Emerging Threats

ARToken Phishing Platform Exposes EvilTokens' Microsoft 365 Toolkit
Cisco Talos researchers have uncovered a sophisticated phishing platform, ARToken, that offers a Microsoft 365 toolkit and goes far beyond traditional credential-harvesting pages, exposing over 80 API endpoints. This phishing-as-a-service operation is a game-changer in the world of cyber threats.

Qilin Consolidates Lead in Ransomware Market
Qilin is tightening its grip on the ransomware market, emerging as a leading player after a recent wave of consolidation, with an estimated 16% share of the cybercriminal market. This surge in power is a result of its technically mature infrastructure and strategic positioning in the ransomware-as-a-service (RaaS) market.

Google and FBI dismantle 2-million device NetNut botnet
In a major win for cybersecurity, Google and the FBI have joined forces to dismantle the massive NetNut botnet, a network of 2 million devices used by cybercriminals and espionage groups to hide their malicious activities. This significant disruption is the latest in a series of efforts to take down tools used to conceal online threats.

Ransomware Gang Exploits Supply Chain Attacks in New Partnership
Ransomware gangs are now operating like businesses, forming partnerships to supercharge their attacks - and a new alliance between Vect and TeamPCP is a prime example, combining massive credential theft with devastating ransomware-as-a-service operations. This unprecedented pairing puts organizations directly in the crosshairs.

FBI and Google Disrupt NetNut Proxy Network Used by Cyber Threat Actors
In a major win for cybersecurity, the FBI and Google have joined forces to dismantle the notorious NetNut proxy network, a go-to tool for cyber threat actors. This disruption has significantly reduced the network's capacity, cutting the available pool of devices by millions.

Impostor Scams Expose Vulnerabilities, Cost $3.5B in 2025
Impostor scams are getting more sophisticated, with personalized attacks costing Americans a staggering $3.5 billion in 2025 - triple the losses since 2020. Social media platforms have become a primary channel for these scams, with $2.1 billion lost to online impostors alone.

PamStealer Targets Mac Users with Fake Maccy Sites and PAM Checks
Researchers have uncovered PamStealer, a sneaky macOS information stealer that tricks users into downloading it from fake Maccy sites, and it can even slip past Apple's security measures. This clever malware uses a two-stage delivery method to steal sensitive info from unsuspecting Mac users.

Pegasus Spyware Targets European Parliament Investigator
In a shocking twist, a member of the European Parliament's PEGA Committee, Stelios Kouloglou, was targeted with the notorious Pegasus spyware - the very same spyware his committee is investigating. This brazen move raises serious concerns about surveillance and accountability.

FBI Disrupts NetNut Proxy Platform Tied to Popa Botnet
In a major cybercrime crackdown, the FBI has seized hundreds of domains linked to NetNut, a residential proxy service allegedly tied to the massive Popa botnet, which controls at least two million devices. This disruption, made possible with the help of industry partners like Google and Lumen, marks a significant blow to the network's operations.

Ransomware Groups Exploit Citrix Bleed 2 in Supply Chain Attacks
Ransomware groups are exploiting the Citrix Bleed 2 vulnerability to launch devastating supply chain attacks, using legitimate remote access tools to spread their reach. This critical flaw has already been linked to multiple ransomware families, including Anubis, which has claimed 91 victims so far.

Google Disrupts Massive NetNut Residential Proxy Network
Google's Threat Intelligence Group has made a significant dent in the massive NetNut residential proxy network, estimated to comprise at least 2 million home devices worldwide, by partnering with the FBI, Lumen, and other allies to reduce its pool of usable devices by millions. This disruption targeted a network used by both cybercriminal and espionage groups.

AI-Driven Ransomware Executes End-to-End Extortion Attack
Meet JadePuffer, the AI-powered ransomware agent that pulled off a brazen end-to-end extortion attack, autonomously executing every step from initial compromise to data destruction. This groundbreaking attack, detected by Sysdig researchers, marks a chilling new era in AI-driven cyber threats.

US Extradites Alleged Scattered Spider Member
In a major cybercrime crackdown, US authorities have extradited a 19-year-old suspect, Peter Stokes, for allegedly being part of the notorious Scattered Spider gang that has wreaked havoc on US companies, extorting employees and causing millions in losses. Stokes, a dual US-Estonian citizen, was arrested in Finland with incriminating evidence and is now in federal custody awaiting cybercrime charges.

FortiBleed exposes link between ransomware gangs
A major breakthrough in the fight against ransomware has been uncovered, revealing a direct link between ransomware gangs and the recent FortiBleed attack. Researchers have found a single operator working with multiple ransomware groups, using infrastructure tied to FortiBleed.

AI Compute Hijacking Exposes New Security Risks
A shocking 62,289 devices have fallen prey to the Millenium RAT, a malicious threat that's being spread through clever social engineering tactics and sold as a cheap, subscription-based service on the dark web. This alarming infection rate highlights the growing risk of small, seemingly harmless actions becoming gateways to devastating cyber attacks.

CISA Flags SharePoint Flaw as Exploitable
Microsoft initially downplayed the risk of a SharePoint vulnerability, saying exploitation was less likely, but the Cybersecurity and Infrastructure Security Agency has since escalated the flaw to its list of known exploited vulnerabilities. This move signals a heightened sense of urgency for organizations to address the potentially critical issue.

Microsoft 365 Accounts Targeted in 3-Second Hijacking Attacks
Beware of a sneaky 3-second hack that can hijack your Microsoft 365 account with just a click - it starts with a harmless-looking link that tricks you into executing the attack yourself. This clever tactic, known as ClickFix, exploits a simple human reflex to gain control of your account.

Researcher Releases Zero-Day Exploits, Bypassing Disclosure Norms
A pseudonymous security researcher, known as "bikini," has made a bold move by releasing over 30 proof-of-concept exploits for zero-day vulnerabilities in open-source projects, sparking both interest and concern in the cybersecurity community. The researcher behind the Exploitarium GitHub repository is urging users to explore these vulnerabilities for research purposes only.

Medtronic Breach Exposes Patient Health Data to Cybercrooks
Medtronic is alerting patients that their personal and health information may have been compromised in a recent data breach, but has reassured them that the incident didn't impact the safe operation of its medical devices. The breach, detected on April 15, occurred between April 13 and 19, and Medtronic is now notifying affected individuals.

ToddyCat APT Exploits OAuth to Breach Gmail via Google API
Meet ToddyCat, a sneaky APT group that's been exploiting OAuth and the Google API to secretly breach corporate Gmail accounts since 2020. Their latest trick involves a cunning malware called Umbrij, which lets them hijack email communications with ease.

Ransomware Attacks Targeted via Fake Interpol Emails
Beware of fake Interpol emails that could be ransomware traps! Cybercriminals are impersonating the law enforcement agency, sending unsolicited emails with suspicious links and password-protected files, trying to trick organizations into compromising their security.

Cisco Confirms Active Exploitation of Unified CM Flaw
Over 200 Cisco Unified Communications Manager instances are vulnerable to a remotely exploitable flaw, CVE-2026-20230, which allows low-complexity server-side request forgery attacks with a simple crafted HTTP request. This critical vulnerability puts widely used IP telephony systems at risk, particularly in Asia and North America.

CISA Warns of Active Exploits of Microsoft SharePoint Flaw
Microsoft warns that a critical flaw in SharePoint, tracked as CVE-2026-45659, is being actively exploited, allowing even low-privilege attackers to execute arbitrary code remotely with ease. This deserialization vulnerability lets authenticated attackers run code on vulnerable servers without needing admin privileges.

Oracle E-Business Suite Exploited Before Public Exploit Code Release
Oracle E-Business Suite deployments were under attack from a critical vulnerability even before hackers made the exploit code publicly available, highlighting the severity of the threat. This precemptive strike underscores the need for urgent attention to secure E-Business Suite systems.