Skip to main content

Emerging Threats

Somber courthouse scene with documents on a wooden desk.

Victims of Predatorgate Sue Spyware Maker for €8 Million

Eight individuals targeted in Greece's Predator spyware scandal are taking a stand, suing the spyware maker for €8 million in moral damages after their devices were hacked between 2020 and 2021. Led by lawyer Zacharias Kesses, the group is seeking justice and accountability for the victims of this massive digital breach.

Analyst 207
Police officers stand near a computer in a softly lit home interior.

Spain foils pro-Russian hacktivist's escape plan

Spain's National Police have thwarted a daring escape plan by a suspected pro-Russian hacktivist, exposing his secret communications with terrorist groups and freezing his cryptocurrency assets. The suspect, allegedly part of the notorious CyberArmy of Russia Reborn and Z-Pentest groups, was caught after a months-long investigation sparked by a tip from the FBI.

Analyst 207
US Army facility interior with 404 error on laptop screen near computer setup.

US Army Websites Targeted in 404 Hijacking Campaign

The US Army has confirmed that two of its websites, oil.army.mil and ai2c.army.mil, were recently hijacked in a 404 error page defacement campaign, displaying politically charged messages that denigrated high-profile figures and promoted a separatist cause. The incident was discovered by independent researcher Ronald Lovelace and reported to US Army officials.

Analyst 207
University computer lab with laptops and ordinary lighting.

China-Aligned Hackers Exploit Roundcube Flaws to Infiltrate Universities

China-aligned hackers have launched a sneaky attack on universities, exploiting two flaws in the popular Roundcube webmail client to steal credentials and gain persistent access. At least a few dozen universities are believed to be affected, with Proofpoint researchers confirming fewer than 10 intrusions so far.

Analyst 207
Help desk area with technician and employees in a retail setting.

FBI Traces Scattered Spider Hacker via Persistent Windows Device ID

In a brazen ransom email, the attackers boldly declared, "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY," leaving no doubt about their malicious intentions. The hackers infiltrated the retailer's network through a clever help-desk ploy, tricking staff into resetting passwords and gaining control of critical accounts.

Analyst 207
Person holding smartphone with subtle phishing website in background, standing on city street.

Google Sues Chinese Scammers Over Gemini AI Misuse

Google is taking a stand against scammers, suing a group called Outsider Enterprise that uses its Gemini AI feature to create fake websites and scam people through text messages. The group, which operates on Telegram, offers phishing-as-a-service, making it easy for non-tech-savvy scammers to target victims.

Analyst 207
Dimly lit, cluttered hackerspace with multiple workstations, notes, and tech gadgets.

Scattered Spider Morphs into Decentralized Cybercrime Network

Meet Scattered Spider, a notorious cybercrime collective that's evolved into a decentralized network of independent clusters, sharing tactics and tools to wreak havoc online. This fresh analysis by Group-IB shatters the traditional view of a single, unified gang, revealing a more complex and dynamic threat.

Analyst 207
Virtual machine setup on a computer in a well-lit room with a monitor display.

Linux Flaw Enables VM Escape on Intel, AMD Devices

A newly disclosed 16-year-old Linux kernel vulnerability, dubbed Januscape, allows hackers to easily escape virtual machines and compromise their host systems - all with just a few clicks from within the guest system. This shocking security flaw, tracked as CVE-2026-53359, has been lurking in the kernel for nearly two decades.

Analyst 207
Police officer stands in doorway of a residential home in a quiet neighborhood.

Spain Arrests Alleged Pro-Russia Hacktivist Tied to Cyber Attacks

Hacktivists aligned with Russia are wreaking havoc on UK organizations with denial-of-service attacks that may be simple, but have a significant impact by disrupting essential services. These attacks can overwhelm important websites and online systems, leaving people unable to access the services they rely on daily.

Analyst 207
Person at computer looks concerned with Microsoft Teams interface blurred, suspicious message in background.

Microsoft Teams Users Targeted by Fake IT Support Scam

Beware of fake IT support scammers on Microsoft Teams who are tricking unsuspecting workers into installing malware by posing as tech support staff. These impostors are using the popular collaboration platform to deceive and compromise employee devices.

Analyst 207
Modern university hallway with offices and classrooms, natural daylight from large windows.

China-Aligned Hackers Exploit Roundcube Flaws at Universities

China-aligned hackers are exploiting vulnerabilities in Roundcube email servers to gain access to sensitive university networks, specifically targeting physics and engineering departments with national security ties. They've cleverly designed their attacks to fly under the radar, using tactics like compromised senders and spoofed domains to reach their targets.

Analyst 207
Brightly-lit office workstation with laptop and server equipment.

Adobe ColdFusion Flaw Exploited in Targeted Attacks

With 775 exposed ColdFusion instances online, a newly patched flaw is being exploited by attackers, putting countless systems at risk. Adobe has urgently warned customers to apply updates immediately to protect against this and 10 other critical vulnerabilities.

Analyst 207
A typical home network setup with a router, laptop, smartphone, and books, focusing on the router's visible lights and ports.

Tenda Router Firmware Exposes Hidden Admin Backdoor

A critical vulnerability in Tenda router firmware, tracked as CVE-2026-11405, allows hackers to bypass password verification and gain full administrative control of your device. This hidden backdoor puts your online security at risk, and a patch is still pending.

Analyst 207
Rows of computer servers and storage equipment in a modern data center.

AI-Powered Ransomware Targets Victims with Autonomous Attacks

Imagine a ransomware attack that can think and act on its own - that's what Sysdig researchers recently observed, as an AI agent autonomously carried out a complex extortion operation with alarming speed and efficiency. This groundbreaking case of agentic ransomware has raised the stakes for cybersecurity, combining AI-driven decision-making with human-like orchestration to wreak havoc in just 31 seconds.

Analyst 207
Laptop screen displays Microsoft Teams call on a home office desk with a phone and headset nearby.

Microsoft Teams Abused to Deploy EtherRAT Malware via Fake IT Support Calls

Beware of fake IT support calls on Microsoft Teams - hackers are using convincing tactics, including a phishing email with a malicious PDF, to trick victims into downloading the potent EtherRAT malware. They impersonate system administrators to gain your trust, making it crucial to stay vigilant.

Analyst 207
Modern Israeli government or IT office lobby with people walking in background.

Iran-Linked Hackers Deploy Cavern C2 Framework to Target Israeli Organizations

Iran-linked hackers have launched a sophisticated cyber attack campaign, dubbed Cavern Manticore, targeting Israeli organizations, particularly in the IT and government sectors, using a cutting-edge .NET-based framework. This threat cluster is affiliated with Iran's Ministry of Intelligence and Security, and its tactics overlap with other notorious groups like MuddyWater and Lyceum.

Analyst 207
Marketing professional looks concerned, holding smartphone amidst papers and laptop.

Phishing Campaign Targets Google Accounts with Fake Job Interviews

Beware of fake job interviews that could be phishing scams! A clever new campaign is targeting marketing pros with emails that appear to be from recruiters, aiming to trick them into handing over their Google account credentials.

Analyst 207
Security researcher examines laptop amidst servers with Gitea Docker setup.

Threat Actors Probe Gitea Docker Flaw Just 13 Days After Patch

Security researchers have spotted threat actors probing a critical Gitea Docker flaw just 13 days after it was patched, highlighting the urgent need for users to update their systems. This highly vulnerable flaw, scoring 9.8, allows attackers to exploit a default setting that trusts user headers from any source IP address.

Analyst 207
Modern Vietnamese government office with a laptop displaying blurred anime on screen.

Vietnam Cracks Down on HiAnime Piracy Ring

Vietnamese authorities have cracked down on a massive anime piracy ring, HiAnime, which raked in a staggering $12.85 million in illicit ad revenue from 2020 to 2026. This notorious site drew hundreds of millions of visitors monthly, briefly outpacing Disney+ and Crunchyroll in web traffic.

Analyst 207
European Parliament interior with desk, laptop, and papers under soft daylight.

EU Faces Calls to Act as Pegasus Spyware Targets MEP

The discovery of Pegasus spyware on MEP Stelios Kouloglou's phone raises alarming questions about the integrity of Europe's oversight mechanisms, particularly when he was actively investigating spyware abuse by European countries. This incident highlights a disturbing threat to independent scrutiny at the highest levels.

Analyst 207
Government building in Tel Aviv with people walking nearby, hint of cyber threat in background.

Iran-Linked Cavern Manticore Targets Israel with Modular Cyber Attacks

Meet Cavern Manticore, a highly skilled and disciplined cyber threat group with ties to Iran, targeting Israel's defense and government sectors with modular attacks. Their sophisticated tactics have allowed them to infiltrate organizations with alarming speed and precision.

Analyst 207
Laptop screen displays innocuous webpage with subtle hidden code in background.

Web Content Conceals Hidden Instructions Targeting AI Agents

As AI agents increasingly interact with the web, hidden instructions embedded in online content can be manipulated to perform unintended actions, posing a new threat to users. Researchers have uncovered real-world campaigns that use indirect prompt injection to steer AI agents into carrying out malicious tasks.

Analyst 207
Server room with equipment racks and monitors, a lone blank laptop screen in foreground.

Ransomware Operators Leverage AI for Autonomous Attacks

Meet JADEPUFFER, a pioneering threat actor that's harnessing AI to launch autonomous ransomware attacks - and adapting in real-time to get the job done. This groundbreaking tactic has been observed by researchers, who spotted JADEPUFFER's lightning-fast 31-second pivot from a failed login to a successful exploit.

Analyst 207
Laptop screen shows generic browser homepage with subtle hint of malicious mod installation in background.

Opera GX Flaw Enables Sites to Auto-Install Malicious Mods

A critical flaw in Opera GX allowed websites to secretly install malicious customization mods, which could then siphon sensitive data from other sites you visited - and it took a $5,000 bounty and a May 8 patch to fix the issue. This sneaky exploit let attackers install mods without your consent, putting your online security at risk.

Analyst 207