惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Jina AI
Jina AI
小众软件
小众软件
GbyAI
GbyAI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
D
DataBreaches.Net
腾讯CDC
V
Visual Studio Blog
博客园 - 叶小钗
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
T
The Blog of Author Tim Ferriss
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
博客园 - 三生石上(FineUI控件)
云风的 BLOG
云风的 BLOG
The Cloudflare Blog
MongoDB | Blog
MongoDB | Blog
有赞技术团队
有赞技术团队
U
Unit 42
博客园 - 司徒正美
博客园 - 聂微东

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
AI-Powered Public Surveillance and Biometric Data Collect...
Tushar Subhra Dutta · 2026-06-19 · via Cyber Security News

Governments are expanding their digital reach in ways unimaginable just a decade ago. A growing wave of AI-powered surveillance, biometric data collection, and commercial spyware is reshaping how states monitor citizens and visitors.

The scale of this shift is drawing urgent attention from security professionals and human rights organizations worldwide.

A new analysis covering 193 countries finds that government digital surveillance poses high or very high risk in 31 nations.

State actors exploit telecommunications infrastructure, deploy commercial spyware, and use AI-driven tools to track foreign nationals with little to no legal accountability. An additional 55 medium-risk countries use surveillance against political opponents, journalists, and activists.

Analysts at Recorded Future said in a report shared with Cyber Security News (CSN) that five broad categories of surveillance capabilities have been identified: network interception, endpoint compromise, platform-level access, public space surveillance, and data aggregation.

The Insikt Group stressed that the risk of abuse is significantly higher in countries where independent oversight is weak or absent.

Foreign nationals and business travelers face serious exposure in high-risk jurisdictions.

Risks include theft of sensitive corporate data, intellectual property loss, reputational damage, and in some cases physical detention driven by digitally gathered intelligence.

Insikt Group found that travelers who fail to prepare before entering certain countries place both themselves and their organizations at real risk.

The convergence of commercial spyware, AI tools, and growing biometric databases is accelerating the threat.

In April 2026, the United Kingdom assessed that roughly 100 countries had procured commercial spyware, signaling a steep drop in barriers to state-level intrusion. Without stronger oversight globally, individuals and organizations remain increasingly exposed.

AI-Powered Public Surveillance and Biometric Data Collection

AI-powered public surveillance has become central to government monitoring in authoritarian states.

Safe City projects, many built using hardware from Chinese technology firms, incorporate facial recognition and license plate readers across cities in Africa, Central Asia, and Eastern Europe.

Following protests in Turkey in March 2025, authorities used AI facial recognition to identify and detain demonstrators the morning after rallies.

A model of State Digital Surveillance Capabilities (Source - Recordedfuture)
A model of State Digital Surveillance Capabilities (Source – Recordedfuture)

Biometric databases represent a deeply intrusive layer of this architecture. Russia’s Unified Biometric System requires foreigners to submit biometric data to a state repository when obtaining mobile services, and the government is building a digital profile drawing from at least 14 agencies.

Myanmar’s military has merged SIM records, airport data, CCTV footage, and identity files into a unified database to eliminate anonymity.

Predictive policing tools add another dimension to the threat. South Korea’s Dejaview system uses historical crime data with real-time CCTV analysis to flag potential criminal behavior.

Digital rights groups warn such tools violate necessity and proportionality and carry serious bias risks against minority communities.

Commercial Spyware and Endpoint Surveillance

Governments are also deploying endpoint tools that directly compromise individual devices. From 2024 to 2026, Insikt Group found evidence that at least 16 countries deployed Predator or Candiru spyware against journalists and civil society members.

In February 2026, Amnesty International confirmed Predator targeted an Angolan journalist, the first forensically verified case against Angolan civil society.

Custom state-built malware is harder to detect. Leaked data from Chinese firm Knownsec revealed GhostX, a Windows remote access trojan enabling screen monitoring, keystroke logging, and password extraction.

Belarus’s KGB was linked to ResidentBat, active since at least 2021, used to pull call logs and stored files from detained activists.

Digital forensics tools are also being misused. Kazakh authorities used Cellebrite’s extraction system to unlock an activist’s phone in early 2026, while Serbian police used similar tools to install NoviSpy spyware on detainees during interrogations.

These cases show how legitimate forensic tools become instruments of repression when oversight is absent.

To reduce exposure, Insikt Group recommends travelers to very high-risk countries use only sterile devices in a Faraday bag. For high-risk destinations, a VPN, pre-departure firmware patches, and end-to-end encrypted apps are essential.

In medium-risk areas, keeping apps updated, avoiding politically sensitive content, and enabling strict social media privacy settings provide a solid protective baseline.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.