Skip to main content

Emerging Threats

Blockchain network operations center with large screen displaying visualization.

Cronos Restarts After $74 Million Tectonic Exploit

Cronos is back online after a swift restart, restoring its chain state to before the $74 million Tectonic exploit and resuming block production from block 90,896,189. The network had temporarily halted activity to protect users from a rapid price-manipulation attack on a major DeFi lending protocol.

Analyst 207
Windows Terminal or PowerShell window on laptop with fake CAPTCHA prompt on compromised website in background.

Microsoft Exposes TerminalFix Attacks Deploying Reverse Tunnels

Beware of TerminalFix attacks that use fake Cloudflare CAPTCHA prompts on compromised websites to trick you into executing malicious PowerShell commands in Windows Terminal. These sneaky attacks can lead to more complex threats, making it crucial to stay vigilant online.

Analyst 207
Blurred office scene with laptop screen and person's hands in foreground.

North Korea Expands Job Fraud Into New Sectors

North Korean workers are pulling off a clever scam, tricking companies into hiring them remotely and often doing legitimate work, all while hiding their true identities. Huntress has uncovered alarming cases of this employment fraud expanding into healthcare, sales, marketing, and medical fields.

Analyst 207
Windows Terminal or PowerShell window on a laptop screen with office background.

Microsoft Warns of TerminalFix Malware Hiding in PNGs

Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Analyst 207
Person sitting at desk with laptop and notebook, surrounded by blurred office background, conveying disrupted productivity.

OpenAI Disrupts ChatGPT Work Amid Outage and Error Reports

Big news for ChatGPT Work users: OpenAI is currently working to resolve an outage that's leaving many unable to start or continue tasks across multiple subscription plans, including ChatGPT Work and Plus. The company is racing to find a fix and get things back up and running smoothly.

Analyst 207
Brightly lit office with a computer screen error message, surrounded by scattered papers and empty coffee cups.

Microsoft Exchange Online Disrupts Email Services Amid Authentication Issues

Microsoft is investigating an outage that's disrupting email delivery and sign-in across Exchange Online, citing a common failure pattern linked to authentication and protocol connectivity issues. The company is actively troubleshooting and working to resolve the problem, which was first acknowledged at 5:30 PM UTC.

Analyst 207
Federal law enforcement facility interior shows signs of concern and disruption.

ATF Cyber Breach Exposes Investigative Targets

The ATF's response to the Qilin ransomware gang's claim of a breach reveals how prepared - or unprepared - the agency was to tackle the incident. A cyber breach at the ATF potentially puts sensitive investigative targets at risk, but details on the incident remain scarce.

Analyst 207
Person sitting at laptop in quiet home office with blurred screen.

Anthropic Disrupts AI Token Mining by Hijacked User Accounts

Anthropic swiftly took action against compromised accounts, logging users out and removing payment methods to prevent stolen sessions from being exploited for paid AI usage. The company assured users that its investigation found no link between the malware and its AI model, Claude.

Analyst 207
Empty office cubicle with computer and papers, suggesting recent use.

Hasbro Breach Compromises Employee Data

A single compromised employee account led to a massive data breach at Hasbro, exposing sensitive employee information, including Social Security numbers and financial data. The alarming incident highlights the importance of robust cybersecurity measures to prevent such breaches.

Analyst 207
Network devices and cables in a data center with a Cisco router and a single cable leading to a patch panel.

Chinese Hackers Exploit Cisco Routers for Covert Surveillance

Chinese hackers have cleverly exploited Cisco routers, transforming them from mere transit devices to covert surveillance platforms, as discovered by incident responders at Sygnia. This sinister manipulation allows hackers to secretly collect data, with one of the first clues being an unexplained GRE tunnel interface on a Cisco IOS XR router.

Analyst 207
A typical office interior with cubicles and workers in business attire at desks.

US Disrupts Chinese Cyber Espionage Proxy Network

The FBI has struck a major blow against Chinese cyber espionage, disrupting a proxy network used to sell reconnaissance and operational routing capabilities to malicious actors. This key takedown targeted a technical quartermaster tied to Nanjing Xinjiuwei Network Technology Company, a company linked to the notorious QTYF spy-proxy network.

Analyst 207
Multifunction printer on office shelf, surrounded by computers and chairs.

PaperCut Vulnerabilities Expose Enterprises to Elevated Threats

PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

Analyst 207
Municipal office interior with rows of desks, computers, and scattered papers.

Berlin Hit by Rhysida Ransomware, Data Theft Confirmed

Berlin's administrative network has been hit by a massive Rhysida ransomware attack, with hackers claiming to have stolen a whopping 5.79 TB of sensitive data, including 1.44 million files, and are now threatening to publish it unless paid a ransom. The breach exposes a vast array of confidential records, from government and financial data to personal info like names, email addresses, and phone numbers.

Analyst 207
Person typing on laptop in modern office workspace surrounded by papers and notes.

Aurora Ransomware Operators Leverage AI Tool Cursor in Targeted Attacks

Aurora ransomware operators are using AI tool Cursor to plan and execute targeted attacks, even going so far as to instruct it in Russian to exclude certain regions and domains. This sophisticated approach has enabled the group to breach over 20 organizations across nine countries in just a few months.

Analyst 207
Cluttered office desk with computer, papers, and tea cups, people working in background.

Silver Fox Exploits Adware to Deploy ValleyRAT Backdoor

Meet Silver Fox, a sneaky threat actor that's been using adware to disguise a powerful backdoor called ValleyRAT, which can give attackers full control over your computer. They've even hijacked a legitimate Chinese desktop wallpaper tool to spread their malicious software.

Analyst 207
A typical urban office setting with a blank laptop screen in the foreground.

ValleyRAT Exploits Adware to Evade Detection

Meet ValleyRAT, a sneaky backdoor that's been evading detection with the help of adware, infecting over 1500 users in China and India with a staggering 100,000 detections in 2026 alone. Its clever disguise was uncovered when researchers dug deeper into a suspicious installer initially labeled as ordinary adware.

Analyst 207
Person sits at cluttered desk, looking concerned while on video conference on computer with Microsoft Teams on screen.

Microsoft Teams Targeted in Voice Phishing Campaigns

Beware of voice phishing scams on Microsoft Teams! A recent campaign, dubbed Spring Ring, used fake IT help desk accounts to trick over 150 employees across 10 organizations into granting remote access.

Analyst 207
Rack of networking equipment including a Cisco router in a control room.

Fire Ant Exploits Cisco Routers to Harvest Credentials and Evade Detection

When hackers take control of routers like Cisco's IOS XR, they don't just gain access - they gain a bird's-eye view of the entire network, allowing them to harvest sensitive credentials and fly under the radar. The notorious Fire Ant group recently exploited these routers to turn them into intelligence collection platforms, putting countless networks at risk.

Analyst 207
US law enforcement officials gather in a formal briefing room with a blurred emblem in the background.

US Extradites Nigerians for Sextortion Linked to Teen Deaths

The FBI and DOJ have brought two Nigerian men, Adebola Festus Adekunle and Mudasiru Afeez Olawale, back to the US to face charges for their roles in a sextortion scheme that tragically led to the deaths of two young victims. This case is a stark reminder that sextortion is a heinous crime that the FBI is committed to stopping, no matter where the perpetrators hide.

Analyst 207
US government agency headquarters building exterior in daytime.

US Agencies Targeted in Chinese Cyber Espionage Operation

The US Department of Justice made a telling edit to their recent press release, quietly changing the wording from "victims" to "among the targets" of a China-linked hacking group that hit several high-profile US agencies. This subtle shift highlights the scope of a brazen cyber espionage operation that compromised sensitive government networks.

Analyst 207
Airport terminal interior with passengers and blurred check-in counter.

FulcrumSec Hack Exposes 86 GB of Manchester Airports Data

Manchester Airports Group swiftly sprang into action after a hack, reassuring customers that they've taken robust measures to safeguard their info and reaching out to those affected, including those with upcoming bookings, to offer extra support. Meanwhile, hackers FulcrumSec claimed responsibility, boasting of swiping 86 GB of sensitive data.

Analyst 207
Person sitting at desk with laptop, looking worried, surrounded by papers and notes in a calm home office setting.

Anthropic Warns of Infostealer Malware Hijacking Claude Sessions

Beware of infostealer malware that's hijacking Claude sessions! Anthropic is taking swift action to protect users, including signing them out of compromised accounts, removing saved payment methods, and offering refunds for unauthorized charges.

Analyst 207
Laptop on a table displays a blurred Chrome Web Store page surrounded by out-of-focus software boxes.

Malicious Chrome Extensions Expose Crypto, Browser Data Theft

Malicious Chrome extensions have been caught stealing cryptocurrency and browser data, with a recent investigation uncovering a sophisticated malware campaign that may have been active since early 2024. The attack used 16 distinct modules to deliver a modular malware framework to unsuspecting Chrome and Edge users.

Analyst 207
Person sits at desk with laptop displaying blurred CAPTCHA prompt on screen.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs

Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Analyst 207