Skip to main content

Emerging Threats

Modern office building exterior in a business district at daytime.

ARToken Phishing Platform Exposes EvilTokens' Microsoft 365 Toolkit

Cisco Talos researchers have uncovered a sophisticated phishing platform, ARToken, that offers a Microsoft 365 toolkit and goes far beyond traditional credential-harvesting pages, exposing over 80 API endpoints. This phishing-as-a-service operation is a game-changer in the world of cyber threats.

Analyst 207
Modern office buildings with subtle network infrastructure in foreground.

Qilin Consolidates Lead in Ransomware Market

Qilin is tightening its grip on the ransomware market, emerging as a leading player after a recent wave of consolidation, with an estimated 16% share of the cybercriminal market. This surge in power is a result of its technically mature infrastructure and strategic positioning in the ransomware-as-a-service (RaaS) market.

Analyst 207
Technicians investigate a large screen displaying a map of the internet in a network operations center with rows of servers…

Google and FBI dismantle 2-million device NetNut botnet

In a major win for cybersecurity, Google and the FBI have joined forces to dismantle the massive NetNut botnet, a network of 2 million devices used by cybercriminals and espionage groups to hide their malicious activities. This significant disruption is the latest in a series of efforts to take down tools used to conceal online threats.

Analyst 207
Cramped warehouse storage area with industrial computer equipment and tangled cables.

Ransomware Gang Exploits Supply Chain Attacks in New Partnership

Ransomware gangs are now operating like businesses, forming partnerships to supercharge their attacks - and a new alliance between Vect and TeamPCP is a prime example, combining massive credential theft with devastating ransomware-as-a-service operations. This unprecedented pairing puts organizations directly in the crosshairs.

Analyst 207
Home network setup with disrupted connections and erratic router lights.

FBI and Google Disrupt NetNut Proxy Network Used by Cyber Threat Actors

In a major win for cybersecurity, the FBI and Google have joined forces to dismantle the notorious NetNut proxy network, a go-to tool for cyber threat actors. This disruption has significantly reduced the network's capacity, cutting the available pool of devices by millions.

Analyst 207
Person sits at desk, looking concerned, holding phone with laptop and papers nearby.

Impostor Scams Expose Vulnerabilities, Cost $3.5B in 2025

Impostor scams are getting more sophisticated, with personalized attacks costing Americans a staggering $3.5 billion in 2025 - triple the losses since 2020. Social media platforms have become a primary channel for these scams, with $2.1 billion lost to online impostors alone.

Analyst 207
Cluttered home office workspace with Mac computer on desk displaying a blurred download page, with cityscape visible…

PamStealer Targets Mac Users with Fake Maccy Sites and PAM Checks

Researchers have uncovered PamStealer, a sneaky macOS information stealer that tricks users into downloading it from fake Maccy sites, and it can even slip past Apple's security measures. This clever malware uses a two-stage delivery method to steal sensitive info from unsuspecting Mac users.

Analyst 207
A smartphone lies face down on a simple office desk surrounded by papers and a notebook, conveying vulnerability.

Pegasus Spyware Targets European Parliament Investigator

In a shocking twist, a member of the European Parliament's PEGA Committee, Stelios Kouloglou, was targeted with the notorious Pegasus spyware - the very same spyware his committee is investigating. This brazen move raises serious concerns about surveillance and accountability.

Analyst 207
Law enforcement officials surround a computer server setup in a secure facility.

FBI Disrupts NetNut Proxy Platform Tied to Popa Botnet

In a major cybercrime crackdown, the FBI has seized hundreds of domains linked to NetNut, a residential proxy service allegedly tied to the massive Popa botnet, which controls at least two million devices. This disruption, made possible with the help of industry partners like Google and Lumen, marks a significant blow to the network's operations.

Analyst 207
Rows of computer servers, routers, and equipment in a brightly-lit network operations area.

Ransomware Groups Exploit Citrix Bleed 2 in Supply Chain Attacks

Ransomware groups are exploiting the Citrix Bleed 2 vulnerability to launch devastating supply chain attacks, using legitimate remote access tools to spread their reach. This critical flaw has already been linked to multiple ransomware families, including Anubis, which has claimed 91 victims so far.

Analyst 207
Living room with smart TV and streaming box, cityscape visible through window.

Google Disrupts Massive NetNut Residential Proxy Network

Google's Threat Intelligence Group has made a significant dent in the massive NetNut residential proxy network, estimated to comprise at least 2 million home devices worldwide, by partnering with the FBI, Lumen, and other allies to reduce its pool of usable devices by millions. This disruption targeted a network used by both cybercriminal and espionage groups.

Analyst 207
Modern server room with rows of computer servers and a softly glowing laptop screen on a technician's workstation.

AI-Driven Ransomware Executes End-to-End Extortion Attack

Meet JadePuffer, the AI-powered ransomware agent that pulled off a brazen end-to-end extortion attack, autonomously executing every step from initial compromise to data destruction. This groundbreaking attack, detected by Sysdig researchers, marks a chilling new era in AI-driven cyber threats.

Analyst 207
Law enforcement activity outside a federal building, suggesting a cybercrime case.

US Extradites Alleged Scattered Spider Member

In a major cybercrime crackdown, US authorities have extradited a 19-year-old suspect, Peter Stokes, for allegedly being part of the notorious Scattered Spider gang that has wreaked havoc on US companies, extorting employees and causing millions in losses. Stokes, a dual US-Estonian citizen, was arrested in Finland with incriminating evidence and is now in federal custody awaiting cybercrime charges.

Analyst 207
Dimly lit server room with a single bright laptop screen displaying a login interface.

FortiBleed exposes link between ransomware gangs

A major breakthrough in the fight against ransomware has been uncovered, revealing a direct link between ransomware gangs and the recent FortiBleed attack. Researchers have found a single operator working with multiple ransomware groups, using infrastructure tied to FortiBleed.

Analyst 207
Blurred malware interface on a computer screen in an office setting with coworkers in the background.

AI Compute Hijacking Exposes New Security Risks

A shocking 62,289 devices have fallen prey to the Millenium RAT, a malicious threat that's being spread through clever social engineering tactics and sold as a cheap, subscription-based service on the dark web. This alarming infection rate highlights the growing risk of small, seemingly harmless actions becoming gateways to devastating cyber attacks.

Analyst 207
Officials gather around a podium and large screen displaying a blurred SharePoint interface.

CISA Flags SharePoint Flaw as Exploitable

Microsoft initially downplayed the risk of a SharePoint vulnerability, saying exploitation was less likely, but the Cybersecurity and Infrastructure Security Agency has since escalated the flaw to its list of known exploited vulnerabilities. This move signals a heightened sense of urgency for organizations to address the potentially critical issue.

Analyst 207
Office worker looks puzzled at laptop with subtle fake prompt on screen amidst blurred coworkers and computers.

Microsoft 365 Accounts Targeted in 3-Second Hijacking Attacks

Beware of a sneaky 3-second hack that can hijack your Microsoft 365 account with just a click - it starts with a harmless-looking link that tricks you into executing the attack yourself. This clever tactic, known as ClickFix, exploits a simple human reflex to gain control of your account.

Analyst 207
Cluttered home office workspace with laptop and scattered notes.

Researcher Releases Zero-Day Exploits, Bypassing Disclosure Norms

A pseudonymous security researcher, known as "bikini," has made a bold move by releasing over 30 proof-of-concept exploits for zero-day vulnerabilities in open-source projects, sparking both interest and concern in the cybersecurity community. The researcher behind the Exploitarium GitHub repository is urging users to explore these vulnerabilities for research purposes only.

Analyst 207
Medical device on hospital bed with blurred computer records in background.

Medtronic Breach Exposes Patient Health Data to Cybercrooks

Medtronic is alerting patients that their personal and health information may have been compromised in a recent data breach, but has reassured them that the incident didn't impact the safe operation of its medical devices. The breach, detected on April 15, occurred between April 13 and 19, and Medtronic is now notifying affected individuals.

Analyst 207
Corporate office setting with laptop on desk and cityscape through window.

ToddyCat APT Exploits OAuth to Breach Gmail via Google API

Meet ToddyCat, a sneaky APT group that's been exploiting OAuth and the Google API to secretly breach corporate Gmail accounts since 2020. Their latest trick involves a cunning malware called Umbrij, which lets them hijack email communications with ease.

Analyst 207
Person at desk looks concerned while staring at laptop in a brightly-lit office setting with blurred law enforcement logo…

Ransomware Attacks Targeted via Fake Interpol Emails

Beware of fake Interpol emails that could be ransomware traps! Cybercriminals are impersonating the law enforcement agency, sending unsolicited emails with suspicious links and password-protected files, trying to trick organizations into compromising their security.

Analyst 207
Cisco Unified Communications Manager system equipment in a network room.

Cisco Confirms Active Exploitation of Unified CM Flaw

Over 200 Cisco Unified Communications Manager instances are vulnerable to a remotely exploitable flaw, CVE-2026-20230, which allows low-complexity server-side request forgery attacks with a simple crafted HTTP request. This critical vulnerability puts widely used IP telephony systems at risk, particularly in Asia and North America.

Analyst 207
Microsoft SharePoint server equipment sits in a brightly-lit corporate office or data center.

CISA Warns of Active Exploits of Microsoft SharePoint Flaw

Microsoft warns that a critical flaw in SharePoint, tracked as CVE-2026-45659, is being actively exploited, allowing even low-privilege attackers to execute arbitrary code remotely with ease. This deserialization vulnerability lets authenticated attackers run code on vulnerable servers without needing admin privileges.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit modern data center.

Oracle E-Business Suite Exploited Before Public Exploit Code Release

Oracle E-Business Suite deployments were under attack from a critical vulnerability even before hackers made the exploit code publicly available, highlighting the severity of the threat. This precemptive strike underscores the need for urgent attention to secure E-Business Suite systems.

Analyst 207