Skip to main content

Emerging Threats

Brightly-lit industrial control system in a neutral server room setting.

CISA Warns of Active Exploitation of Adobe, Joomla, and Langflow Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on four high-severity vulnerabilities in Adobe, Joomla, and Langflow that are being actively exploited by hackers. Federal agencies have until July 10, 2026, to patch these flaws and avoid potential breaches.

Analyst 207
Linux workstation in a dimly lit lab with code on the laptop screen and blurred computer equipment in the background.

Linux Flaw Enables Root Control on Most Distros

A shocking 15-year-old flaw in the Linux kernel, dubbed GhostLock, allows any logged-in user to gain full root control of a machine in just five seconds - if it hasn't been patched. This vulnerability, which affects most Linux distributions, is a serious wake-up call for developers and users alike.

Analyst 207
Blurred laptop screen on a plain surface in a dimly lit room, conveying solemnity and concern.

Lawsuit Exposes AI Firms' Role in Deepfake Child Abuse Material

A shocking new lawsuit reveals that AI firms are enabling the creation of over 7,000 deepfake images of child abuse, leaving victims feeling humiliated and ashamed. The alarming case has been expanded to include two new anonymous plaintiffs, highlighting the devastating impact of this nonconsensual exploitation.

Analyst 207
Cracked software package on laptop screen with archive being extracted in background.

Vidar Stealer Campaign Exposes Code Signing Abuse and Evasion Tactics

In a clever April 2026 campaign, cyber attackers used malvertising to trick victims into downloading seemingly cracked software versions, which actually unleashed the Vidar stealer and XMRig malware via a sneaky loader called Factory-v3. The attackers cleverly hid their malware in password-protected .bin archives to evade detection.

Analyst 207
Law enforcement officials coordinate in a formal office setting.

Spain Seizes Suspect Tied to Russian Hacktivist Group

In a major cybercrime crackdown, Spanish authorities have arrested a suspect linked to a notorious pro-Russian hacktivist group, following a nearly year-long investigation sparked by a tip from the FBI. This breakthrough is a testament to global law enforcement collaboration, with the FBI vowing to continue disrupting cybercriminals worldwide.

Analyst 207
A brightly-lit office lobby with subtle hints of technology in the background.

Accenture Confirms Data Breach After Hacker Offers Stolen Source Code for Sale

Accenture swiftly responded to a data breach, confirming that a security issue was isolated and resolved, with no disruption to their operations or client services. The company remains tight-lipped about the breach's scope and impact, leaving many questions unanswered.

Analyst 207
Law enforcement setting with blurred computer screen in foreground.

Microsoft Telemetry Fingers Scattered Spider Suspect in US Crackdown

Microsoft's sharp-eyed telemetry has helped track down a suspect linked to the notorious Scattered Spider group, a prolific gang that allegedly raked in over $100 million in ransom payments by infiltrating more than 100 US company networks.

Analyst 207
Person working on laptop in modern office setting with GitHub pages on screens.

GitHub AI Agent Exposes Private Repos to Malicious Prompts

A shocking vulnerability in GitHub's AI-powered Agentic Workflows has been discovered, allowing attackers to expose private repositories with just a cleverly crafted issue and some plain English instructions - no coding skills or credentials required. This flaw lets hackers fetch and publicly share sensitive files, putting organizations at risk.

Analyst 207
Dimly lit storefront at night with scattered neon signs and a blank smartphone screen on a cluttered counter.

RedWing Malware Targets Android Users with Bank Fraud as a Service

A new, ready-to-use bank-fraud tool called RedWing is being rented on Telegram, allowing even novice criminals to hijack Android users' phones and steal their banking information. This malicious kit is sold as a complete package, complete with step-by-step guides and how-to videos, making it alarmingly easy for scammers to get started.

Analyst 207
Empty customer service area with rows of desks and chairs near a large window.

KDDI Breach Exposes 12.2M Customer Emails

A massive data breach at KDDI Corporation has put 12.2 million customer emails and 7.6 million passwords at risk, all stemming from a single unpatched vulnerability in a third-party software system. This staggering incident highlights the importance of robust cybersecurity measures, even for seemingly secure systems.

Analyst 207
Dimly lit server room with rows of computer servers and networking equipment in disarray.

Cloud Worm CAI Disrupts Rivals, Steals Secrets and Mines Crypto

Meet CAI, a malicious botnet that's disrupting rival operations, swiping sensitive secrets, and mining cryptocurrency - all while eliminating competing malware to maintain its grip on compromised targets. This centralized worm is a powerhouse of credential theft and cryptomining, making it a force to be reckoned with.

Analyst 207
GitHub issue page on laptop with public repository and subtle hint of private content exposure.

GitHub Agentic Workflows Exposed to Data Leak Threat via Public Issues

GitHub's Agentic Workflows are vulnerable to a data leak threat, as researchers have demonstrated a clever technique called GitLost that tricks AI agents into spilling private content from secure repositories into public comments. All it takes is a simple public issue to launch the attack, with no stolen credentials or special access required.

Analyst 207
Concerned business owner sits at desk, scrutinizing suspicious email on smartphone.

Meta Disrupts Phishing Campaign Targeting Facebook Business Users

Watch out for phishing scams targeting Facebook Business users - red flags include broken graphics, suspicious links, and unsolicited emails promising exciting opportunities. Experts warn that cybercriminals are getting sneaky, using legitimate-looking emails and Messenger chatbots to trick victims into taking action.

Analyst 207
Office worker looks confused at laptop screen with phone and notebook nearby.

Phishers Exploit Microsoft Device Code Flow to Hijack M365 Accounts

Cyber attackers have cleverly exploited Microsoft's device code login flow to hijack M365 accounts, using a sneaky collaboration-style lure to trick users into handing over session tokens without even needing to steal passwords. This clever tactic abuses the OAuth 2.0 Device Authorization Grant, designed for constrained devices, to bypass security measures like multifactor authentication.

Analyst 207
University campus scene with a building and clock tower, hint of computer equipment in foreground.

China-Aligned Hackers Exploit Roundcube Servers at US, Canada Universities

China-aligned hackers are targeting universities in the US and Canada, exploiting vulnerable Roundcube webmail servers to gain access to sensitive physics and engineering departments with potential national security links. This latest campaign highlights the ongoing threat of email-based attacks and the need for robust server security.

Analyst 207
Somber courthouse scene with documents on a wooden desk.

Victims of Predatorgate Sue Spyware Maker for €8 Million

Eight individuals targeted in Greece's Predator spyware scandal are taking a stand, suing the spyware maker for €8 million in moral damages after their devices were hacked between 2020 and 2021. Led by lawyer Zacharias Kesses, the group is seeking justice and accountability for the victims of this massive digital breach.

Analyst 207
Police officers stand near a computer in a softly lit home interior.

Spain foils pro-Russian hacktivist's escape plan

Spain's National Police have thwarted a daring escape plan by a suspected pro-Russian hacktivist, exposing his secret communications with terrorist groups and freezing his cryptocurrency assets. The suspect, allegedly part of the notorious CyberArmy of Russia Reborn and Z-Pentest groups, was caught after a months-long investigation sparked by a tip from the FBI.

Analyst 207
US Army facility interior with 404 error on laptop screen near computer setup.

US Army Websites Targeted in 404 Hijacking Campaign

The US Army has confirmed that two of its websites, oil.army.mil and ai2c.army.mil, were recently hijacked in a 404 error page defacement campaign, displaying politically charged messages that denigrated high-profile figures and promoted a separatist cause. The incident was discovered by independent researcher Ronald Lovelace and reported to US Army officials.

Analyst 207
University computer lab with laptops and ordinary lighting.

China-Aligned Hackers Exploit Roundcube Flaws to Infiltrate Universities

China-aligned hackers have launched a sneaky attack on universities, exploiting two flaws in the popular Roundcube webmail client to steal credentials and gain persistent access. At least a few dozen universities are believed to be affected, with Proofpoint researchers confirming fewer than 10 intrusions so far.

Analyst 207
Help desk area with technician and employees in a retail setting.

FBI Traces Scattered Spider Hacker via Persistent Windows Device ID

In a brazen ransom email, the attackers boldly declared, "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY," leaving no doubt about their malicious intentions. The hackers infiltrated the retailer's network through a clever help-desk ploy, tricking staff into resetting passwords and gaining control of critical accounts.

Analyst 207
Person holding smartphone with subtle phishing website in background, standing on city street.

Google Sues Chinese Scammers Over Gemini AI Misuse

Google is taking a stand against scammers, suing a group called Outsider Enterprise that uses its Gemini AI feature to create fake websites and scam people through text messages. The group, which operates on Telegram, offers phishing-as-a-service, making it easy for non-tech-savvy scammers to target victims.

Analyst 207
Dimly lit, cluttered hackerspace with multiple workstations, notes, and tech gadgets.

Scattered Spider Morphs into Decentralized Cybercrime Network

Meet Scattered Spider, a notorious cybercrime collective that's evolved into a decentralized network of independent clusters, sharing tactics and tools to wreak havoc online. This fresh analysis by Group-IB shatters the traditional view of a single, unified gang, revealing a more complex and dynamic threat.

Analyst 207
Virtual machine setup on a computer in a well-lit room with a monitor display.

Linux Flaw Enables VM Escape on Intel, AMD Devices

A newly disclosed 16-year-old Linux kernel vulnerability, dubbed Januscape, allows hackers to easily escape virtual machines and compromise their host systems - all with just a few clicks from within the guest system. This shocking security flaw, tracked as CVE-2026-53359, has been lurking in the kernel for nearly two decades.

Analyst 207
Police officer stands in doorway of a residential home in a quiet neighborhood.

Spain Arrests Alleged Pro-Russia Hacktivist Tied to Cyber Attacks

Hacktivists aligned with Russia are wreaking havoc on UK organizations with denial-of-service attacks that may be simple, but have a significant impact by disrupting essential services. These attacks can overwhelm important websites and online systems, leaving people unable to access the services they rely on daily.

Analyst 207