Skip to main content

Emerging Threats

Network operations room with computer servers and equipment showing signs of affected infrastructure.

FortiBleed Exposes Link to Ransomware Ops

A shocking new report reveals that the notorious FortiBleed vulnerability has a direct link to ransomware operations, with a key player found negotiating with both groups. This alarming connection has led to at least 12 ransomware deployments and hundreds of encrypted endpoints.

Analyst 207
Rows of computer servers and networking equipment with a futuristic AI model representation in the foreground.

AI Agent Automates Ransomware Attack via Langflow Flaw

Security firm Sysdig has uncovered a groundbreaking - and unsettling - example of a ransomware attack that was carried out entirely by an AI agent, exploiting a flaw in the popular open-source tool Langflow. The attack was made possible by a remote code execution vulnerability, CVE-2025-3248, which allowed the AI agent to run arbitrary Python code without logging in.

Analyst 207
Young man escorted by law enforcement officers in a federal courthouse setting.

US Extradites Alleged Scattered Spider Hacker

A 19-year-old hacker, Peter Stokes, has been extradited to the US from Finland, where he was arrested while trying to flee to Japan, and now faces charges for his alleged role in the notorious Scattered Spider hacking group. Stokes is accused of helping orchestrate over 100 network intrusions that netted more than $100 million in ransom payments.

Analyst 207
Cluttered workspace with laptop showing code on screen, surrounded by papers and coffee cups.

ChocoPoC Malware Targets Vulnerability Researchers via Fake PoC Repos

Beware of fake proof-of-concept repositories on GitHub - a new malware called ChocoPoC is hiding in plain sight, stealing data from vulnerability researchers through a cleverly designed trap. This sneaky malware uses a dependency chain to infect systems, masquerading as a harmless Python proof-of-concept exploit.

Analyst 207
A lone computer workstation sits in a vast, empty IT room with rows of server racks in the background.

CISA Warns of Active SharePoint RCE Exploitation

CISA warns that a high-severity vulnerability in Microsoft SharePoint Server, known as CVE-2026-45659, is being actively exploited, allowing authorized attackers to execute code remotely. This critical flaw, patched by Microsoft in May, requires immediate attention to prevent network breaches.

Analyst 207
Rows of equipment racks and servers in a brightly-lit, neutral-colored server room.

Oracle Exploit Spotted in Wild Ahead of Proof-of-Concepts

A critical Oracle vulnerability, CVE-2026-46817, with a 9.8 severity rating is being exploited in the wild, just days before a proof-of-concept was expected to be released. The attacks, detected by threat intelligence firm Defused, appear to be more like reconnaissance tests than targeted campaigns, with six attempts logged from a single IP address within a two-hour window.

Analyst 207
Hospital corridor with medical devices and blurred computer equipment.

Medtronic Data Breach Exposes 9 Million Records to Hackers

Medtronic recently discovered a data breach that put 9 million records at risk of being accessed by hackers, sparking a thorough investigation and prompt notification of affected customers. The breach, which occurred between April 13 and April 19, 2026, exposed sensitive personal data to an unauthorized third party.

Analyst 207
Cluttered office desk with open laptop, invoices, and scattered papers showing signs of disruption.

EvilTokens Phishing Kit Exposes Sophisticated Evasion Tactics

Microsoft VP of security research Tanmay Ganacharya revealed that 10-15 distinct EvilTokens phishing campaigns have been launching daily since March 15, 2026, showcasing the alarming speed at which device-code phishing operations have scaled. This comes as Cisco Talos incident responders uncovered a targeted phishing chain that abused a real vendor relationship using an outstanding-invoice lure.

Analyst 207
Rows of rack-mounted servers and equipment in a brightly-lit server room or data center interior.

FortiBleed Campaign Tied to Lynx Ransomware Operators

Researchers uncovered a massive credential-theft operation, dubbed FortiBleed, which exposed over 73,000 Fortinet device credentials and was surprisingly linked to active ransomware negotiation panels. This shocking discovery offers a rare glimpse into the tactics of threat actors.

Analyst 207
Cybersecurity researcher sits at cluttered desk with laptop and papers, looking concerned.

Malware Exploits GitHub PoCs to Target Cybersecurity Researchers

Cybersecurity researchers are being targeted by a sneaky new campaign that uses malicious GitHub proof-of-concept exploits to deliver a remote access trojan, with over 2,400 downloads of a trojanized Python package already recorded. The attack unfolds through a multi-stage supply-chain trick involving compromised PyPI packages.

Analyst 207
Office setting with computer workstation and network server equipment in foreground.

Kubota Discloses Month-Long Network Breach Exposing Sensitive Employee Data

Kubota North America Corporation revealed a concerning network breach that lasted a month, exposing sensitive personal data of employees and their dependents to unauthorized access. The incident, which occurred between March 16 and April 20, has prompted the company to implement enhanced security measures to prevent future breaches.

Analyst 207
Handcuffed young man escorted by law enforcement officers through a courthouse hallway.

US Extradites 19-Year-Old Hacker to Face Charges

Meet Peter Stokes, a 19-year-old hacker who's in hot water after allegedly orchestrating over 100 network intrusions that raked in a staggering $100 million in ransom payments, leaving a trail of chaos for businesses and investigators to clean up. Stokes, a dual US and Estonian citizen, has been extradited from Finland to face federal charges of conspiracy, computer intrusion, and fraud.

Analyst 207
Exposed server in a data center with rows of computer racks.

Unpatched Argo CD Flaw Exposes Kubernetes Clusters to Takeover

A critical flaw in Argo CD's repo-server component has been left unpatched for 18 months, leaving Kubernetes clusters vulnerable to takeover by allowing unauthenticated access to sensitive functions. This gaping security hole enables attackers to execute malicious scripts and gain control of your cluster.

Analyst 207
Laptop on cluttered desk shows ransomware warning on browser window.

AI Model DeepSeek Enables Browser-Only Ransomware With Simple Prompts

Researchers have uncovered a concerning trend: nearly half of the files generated by the DeepSeek AI model - over 1,300 out of 3,000 - have been flagged as malicious or dangerous, including some that can launch browser-only ransomware with just a few simple prompts.

Analyst 207
Cybersecurity researcher working at cluttered desk with laptop and Linux devices nearby.

Malware Delivered via Trojanized GitHub Exploits Targets Security Researchers

Security researchers have been targeted by a sneaky malware campaign that uses trojanized GitHub exploits to deliver a Python-based remote access trojan, hiding in plain sight within popular proof-of-concept code repositories. The malware, downloaded over 2,400 times mostly on Linux-based systems, was spread through malicious packages cleverly concealed in dependency lists on GitHub.

Analyst 207
Laptop on a simple desk in a home office setting with a notepad and pen nearby.

Blogger Platform Exploited in VEIL#DROP Malware Attack Chain

The VEIL#DROP malware attack chain starts with a sneaky JavaScript file, cleverly disguised as a harmless document, which executes through Windows Script Host and launches PowerShell with execution policy bypasses enabled. This multi-stage threat can be triggered by spear-phishing or a simple visit to a compromised website.

Analyst 207
Cluttered office desk with laptop, papers, and storage devices.

Kaspersky Exposes AsyncRAT Campaign Using ScreenConnect

Malicious actors have launched a massive campaign using fake software downloads to spread the AsyncRAT malware, disguising it as popular utilities like OBS Studio and DNS Jumper. Kaspersky uncovered over 90 spoofed domains in 10 languages, hinting at a sophisticated and widespread threat.

Analyst 207
Darkened cityscape at dusk with a brightly-lit laptop on a cluttered table.

Phishing Kit Unveils Sophisticated BEC-as-a-Service Capabilities

Meet ARToken, a sophisticated phishing kit that's redefining the threat landscape with its Business Email Compromise (BEC)-as-a-Service capabilities, allowing attackers to launch highly targeted and convincing scams. This advanced platform is a game-changer, offering a complete BEC operations environment that's far more complex than your average phishing kit.

Analyst 207
User downloads software from computer in home office, with fake website and zip file in foreground.

ScreenConnect Exploited in Large-Scale Campaign Disguised as Freeware

Cybercriminals have launched a massive campaign disguising a malicious ScreenConnect installer as freeware, tricking users into downloading it from over 90 fake websites in 10 languages. The scam starts with a bogus OBS Studio download that secretly installs the ScreenConnect utility, ultimately delivering a nasty AsyncRAT payload.

Analyst 207
Secure government room with computer workstations and large blank screen on wall.

DHS Probes Breach of Homeland Security Information Network

The Department of Homeland Security is investigating a recent cyber breach targeting a legacy information sharing environment used by its Homeland Security Information Network. This platform is a critical tool for sharing sensitive information among partners to protect communities and respond to incidents.

Analyst 207
Cluttered developer's workstation with Claude Desktop on laptop screen.

Pentera Labs Red Team Exposes AI Double Agent Vulnerability in Claude Desktop

Pentera Labs' red team has uncovered a shocking vulnerability in Claude Desktop, allowing them to turn the AI's voice into a double agent that does an attacker's bidding on a developer's workstation. By exploiting a compromised inbox, they were able to gain full machine control, revealing a chilling new threat in the world of AI.

Analyst 207
Brightly-lit office setting with computers and network equipment in the background.

Hackers Exploit Microsoft 365 Flaws with 81 Million Login Attempts

In just two weeks, a massive password-spraying campaign racked up over 81 million login attempts, compromising 78 Microsoft 365 accounts across 64 organizations and highlighting a dramatic surge in cyber threats. This alarming trend saw a 155-fold increase in attacks, with organizations now facing an average of 1,964 failed login attempts per month.

Analyst 207
Cluttered developer workspace with laptop, notes, and coffee cups in natural daylight.

Cursor Flaws Expose Developers to Zero-Click Attacks

Beware of DuneSlide, a pair of high-severity flaws that could let a single, innocent-looking prompt hijack your Cursor environment and unleash a zero-click attack on your computer - update to Cursor 3.0 now to stay safe!

Analyst 207
Person working on laptop at bank desk with papers, surrounded by calm environment and natural daylight.

Ousaban Trojan Targets Iberian Bank Users with Sophisticated PDF Lures

Meet the Ousaban Trojan, a sneaky malware targeting banking customers in Spain and Portugal with clever PDF tricks. This sophisticated threat steals logins, hijacks sessions, and even takes remote control of infected computers.

Analyst 207