond digital networks into tangible restrictions on technology and hardware to mitigate espionage risks tied to cyber vulnerabilities. For instance, Poland’s ban on Chinese-made vehicles within military installations and Texas’s lawsuit against TP-Link over national security concerns exemplify how nations are proactively severing technological dependencies. This trend, coupled with NATO’s call at the Munich Security Conference to shift from deterrence rhetoric to imposing concrete consequences on state-backed cyber aggressors like Russia and China, signals a new era where cybersecurity is a frontline domain of geopolitical power and conflict.

Sources
CISO Talk by James AzarPR Newswire - Consumer TechnologyCISO Talk by James AzarCISO Talk by James Azar

Pre-Positioning for Hybrid Conflict

Chinese and Russian cyber groups are embedding in critical infrastructure and perfecting long-term access, setting the stage for coordinated digital and physical attacks.

By early 2026, state-sponsored cyber operations have escalated into a strategic chess game of pre-positioning and hybrid warfare, with Chinese groups like Volt Typhoon embedding themselves stealthily across 10 of 16 U.S. critical infrastructure sectors, including energy and telecom, not for immediate disruption but to set conditions for potential destructive attacks amid rising geopolitical tensions over Taiwan. Simultaneously, China-linked APTs such as UAT-8837 have exploited high-severity zero-day vulnerabilities like Sitecore CVE-2025-53690 to intensify offensive campaigns against North American infrastructure, employing sophisticated open-source tools for credential harvesting and reconnaissance, and even exfiltrating DLL-based libraries that raise alarms about future supply chain compromises. This layered approach underscores a patient, long-term strategy blending cyber espionage with kinetic conflict triggers, compelling urgent responses from Western governments to secure operational technology environments.

Western democracies are shifting from reactive defense to proactive offense in cyberspace, driven largely by the lessons of Russia’s invasion of Ukraine and the increasing aggressiveness of cybercrime and influence operations targeting their own citizens. Countries including Canada, Germany, and Denmark are updating legal frameworks and recruiting specialized cyber talent—Denmark’s Defense Intelligence Service, for example, launched a hacker academy to train recruits in offensive operations. The U.S. is exploring leveraging private contractors to augment government cyber efforts, signaling a broader institutional embrace of offensive cyber capabilities as a key component of national security strategy.

The integration of cyber and kinetic warfare has become a defining feature of modern conflicts, as vividly illustrated by the Iran–US/Israel confrontation and the Russia–Ukraine war. U.S. and Israeli military strikes on Iranian infrastructure are now routinely paired with immediate cyber retaliation campaigns disrupting Iranian digital networks, while Israeli intelligence has exploited hacked surveillance systems in Tehran to directly inform missile targeting. Similarly, Russian cyber intrusions into Ukrainian infrastructure have enhanced missile strike precision through improved surveillance and targeting intelligence. This fusion of domains extends to hybrid tactics where pro-Russian ransomware groups weaponize criminal ecosystems to destabilize European governments, complicating attribution and deterrence efforts.

Coalition-based adversaries are emerging as a formidable force in hybrid warfare, exemplified by the growing collaboration between pro-Russia actors and Iran-linked hacking groups who share infrastructure, tooling, and operational tactics. Chinese espionage groups like UNC2814 have leveraged innovative covert channels such as Google Sheets APIs to maintain persistent access across telecom providers and governments in over 40 countries, while Iranian groups have mobilized extensive hacktivist coalitions under platforms like Telegram’s Electronic Operations Room to conduct retaliatory cyber operations. These alliances blur traditional boundaries, combining advanced persistent threats with psychological operations and misinformation campaigns amplified by AI-generated content, thereby expanding the battlefield into the digital and cognitive realms.

Iranian state-sponsored cyber operations have notably escalated in sophistication and destructive potential, as seen in campaigns like the Handala Hack Team’s weaponization of Microsoft Intune to remotely wipe 200,000 devices across 79 countries, and the CyberAv3ngers group’s manipulation of nearly 3,900 Rockwell Automation PLCs to disrupt U.S. water and energy infrastructure. These operations blend cyber intrusion with kinetic effects, using legitimate engineering software such as Studio 5000 Logix Designer to mimic normal operator activity and evade detection. This evolution reflects a coordinated 'one-two punch' hybrid warfare model where espionage units establish persistent access while destructive units execute impactful attacks, underscoring the merging of cyber and physical domains in state-sponsored campaigns amid heightened geopolitical tensions.

Sources
Intruvent EdgeThe Hacker NewsCISO Talk by James AzarSecurity Now (Audio)CISO Talk by James AzarCISO Talk by James Azar

Supply Chains Under Siege

State-backed attackers exploit zero-days and supply chain vulnerabilities to gain persistent access to government and infrastructure systems, fusing cyber espionage with kinetic disruption.

By early 2026, Chinese state-sponsored cyber groups have dramatically escalated their infiltration of U.S. critical infrastructure and government supply chains. Volt Typhoon, dubbed "The Silent Storm," had stealthily embedded itself across 10 of 16 critical sectors, including energy, water, and telecom, as part of what Air Force cyber leadership called the most sophisticated pre-positioning campaign in cyber history, likely intended to enable destructive attacks if a regional conflict over Taiwan erupts. Meanwhile, its espionage-focused cousin Salt Typhoon breached Congressional committee staff emails spanning Intelligence, Foreign Affairs, and Armed Services, exposing glaring vulnerabilities in government communication channels and underscoring the intertwined risks to both infrastructure and supply chains.

Supply chain vulnerabilities have become a central vector exploited by diverse state-backed groups, with zero-day exploits and sophisticated tactics amplifying operational risks. For instance, the China-linked UAT-8837 group has leveraged a high-severity zero-day in Sitecore (CVE-2025-53690) since at least 2025 to infiltrate North American critical infrastructure, employing open-source tools like SharpHound and Rubeus for credential harvesting and persistent access. This campaign's exfiltration of DLL-based shared libraries raises alarms about trojanized software and supply chain compromises, prompting urgent guidance from Western cybersecurity agencies to secure operational technology environments. Similarly, the Asian state-backed TGR-STA-1030 group breached 70 government and infrastructure entities across 37 countries using phishing, custom malware loaders, and zero-day or N-day exploits, maintaining long-term access to sensitive government functions that could disrupt physical and administrative systems.

The operational impact of cyberattacks on physical systems is increasingly tangible, with kinetic and cyber warfare converging to disrupt critical infrastructure globally. Iranian-affiliated actors, notably the CyberAv3ngers group linked to the IRGC-CEC, have escalated attacks against nearly 3,900 internet-exposed Rockwell Automation PLCs in U.S. water and energy sectors, manipulating control systems via legitimate engineering software like Studio 5000 Logix Designer to evade detection and cause confirmed service interruptions. Concurrently, Iranian-linked drone strikes targeted AWS data centers, highlighting the physical vulnerabilities underpinning cloud infrastructure. This fusion of cyber and kinetic tactics is mirrored by Russian cyber intrusions supporting missile strikes in Ukraine and pro-Russian ransomware groups aligning with geopolitical objectives in Europe, underscoring how cyber reconnaissance and disruption now directly enhance battlefield operations and infrastructure destabilization.

Supply chain security concerns have expanded beyond digital systems into physical infrastructure and connected devices, prompting regulatory and operational shifts. Poland’s ban on Chinese-made vehicles at military installations exemplifies fears that modern electric vehicles, acting as rolling IoT platforms with persistent telemetry and connectivity, pose espionage risks near sensitive sites. Similarly, Texas’s lawsuit against TP-Link over alleged Chinese affiliations signals growing scrutiny of hardware vendors at the geopolitical level. Meanwhile, vulnerabilities in telecom infrastructure persist, as demonstrated by Rapid7’s exposure of China-linked Red Menshen sleeper cells embedded in global telecom networks since 2021, exploiting edge devices from major vendors like Cisco and Juniper to gain stealthy access. These developments highlight the urgent need for multi-provider failover strategies, vendor risk reassessments, and security-by-design approaches in next-generation infrastructure to mitigate cascading supply chain and operational risks.

Sources
Intruvent EdgeCISO Talk by James AzarThe Hacker NewsThe Hacker NewsCISO Talk by James AzarBleeping Computer

Sanctions and Cyber Retaliation

NATO and the EU are tying cyberattacks to real-world reprisals, with multinational sanctions and legal reforms turning the threat of retaliation into a daily business risk.

By early 2026, NATO marked a pivotal shift from deterrence rhetoric to enforcing tangible consequences against state-backed cyber threats, particularly targeting Russia and China. This strategic evolution, publicly articulated at the Munich Security Conference by NATO’s Deputy Secretary General, signals that sanctions, trade restrictions, and diplomatic reprisals will be explicitly linked to cyber campaigns, reflecting frustration over years of Russian infrastructure attacks and Chinese espionage. Consequently, multinational organizations are urged to brace for supply chain disruptions, retaliatory cyber operations, and sanction-driven operational impacts, elevating geopolitical cyber risk to a critical board-level concern.

The European Union has intensified its punitive measures by sanctioning Chinese and Iranian firms such as Integrity Technology Group, Anxun Information Technology, and Emennet Pasargad, along with individuals involved in cyberattacks and influence campaigns targeting EU member states. These sanctions, including asset freezes, bans on financial dealings, and travel restrictions, underscore the EU’s ongoing commitment since 2019 to hold state-affiliated cyber actors accountable, exemplified by Integrity Technology Group’s role in the Raptor Train botnet compromising over 65,000 devices and Emennet Pasargad’s audacious hijacking of billboards during the 2024 Paris Olympics.

Globally, governments are recalibrating legal frameworks and operational policies to confront escalating cyber threats: Japan’s Self Defense Forces will commence authorized offensive cyber operations from October 2026, reflecting a proactive defense posture amid worsening cyber risks. Meanwhile, the U.S. advocates for flexible, partnership-driven incident response models across critical infrastructure sectors, with Acting CISA Director Nick Anderson emphasizing the need to defer to agencies best connected to affected operators to overcome bureaucratic delays, as seen in responses to Guam and telecom incidents.

Heightened geopolitical concerns over espionage and data security have prompted tangible regulatory actions beyond cyberspace, such as Poland’s ban on Chinese-made vehicles from military bases—recognizing modern electric vehicles as IoT platforms vulnerable to surveillance—and Texas’s lawsuit against TP-Link over alleged Chinese state ties. Complementing these measures, major tech companies including Google, Microsoft, and Meta have formed the Online Services Accord Against Scams to enhance cross-industry information sharing and deploy advanced fraud detection tools, illustrating an evolving synergy between government mandates and private sector initiatives to mitigate cyber geopolitical risks.

Sources
CISO Talk by James AzarCISO Talk by James AzarBleeping ComputerCybersecurity HeadlinesCyberWire DailyCISO Talk by James Azar

AI and Quantum Escalate the Stakes

AI-driven threats, patching gaps, and looming quantum decryption are outpacing defenses, forcing organizations to rethink identity, access, and encryption strategies.

By early 2026, AI-driven automation platforms like n8n have revealed critical vulnerabilities enabling unauthenticated remote code execution, with over 59,500 internet-exposed hosts still vulnerable worldwide, underscoring the persistent challenge of patching critical infrastructure software. These flaws often stem from overlooked configuration weaknesses in complex automation workflows, highlighting the difficulty of securing essential systems that cannot afford frequent downtime. As one expert noted, unlike consumer software that enforces regular updates, critical infrastructure software lacks mechanisms to mandate timely patching, leaving high-risk systems exposed for extended periods.

The cybersecurity landscape in 2026 is increasingly dominated by AI's dual role in both defense and offense, accelerating deception, identity abuse, and threat complexity faster than institutions can adapt. Recorded Future's 2026 State of Security Report highlights that most serious intrusions now begin with stolen credentials rather than technical exploits, shifting the security focus to robust identity and access governance. Moreover, AI-driven verification failures amplify social engineering at scale, while attackers exploit AI platforms as covert command-and-control channels, embedding malware instructions within AI query responses to evade detection, thus demanding comprehensive AI security governance frameworks.

Quantum computing advances are rapidly closing in on the ability to decrypt traditional RSA encryption, prompting urgent calls for crypto-agility and migration to quantum-resistant protocols like the BB84 quantum cryptography pioneered by Bennett and Brossard. This looming threat is compounded by the 'harvest now, decrypt later' campaigns, where adversaries collect encrypted data today with the expectation of decrypting it once quantum capabilities mature, forcing organizations to rethink long-term data protection strategies amid accelerating geopolitical cyber tensions.

The expanding attack surface across critical infrastructure—from cloud platforms like AWS and identity intelligence providers such as LexisNexis to network management tools like VMware Aria and Cisco SD-WAN—exposes systemic vulnerabilities that adversaries exploit for persistent access and credential theft. Compounding this, physical attacks such as Iranian drone strikes on AWS data centers reveal the fragile interdependence of cyber and physical security. These developments underscore the necessity of rigorous network segmentation, strict isolation of operational technology, and continuous credential rotation to mitigate risks in an era where nation-states and decentralized criminal coalitions collaborate and escalate cyber warfare tactics.

Sources
The Hacker NewsCyberWire DailyChinaTalkPR Newswire - Consumer TechnologyCISO Talk by James AzarCISO Talk by James Azar

Information Warfare Redefined

Nation-states now favor intelligence, disinformation, and AI-powered confusion over outright destruction, reshaping global influence and public trust in the digital age.

By early 2026, nation-state cyber strategies have evolved to prioritize intelligence gathering, reconnaissance, and sowing confusion over outright destructive attacks, as Matt Suiche observed in recent conflicts where significant destruction was notably absent. This subtle approach is complemented by sophisticated misinformation campaigns amplified by AI-generated content, flooding social media with disinformation, bots, and fabricated videos that blur truth and fiction even in peacetime, thereby shaping public perception and destabilizing adversaries without kinetic engagement.

China's cyber doctrine, rooted in early infrastructure projects like the Great Firewall and the Golden Project from the 1990s, reflects a long-term vision of stringent information control within its borders, creating a 'walled garden' that tightly manages its populace's digital environment. However, this protective barrier ironically hampers China's ability to conduct viral influence operations abroad, as attackers often expose themselves by logging into personal social media accounts once outside the firewall, limiting the global reach and stealth of their campaigns compared to Russia's more aggressive and overt tactics.

Russia, arriving later to the information control arena, has focused heavily on information warfare and influence operations, becoming a global exemplar for countries like Iran in executing effective disinformation campaigns. Unlike China, Russia's less restrictive internet environment enables these operations to gain viral traction, allowing it to guide conversations and manipulate narratives internationally, a strategy that contrasts sharply with the United States’ emphasis on freedom and innovation, where protections like Section 230 foster open expression but also create vulnerabilities to hate speech, misinformation, and election interference.

Emerging hybrid tactics blur the lines between cyber and kinetic warfare, exemplified by inexpensive drones targeting critical infrastructure such as Amazon’s cloud data centers, causing significant outages and revealing gaps in traditional threat models. This novel approach exploits centralized dependencies in cloud and AI services, signaling a shift where physical attacks complement cyber operations, thereby expanding the battlefield and complicating defense strategies for governments and tech companies alike.

Sources
Odd LotsThreat Vector by Palo Alto Networks

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.