APT folks... is UNC3886 becoming a top-tier actor?
Revisiting UNC3886 Tactics to Defend Against Present Risk
We examine the past tactics used by UNC3886 to gain insights for insights on how to best strengthen defenses against the continued and emerging threats of this APT group.
Trend Micro (www.trendmicro.com)

Fire Ant: Hypervisor-Level Espionage Targeting VMware ESXi & vCenter | Sygnia
Discover Sygnia’s investigation into Fire Ant, an advanced cyber-espionage campaign breaching VMware ESXi, vCenter, and network appliances. Learn how the attackers bypassed traditional defenses with hypervisor-level persistence and stealth.

Sygnia (www.sygnia.co)

Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation | Google Cloud Blog
A suspected Chinese actor used a zero-day vulnerability in FortiOS and multiple custom malware families as part of an espionage campaign.
Google Cloud Blog (cloud.google.com)