Skip to main content

Emerging Threats

Person working on laptop at bank desk with papers, surrounded by calm environment and natural daylight.

Ousaban Trojan Targets Iberian Bank Users with Sophisticated PDF Lures

Meet the Ousaban Trojan, a sneaky malware targeting banking customers in Spain and Portugal with clever PDF tricks. This sophisticated threat steals logins, hijacks sessions, and even takes remote control of infected computers.

Analyst 207
City office building with a laptop in foreground, hint of concern, abstract browser window.

AI-Generated Ransomware Exploits Chromium API in Browser Attacks

A groundbreaking AI-generated ransomware attack has been detected, cleverly exploiting the Chromium API to launch a devastating browser-based assault, stealing credentials, exfiltrating data, and holding files hostage. This alarming first-of-its-kind threat, dubbed InfernoGrabber v9.0, marks a chilling new frontier in cybercrime.

Analyst 207
Southern European city street with a blurred laptop on a desk in a small business district.

Ousaban Trojan Expands to Spain, Portugal with Advanced Evasion Tactics

Meet Ousaban, a sneaky banking Trojan that's evolved from decade-old tactics to target unsuspecting customers in Spain and Portugal, starting with a clever phishing PDF disguised as a broken file. This highly optimized threat profiles its victims before striking, making it a force to be reckoned with.

Analyst 207
Industrial control panel in foreground, with monitors and equipment in background.

Progress LoadMaster Flaw Sees Active Exploitation Attempts

A critical vulnerability in Progress Kemp LoadMaster, tracked as CVE-2026-8037, is under active exploitation attempts, with Canadian cybersecurity firm eSentire's Threat Response Unit detecting and thwarting attacks starting June 29, 2026. The attacks, though unsuccessful, raise concerns about potential future breaches given the vulnerability's high CVSS score of 9.6.

Analyst 207
Person sitting at laptop in dimly lit space, looking concerned.

Google Blogspot Abused to Deploy Fileless Infostealer

Cybercriminals are selling stolen credentials on underground marketplaces, giving other threat actors easy access to compromised accounts and environments. This latest threat, known as Veil#Drop, uses a sneaky fileless chain to infect victims who unknowingly download a malicious script disguised as a harmless document.

Analyst 207
Rows of computer servers in a brightly-lit network operations room.

Oracle E-Business Flaw Exploited in Ongoing Attacks

A critical flaw in Oracle E-Business, known as CVE-2026-46817, is being exploited by attackers, allowing them to take over vulnerable systems with just HTTP network access. This highly severe vulnerability, with a CVSS score of 9.8, has now been targeted in real-world attacks, with security researchers observing exploitation attempts on Oracle E-Business honeypots.

Analyst 207
Concerned employees in a brightly-lit office or data center examine computer screens with somber expressions.

Aflac Japan Discloses Data Breach Compromising Millions

Aflac Japan has suffered a massive data breach, exposing sensitive personal and financial information of nearly 4.4 million customers after a mysterious hacker gained access to company systems for 10 days in June. The breach, confined to Aflac's Japanese operations, has sparked an ongoing investigation into its full impact.

Analyst 207
Person working in office with router and cables in background.

AI Models Expose Millions to Phantom Squatting Phishing Threat

Millions are now at risk of falling prey to a new, rapidly evolving phishing threat called phantom squatting, where attackers exploit AI-generated links to create malicious websites that can evade detection. By registering domains invented by large language models, hackers can create seemingly trustworthy sites that are actually designed to steal sensitive information or spread malware.

Analyst 207
Developer workstation with laptop and software tools on a clean office background.

Adobe Fixes Seven High-Risk Flaws in ColdFusion, Campaign Platforms

Adobe is urging administrators to act fast and install a critical security update within 72 hours to patch seven high-risk vulnerabilities in its ColdFusion and Campaign Classic platforms that are being targeted by hackers. This update fixes maximum-severity flaws that could put your systems at risk if left unaddressed.

Analyst 207
Security researcher analyzing a small device under a focused light in a lab.

Researcher Exposes API-Driven Malware Delivery in ClickFix Campaigns

Security researcher Bert-Jan Pals' in-depth analysis of 3,000 live payloads reveals that the ClickFix campaign's API-driven malware delivery method is rapidly evolving, making it a persistent threat that's hard to defend against. This sneaky tactic moves malicious actions off the page and into backend services, issuing commands on demand with fresh disguises on every request.

Analyst 207
Server racks in a brightly-lit data center with a single blurred-out laptop in the foreground.

Azure CLI Hit by Massive Password Spray Attack Targeting 78 Accounts

In a staggering display of cyber aggression, a threat actor launched a massive password spray attack on Microsoft's Azure CLI, racking up over 81 million login attempts and breaching at least 78 accounts across 64 organizations in just two weeks. The relentless campaign, which unfolded between June 12 and June 26, successfully compromised accounts at an alarming rate of two to four per day, with some days seeing spikes of up to 30 breaches.

Analyst 207
LLMs Expose Software Supply Chain to Phantom Squatting Threat

LLMs Expose Software Supply Chain to Phantom Squatting Threat

Imagine a hidden threat lurking in the software supply chain, where 250,000 "phantom" domains lie waiting to be claimed by malicious actors - a vulnerability uncovered in a staggering 2.1 million URLs generated by LLMs. This phantom squatting threat has the potential to compromise security, and it's essential to understand its scope and impact.

Analyst 207
Person interacting with laptop in modern workspace with blurred background.

BioShocking Attack Exploits AI Browsers for Data Theft

Researchers have uncovered a chilling new attack, dubbed BioShocking, that exploits AI browsers to steal sensitive data by cleverly tricking them into treating real actions as fictional. This ingenious technique uses a simple game to condition AI agents into accepting fake actions as valid, putting even the most secure systems at risk.

Analyst 207
Python developer workstation with laptop, terminal, and programming notes, hint of Telegram logo in background.

Malicious PyPI Packages Expose Telegram Bot Servers to Hacker Control

Hackers have launched a sneaky attack, hiding malicious code in fake Python packages on PyPI, which can take control of Telegram bot servers and give attackers access to sensitive info like chats, contacts, and environment variables. This backdoor can be activated with a simple command, allowing attackers to execute any Python code on the victim's machine.

Analyst 207
Dimly lit network closet with scattered outdated devices and cables.

RustDuck Botnet Evolves with Rust Rewrite to Evade Detection

Meet RustDuck, a sneaky botnet that's been evolving to evade detection since February 2026, tracked by researchers at QiAnXin's XLab. It gains a foothold by exploiting weak passwords, unpatched vulnerabilities, and targeting specific web software.

Analyst 207
Cramped office with people at desks surrounded by clutter and technology.

Ransomware Groups Adopt Corporate Structure to Extort Victims

Meet Black Basta, a ransomware group that operated like a corporate powerhouse, launching attacks on 520 victims across 39 industries and raking in at least $107 million in bitcoin payments. With a structured team, set schedules, and outsourced tasks, this syndicate's business model was surprisingly sophisticated.

Analyst 207
Blurred laptop screen on a desk with a concerned person in the background.

Huntress Insider Threat Exposed in Ransomware Probe Leak

A Huntress insider reportedly made a grave mistake, casually disclosing to a cybercriminal that law enforcement was on their tail - a moment of poor judgment that fell short of the company's high standards. The alarming exchange was part of a larger pattern of questionable communication uncovered between the currently employed threat hunter and the threat actor.

Analyst 207
Blurred computer screen at a corporate office workstation in bright daylight.

ToddyCat APT Group Exploits Google API for Email Access

Meet ToddyCat, a sneaky APT group that's taken automation to the next level with its new tool, Umbrij - allowing it to secretly tap into corporate email and cloud resources by exploiting Google API. This stealthy move has helped ToddyCat remain undetected by monitoring systems, leaving organizations vulnerable to attack.

Analyst 207
Brightly-lit server in a neutral data center setting.

Langflow Vulnerability Exploited to Deploy Monero Miner on AI App Endpoints

Hackers exploited a critical vulnerability in Langflow to sneak a Monero cryptocurrency miner onto AI app endpoints, using just one line of Python code to start the attack. Over 19 days in March and April, threat actors took advantage of the unauthenticated remote code execution flaw, rated CVSS 9.3, to spread the malware.

Analyst 207
Browser window with generic extension interface on a laptop screen in a home office setting.

Malware Exploits Google Notes Extension to Steal Crypto Wallet Addresses

Malware actors are using a fake Google Notes extension to secretly steal cryptocurrency wallet addresses, and it's being delivered through sneaky unsigned installers that disguise the threat as a harmless utility. This stealthy operation, dubbed Silent Swap, uses a malicious Chromium extension to gain broad access to your browsing data and clipboard.

Analyst 207
Empty corporate office with rows of desks and computers, focus on a blurred laptop screen.

Nissan Breach Exposes Sensitive Employee Data via Oracle Zero-Day Flaw

Nissan's HR and payroll systems were compromised when hackers exploited a critical Oracle PeopleSoft vulnerability, putting sensitive employee data at risk. The breach, which occurred between May 27 and June 9, is a stark reminder of the importance of robust data security measures.

Analyst 207
Laptop on a desk with a Chromium browser window open, displaying a search results page.

Malicious Chrome Extension Exploits Perplexity AI Brand for Data Collection

Beware of a fake Chrome extension hiding in plain sight: masquerading as Perplexity AI, it secretly intercepts your searches and reroutes them through attacker-controlled servers. This sneaky impostor uses a similar name and branding to the real deal, but its true intentions are far from AI-powered assistance.

Analyst 207
Remote monitoring software interface on a laptop in an office setting.

SimpleHelp Vulnerability Exploited to Deliver Novel Malware

A critical vulnerability in SimpleHelp's remote monitoring software, rated a perfect 10 in severity, was exploited by attackers to masquerade as trusted technicians and deploy brand-new malware across customer networks. This flaw allowed hackers to bypass authentication and gain unauthorized access with ease.

Analyst 207
Cramped, dimly lit workspace with scattered laptop and papers, suggesting a makeshift operation.

Business Email Compromise Attacks Evolve with AI-Powered Tactics

Business Email Compromise attacks are no ordinary email scams - they're sophisticated, organized operations that now utilize AI-powered tactics to deceive and defraud. A recent underground forum thread reveals the inner workings of modern BEC schemes, from initial malware attacks to sending fake invoices.

Analyst 207