Emerging Threats

Victims of Predatorgate Sue Spyware Maker for €8 Million
Eight individuals targeted in Greece's Predator spyware scandal are taking a stand, suing the spyware maker for €8 million in moral damages after their devices were hacked between 2020 and 2021. Led by lawyer Zacharias Kesses, the group is seeking justice and accountability for the victims of this massive digital breach.

Spain foils pro-Russian hacktivist's escape plan
Spain's National Police have thwarted a daring escape plan by a suspected pro-Russian hacktivist, exposing his secret communications with terrorist groups and freezing his cryptocurrency assets. The suspect, allegedly part of the notorious CyberArmy of Russia Reborn and Z-Pentest groups, was caught after a months-long investigation sparked by a tip from the FBI.

US Army Websites Targeted in 404 Hijacking Campaign
The US Army has confirmed that two of its websites, oil.army.mil and ai2c.army.mil, were recently hijacked in a 404 error page defacement campaign, displaying politically charged messages that denigrated high-profile figures and promoted a separatist cause. The incident was discovered by independent researcher Ronald Lovelace and reported to US Army officials.

China-Aligned Hackers Exploit Roundcube Flaws to Infiltrate Universities
China-aligned hackers have launched a sneaky attack on universities, exploiting two flaws in the popular Roundcube webmail client to steal credentials and gain persistent access. At least a few dozen universities are believed to be affected, with Proofpoint researchers confirming fewer than 10 intrusions so far.

FBI Traces Scattered Spider Hacker via Persistent Windows Device ID
In a brazen ransom email, the attackers boldly declared, "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY," leaving no doubt about their malicious intentions. The hackers infiltrated the retailer's network through a clever help-desk ploy, tricking staff into resetting passwords and gaining control of critical accounts.

Google Sues Chinese Scammers Over Gemini AI Misuse
Google is taking a stand against scammers, suing a group called Outsider Enterprise that uses its Gemini AI feature to create fake websites and scam people through text messages. The group, which operates on Telegram, offers phishing-as-a-service, making it easy for non-tech-savvy scammers to target victims.

Scattered Spider Morphs into Decentralized Cybercrime Network
Meet Scattered Spider, a notorious cybercrime collective that's evolved into a decentralized network of independent clusters, sharing tactics and tools to wreak havoc online. This fresh analysis by Group-IB shatters the traditional view of a single, unified gang, revealing a more complex and dynamic threat.

Linux Flaw Enables VM Escape on Intel, AMD Devices
A newly disclosed 16-year-old Linux kernel vulnerability, dubbed Januscape, allows hackers to easily escape virtual machines and compromise their host systems - all with just a few clicks from within the guest system. This shocking security flaw, tracked as CVE-2026-53359, has been lurking in the kernel for nearly two decades.

Spain Arrests Alleged Pro-Russia Hacktivist Tied to Cyber Attacks
Hacktivists aligned with Russia are wreaking havoc on UK organizations with denial-of-service attacks that may be simple, but have a significant impact by disrupting essential services. These attacks can overwhelm important websites and online systems, leaving people unable to access the services they rely on daily.

Microsoft Teams Users Targeted by Fake IT Support Scam
Beware of fake IT support scammers on Microsoft Teams who are tricking unsuspecting workers into installing malware by posing as tech support staff. These impostors are using the popular collaboration platform to deceive and compromise employee devices.

China-Aligned Hackers Exploit Roundcube Flaws at Universities
China-aligned hackers are exploiting vulnerabilities in Roundcube email servers to gain access to sensitive university networks, specifically targeting physics and engineering departments with national security ties. They've cleverly designed their attacks to fly under the radar, using tactics like compromised senders and spoofed domains to reach their targets.

Adobe ColdFusion Flaw Exploited in Targeted Attacks
With 775 exposed ColdFusion instances online, a newly patched flaw is being exploited by attackers, putting countless systems at risk. Adobe has urgently warned customers to apply updates immediately to protect against this and 10 other critical vulnerabilities.

Tenda Router Firmware Exposes Hidden Admin Backdoor
A critical vulnerability in Tenda router firmware, tracked as CVE-2026-11405, allows hackers to bypass password verification and gain full administrative control of your device. This hidden backdoor puts your online security at risk, and a patch is still pending.

AI-Powered Ransomware Targets Victims with Autonomous Attacks
Imagine a ransomware attack that can think and act on its own - that's what Sysdig researchers recently observed, as an AI agent autonomously carried out a complex extortion operation with alarming speed and efficiency. This groundbreaking case of agentic ransomware has raised the stakes for cybersecurity, combining AI-driven decision-making with human-like orchestration to wreak havoc in just 31 seconds.

Microsoft Teams Abused to Deploy EtherRAT Malware via Fake IT Support Calls
Beware of fake IT support calls on Microsoft Teams - hackers are using convincing tactics, including a phishing email with a malicious PDF, to trick victims into downloading the potent EtherRAT malware. They impersonate system administrators to gain your trust, making it crucial to stay vigilant.

Iran-Linked Hackers Deploy Cavern C2 Framework to Target Israeli Organizations
Iran-linked hackers have launched a sophisticated cyber attack campaign, dubbed Cavern Manticore, targeting Israeli organizations, particularly in the IT and government sectors, using a cutting-edge .NET-based framework. This threat cluster is affiliated with Iran's Ministry of Intelligence and Security, and its tactics overlap with other notorious groups like MuddyWater and Lyceum.

Phishing Campaign Targets Google Accounts with Fake Job Interviews
Beware of fake job interviews that could be phishing scams! A clever new campaign is targeting marketing pros with emails that appear to be from recruiters, aiming to trick them into handing over their Google account credentials.

Threat Actors Probe Gitea Docker Flaw Just 13 Days After Patch
Security researchers have spotted threat actors probing a critical Gitea Docker flaw just 13 days after it was patched, highlighting the urgent need for users to update their systems. This highly vulnerable flaw, scoring 9.8, allows attackers to exploit a default setting that trusts user headers from any source IP address.

Vietnam Cracks Down on HiAnime Piracy Ring
Vietnamese authorities have cracked down on a massive anime piracy ring, HiAnime, which raked in a staggering $12.85 million in illicit ad revenue from 2020 to 2026. This notorious site drew hundreds of millions of visitors monthly, briefly outpacing Disney+ and Crunchyroll in web traffic.

EU Faces Calls to Act as Pegasus Spyware Targets MEP
The discovery of Pegasus spyware on MEP Stelios Kouloglou's phone raises alarming questions about the integrity of Europe's oversight mechanisms, particularly when he was actively investigating spyware abuse by European countries. This incident highlights a disturbing threat to independent scrutiny at the highest levels.

Iran-Linked Cavern Manticore Targets Israel with Modular Cyber Attacks
Meet Cavern Manticore, a highly skilled and disciplined cyber threat group with ties to Iran, targeting Israel's defense and government sectors with modular attacks. Their sophisticated tactics have allowed them to infiltrate organizations with alarming speed and precision.

Web Content Conceals Hidden Instructions Targeting AI Agents
As AI agents increasingly interact with the web, hidden instructions embedded in online content can be manipulated to perform unintended actions, posing a new threat to users. Researchers have uncovered real-world campaigns that use indirect prompt injection to steer AI agents into carrying out malicious tasks.

Ransomware Operators Leverage AI for Autonomous Attacks
Meet JADEPUFFER, a pioneering threat actor that's harnessing AI to launch autonomous ransomware attacks - and adapting in real-time to get the job done. This groundbreaking tactic has been observed by researchers, who spotted JADEPUFFER's lightning-fast 31-second pivot from a failed login to a successful exploit.

Opera GX Flaw Enables Sites to Auto-Install Malicious Mods
A critical flaw in Opera GX allowed websites to secretly install malicious customization mods, which could then siphon sensitive data from other sites you visited - and it took a $5,000 bounty and a May 8 patch to fix the issue. This sneaky exploit let attackers install mods without your consent, putting your online security at risk.