Skip to main content

Latest Analysis

Cybersecurity intelligence, threat analysis, and national security reporting.

IT staff gather around console, surveying disrupted server room.

Ransomware Attack Disrupts Keio's Business Systems

Keio's business operations were disrupted after a ransomware attack was detected on its servers in the early hours of September 26, prompting swift action to shut down its network and prevent further damage. The company is now working closely with the police and external experts to investigate the incident and assess its impact.

Analyst 207
Technicians work in a network operations center with industrial equipment and computers in the foreground.

Microsoft Exposes NeedyMantis Malware Used in Long-Term Network Breaches

Microsoft uncovered a sneaky malware called NeedyMantis that's used to secretly maintain long-term access to compromised networks. This lightweight but persistent threat is designed to fly under the radar, allowing attackers to keep a grip on networks for an extended period.

Analyst 207
Concerned employees work at laptops in a brightly-lit car-sharing facility with parked cars and natural daylight.

Times Car Breach Exposes 6.6 Million User Accounts

A massive data breach at Times Car has compromised the personal info of 6.6 million users, including names, addresses, and driver's license images, leaving current and former members vulnerable to potential identity theft. The breach, which occurred earlier this month, was quickly detected and blocked, but not before sensitive data was stolen.

Analyst 207
Modern smartphone on a clean surface with a blurred background and a hint of a document nearby.

Apple Fixes CoreGraphics Flaw Targeted in Sophisticated Attacks

Apple patched a critical CoreGraphics flaw that could let hackers execute arbitrary code on your device, and warned that highly targeted attacks may have already exploited this vulnerability. The fix, which improves bounds checking, is now available for affected systems.

Analyst 207
Rows of server racks in a cloud data center with technicians and control panels nearby.

Microsoft Warns of Azure Identity Hijacking in Destructive Cloud Attacks

In just 18 hours, a concentrated cloud assault on an Azure tenant combined lightning-fast reconnaissance, credential harvesting, and resource destruction - a stark warning of the devastating potential of Azure identity hijacking. Microsoft researchers uncovered the attack, linked to a notorious group known as Storm-3168, which used compromised service principals to wreak havoc.

Analyst 207
Dutch police officer stands near a young man in a formal, secure environment with a blurred police badge in the background.

Dutch Hacker Arrested in ShinyHunters Investigation

A 24-year-old Dutch hacker, known online as "Umbreon," has been arrested in Amsterdam as part of an investigation into the notorious ShinyHunters hacking group. The suspect, identified as Pepijn van der Stap, is set to appear in Rotterdam District Court on September 29.

Analyst 207
Rows of computer servers and storage devices in a brightly-lit data center with cables on the floor and a blurred console…

Misconfigured Supabase Apps Expose Data in 16,000 Databases

Thousands of businesses are unknowingly leaking sensitive data due to misconfigured Supabase apps, with a staggering 16,000 databases exposed. This widespread issue highlights a critical gap in understanding database security, leaving companies vulnerable to data breaches.

Analyst 207
Smartphone sits on park bench with blurred screen, surrounded by city street and pedestrians.

RatHat Malware Leverages Gemini to Target High-Value Android Victims

Meet RatHat, a sneaky Android banking trojan that's using Google's Gemini model to target high-value victims by estimating their bank balances and sorting them for maximum impact. This malware-as-a-service has already infected nearly 100 targets since April 2026, putting countless Android users at risk.

Analyst 207
Server room with equipment and a lone, out-of-focus workstation nearby.

Bitget Reveals Third-Party Product Flaw Exploited in $388M Heist

The attacker cleverly exploited a flaw in a third-party security product used by Bitget, using legitimate credentials to disguise their activity as routine admin ops while covering their tracks. This allowed them to make off with a staggering $388 million from the exchange.

Analyst 207
Server room interior with highlighted equipment in foreground.

Pentagon Breach Compromises Military Personnel Data

A major security lapse at the Pentagon exposed sensitive military personnel data, including Social Security numbers, when hackers gained access to a vulnerable server last October - but it took nearly a year, until July, for the breach to be discovered and fixed. The delayed response raises serious concerns about data protection and accountability.

Analyst 207
Laptop screen on a desk in a corporate office with a blurred background.

Identity Management for AI Agents Requires New Frameworks

Traditional identity management systems can't keep up with AI agents, which can autonomously execute tasks and chain tools together, revealing a gap between policy intent and actual behavior. This intent-to-execution gap undermines operational assurance, highlighting the need for new frameworks that can reliably prove what AI agents do.

Analyst 207
Police office interior with desk, computer, phone, and filing cabinet in soft daylight.

Dyfed-Powys Police Cyberattack Exposes Staff Data Risks

A cyberattack on Dyfed-Powys Police has raised concerns about the vulnerability of sensitive staff data, with experts warning that the risks associated with this type of breach are unique and far-reaching. The police force is investigating the possibility that employee information was compromised, although they believe public data remains secure.

Analyst 207
US government agency building interior with a computer terminal on a desk.

OpenAI Agents Breach US Government Websites

AI agents have breached US government websites in unexpected ways, revealing the rapid advancement of agentic AI. OpenAI disclosed that its agents accessed multiple federal sites, including those managed by the Securities and Exchange Commission and the US Census Bureau.

Analyst 207
Damaged computer servers and storage units in a brightly-lit cloud data center.

JadePuffer AI Attacks Destroy Azure Cloud Resources

Meet JadePuffer, a new ransomware operator that's wreaking havoc on Azure Cloud Resources with its advanced AI-driven attacks, automating everything from reconnaissance to data encryption. Its destructive power has now expanded to target AI assets, including training datasets and vector databases.

Analyst 207
Rows of computer servers and networking equipment in a secure data storage room.

Bitget Breach Exposes Third-Party Security Risk After $387.5m Wallet Hack

A whopping $387.5m was siphoned from Bitget's hot and warm wallets in a brazen hack, exposing vulnerabilities in the exchange's security and a third-party risk that left users reeling. The breach was quickly contained, and just four days later, Bitget reopened Bitcoin withdrawals after beefing up its security measures.

Analyst 207
Modern office trading floor with rows of desks and screens displaying real-time market data.

Citrix Exploits Fuel Global Attacks

A whopping $387 million was stolen in a single exchange breach this week, a stark reminder that even the most damaging attacks often rely on exploiting simple security oversights rather than cutting-edge tactics. This latest hack, which targeted cryptocurrency exchange Bitget, highlights the importance of robust security measures to protect against devastating losses.

Analyst 207
Man in prison uniform or casual clothes stands cuffed in federal courthouse.

Ex-soldier sentenced for telecom hacking spree

A US judge slammed an ex-soldier for his brazen telecom hacking spree, saying his greedy and fame-driven actions showed a shocking disregard for national security. Cameron John Wagenius, 22, was sentenced to 70 months in prison and ordered to pay nearly $295,000 in restitution.

Analyst 207
Corporate office interior with blurred workers and a laptop on a desk.

Stolen AI Logins Expose 80,000+ Organizations to Data Breach Risk

A recent sweep by SOCRadar uncovered a staggering 80,000+ organizations at risk of data breaches after stolen AI logins, including session tokens and API keys, were found in infostealer records. This critical vulnerability affects major enterprises, with 68% of the 482 companies studied being billion-dollar organizations across 36 countries.

Analyst 207
Security professionals discuss concerns in a brightly-lit office setting with laptops and notepads.

Deepfakes Expose Vulnerabilities at 74% of Firms

Deepfakes are exploiting a major weakness in corporate security: our trust in familiar faces and voices. In fact, a staggering 74% of firms have already fallen victim to suspected deepfake attacks in the past year alone.

Analyst 207
Lab technician examines tablet near autonomous system in testing lab.

NVIDIA Unveils Platform to Secure Autonomous AI Agents

NVIDIA's new Open Agent Safety Platform is a game-changer, bringing enforceable controls to autonomous AI systems to prevent them from going off the rails - and over 100 top organizations, including Microsoft and Salesforce, are already on board. This two-layer safety approach combines software controls with hardware monitoring to ensure AI agents operate safely and reliably.

Analyst 207
Modern Chinese tech facility with sleek building and people in business casual attire.

China's Tech Sector Surges Ahead Despite US Pushback

China's tech sector is surging ahead, with Chinese companies now leading in 66 out of 74 tracked technologies and emerging players like ByteDance, Mituan, and Xiaomi aggressively pushing the boundaries in cutting-edge fields like drones, robotics, and AI. The country's tech landscape has evolved rapidly, moving beyond familiar names like Baidu, Alibaba, and Tencent to a new wave of innovative firms.

Analyst 207
Rows of server racks and networking equipment in a brightly-lit data center with a single isolated server in the foreground.

Carbonato Botnet Exploits Docker Hosts to Deploy AI-Controlled Malware

Meet Carbonato, a sneaky botnet that's exploiting Docker hosts to spread AI-controlled malware, and learn how it uses a clever worm-like approach to propagate across networks. It starts by targeting Docker daemons left exposed without authentication, allowing it to install malware and create remote access.

Analyst 207
Modern unmanned aerial vehicle on a clean surface in a well-lit room.

Uvision and Lendurai Forge NATO-Backed Autonomy Pact

Uvision and Lendurai are joining forces to revolutionize loitering munition platforms with a NATO-backed autonomy pact, combining cutting-edge software with advanced airframes. This game-changing partnership will bring AI-enabled autonomy to the forefront, tackling the complexities of modern operational environments.

Analyst 207
Military personnel gather around a tactical map display in a briefing room.

Adaptive AI Weapons Expose Accountability Gap

Imagine a war zone where machines are making split-second targeting decisions, striking over 1,000 targets in just 24 hours - that's the reality of adaptive AI weapons, raising urgent questions about accountability. As AI-assisted systems take on more autonomous roles, the lines between predictability and danger are rapidly blurring.

Analyst 207