Skip to main content

Emerging Threats

Southeast Asian cityscape with industrial control system hinted in background.

China-Linked Hackers Deploy TinyRCT Backdoor in Southeast Asian Infrastructure Attacks

For years, a stealthy China-linked hacking group has been quietly targeting critical infrastructure in Southeast Asia, with a clear strategic interest in disrupting or monitoring key regional industries. Their sophisticated attacks have zeroed in on state-owned energy and government sectors, using a potent tool called the TinyRCT backdoor.

Analyst 207
Hotel front desk with computer workstation and blurred laptop screen in background.

Microsoft Uncovers ZIP Phishing Campaign Targeting Hotels with Node.js Implant

Microsoft warns of a sneaky ZIP phishing campaign that's been targeting hotels across Europe and Asia since April 2026, using photo-themed attachments to deliver a Node.js implant to front-desk machines. The cleverly crafted emails, often written in Japanese, Danish, or Dutch, use urgent and reputation-focused themes to trick recipients into opening the malicious attachments.

Analyst 207
Smartphone lies on a plain surface with a blurred background, screen off.

Cellebrite Tool Used by Russia on Jailed Activist's iPhone Despite Sales Cutoff

Despite Cellebrite's claims to have cut off sales to Russia, a shocking forensics trail on a jailed activist's iPhone reveals that the company's tool was used to extract data as recently as June 2021. This alarming discrepancy raises serious questions about Cellebrite's control over its technology.

Analyst 207
Dimly lit office space with computer workstation, scattered papers, and RAR archive box, conveying targeted espionage.

Turla Unveils STOCKSTAY Backdoor in Ukraine Espionage Campaigns

Russian hackers, specifically the state-sponsored group Turla, have unleashed a new and stealthy backdoor called STOCKSTAY in a recent espionage campaign targeting Ukraine. This sneaky malware uses a secure WebSocket connection to communicate with its command center, making it a formidable tool for cyber spies.

Analyst 207

UK Cyber Monitoring Centre Probes Canvas Breach Impact

The UK's Cyber Monitoring Centre is investigating a massive breach of Canvas, a popular learning management system, that exposed sensitive data at nearly 160 UK universities and colleges, as part of a global incident affecting around 9,000 educational institutions. The breach was caused by a notorious cybercrime group that exploited vulnerabilities on April 29 and again on May 7.

Analyst 207
Small business workstation with computer in foreground and subtle tech hints.

Cyberattacks on SMBs Surge via AI Tool Lures

Small and medium-sized businesses are under siege, with a staggering 33,352 cyberattacks detected in just four months as scammers disguise malware as popular AI tools. This alarming surge highlights how quickly cybercriminals are leveraging the latest tech trends to target vulnerable businesses.

Analyst 207
Government building with technology infrastructure in background.

Chinese Hackers Target Southeast Asia's Energy, Government Sectors

Chinese hackers have launched a stealthy assault on Southeast Asia's energy and government sectors, infiltrating at least ten organizations between October and December 2025. This sophisticated threat, tracked as CL-STA-1062, has been lurking in the shadows since March 2022, using clever tactics like hard-coded encryption keys to evade detection.

Analyst 207
Corporate office building with subtle network infrastructure hint.

Mistic Backdoor Exposes Link to Corporate Network Access Broker

Meet Mistic, a sneaky new backdoor that allows attackers to secretly access and control corporate networks for months on end, all while erasing its digital tracks. This stealthy threat can execute remote payloads in memory, upload and download files, and even self-destruct to avoid detection.

Analyst 207
Authorities in formal attire gather in a briefing room with subtle tech infrastructure in the background.

Poland Disrupts SIM-Swapping Gang Linked to Crypto Heists

In a major breakthrough, Polish authorities have dismantled a notorious SIM-swapping gang that used social engineering and specialized software to orchestrate a string of crypto heists, with four suspects now facing charges. The successful takedown was made possible through a collaborative effort with the FBI and Homeland Security Investigations.

Analyst 207
Dimly lit office cubicle with scattered papers, open laptop, and concerned coworkers in the background.

Huntress Insider Leak Exposes Potential Security Breach

A shocking security breach at Huntress has come to light, with a former analyst claiming that a colleague may have compromised the company's integrity by passing sensitive law enforcement communications to a notorious cybercriminal. The explosive allegations have left many questions unanswered about the breach and its potential impact.

Analyst 207
Person looks concerned while checking phone in cluttered living room with open laptop and shopping boxes nearby.

Scammers Exploit Shop App to Fuel Callback Phishing Attacks

Beware of scammers exploiting the popular Shop app, with 50 million downloads, to trick you into callback phishing attacks with fake purchase receipts and phony support agents. They're impersonating big brands like Norton and Apple to steal your account credentials and sensitive info.

Analyst 207
A generic VPN gateway device sits on a rack in a brightly-lit data center.

Perimeter Devices Exposed as Vulnerability in Authentication Bypass Attacks

A recent emergency directive from CISA revealed a shocking vulnerability in Check Point Remote Access VPN, allowing attackers to bypass authentication and gain trusted user access since early May. This critical flaw, with a CVSS score of 9.3, enables remote attackers to establish a fully authenticated VPN session without a valid password, essentially turning a security gateway into an entry point for intruders.

Analyst 207
Young man with somber expression sits in federal courtroom surrounded by institutional architecture.

Minnesota Hacker 'Snoopy' Sentenced for DraftKings Breach Role

A 21-year-old Minnesota hacker known as "Snoopy" has been sentenced to 18 months in prison for his role in a massive credential stuffing attack that compromised nearly 60,000 DraftKings user accounts. He'll also serve three years of supervised release, pay over $1.3 million in restitution, and forfeit $463,000.

Analyst 207
Smartphone on a plain surface in a Russian government building with a blurred historic background and forensic tools nearby.

Cellebrite Tool Exploited by Russia to Infiltrate Activist's Phone

Russian authorities exploited a loophole in Cellebrite's UFED tool, using it to extract data from activist Andrey Pivovarov's phone, even after the device was no longer receiving updates. This security gap allowed the authorities to access the phone's data as far back as June 2021.

Analyst 207
macOS computer screen with error message box on a cluttered desktop surrounded by icons and folders on a clean desk.

macOS Malware Embeds Fake Errors to Evade AI Analysis

Meet macOS.Gaslight, a sneaky new malware family from a North Korean-linked threat actor that's got a clever trick up its sleeve - embedding 38 fake system messages to throw off AI analysis tools. This tiny 3.5 KB payload is packed with deception, making it a formidable foe for cybersecurity experts.

Analyst 207
Water utility company's outdoor infrastructure with personnel and subtle computer systems.

Iranian Hackers Exploit Credentials in Cal Water Breach

Cal Water swiftly sprang into action when an Iranian-linked group, Handala, claimed to have hacked their system, activating their cybersecurity response plan and launching a thorough investigation. Thankfully, experts from Mandiant found that the breach was limited to third-party accounts, containing no evidence of a larger-scale attack.

Analyst 207
Law enforcement officials gather around a large screen displaying a world map during a briefing on a global sports piracy…

Authorities Disrupt PirloTV Sports Piracy Network, Seize 44 Domains

In a major blow to sports piracy, authorities have shut down PirloTV, a notorious network that illegally streamed live sports to over 950 million visitors worldwide each year. The operation, involving UEFA, UC3, and Mexican authorities, seized 44 domains used to distribute unauthorized streams.

Analyst 207
Laptop on a table in a brightly-lit public area, suggesting internet access.

Bluekit Phishing Kit Enhances Login Theft with Browser-in-the-Middle Tactics

Bluekit's phishing kit just got a sinister upgrade, now using browser-in-the-middle tactics to steal logins in real-time. This move has led to a massive expansion of its infrastructure, with nearly 70 new hostnames appearing in just one week.

Analyst 207
Technicians work in a brightly-lit network operations room with a Cisco device on a rack surrounded by generic networking…

Google Warns of Cisco Vulnerability Exploited as Zero-Day Months Before Disclosure

Google sounded the alarm on a Cisco vulnerability that was exploited as a zero-day months before its disclosure, putting users of Cisco Catalyst SD-WAN products on high alert. This critical flaw, tracked as CVE-2026-20245, allows authenticated local attackers to wreak havoc due to insufficient validation of user input in the command-line interface.

Analyst 207
Smart TV on an entertainment center in a living room with ambient daylight and low-utility apps on the screen.

Smart TVs Compromised by Proxyware Vulnerabilities Plague 24-Year-Old Curl AI Emerges in Cybercrime Forums Hackers Exploit Microsoft Teams Legacy Credentials Fuel Data Breaches

Over a third of smart TV apps, including clocks, screensavers, and games, contain residential proxy software, putting your device at risk. Researchers found that 42.5% of LG webOS and 26.9% of Samsung Tizen apps harbour these vulnerabilities.

Analyst 207
Suburban homes with visible Wi-Fi routers and cables leading to a utility pole or small server.

US IP Addresses Fuel Proxy Services for Cybercrime

Millions of unsuspecting US households are unwittingly fueling cybercrime, with an estimated 20 million connections being repurposed as proxies, often without their knowledge. This shocking trend highlights the dark side of residential IP addresses being exploited for malicious activities.

Analyst 207
Crowded sports arena with spectators and staff, subtle tech infrastructure in background.

ShinyHunters Breach Exposes Madison Square Garden Data

A recent cyberattack by ShinyHunters has exposed sensitive data from Madison Square Garden, highlighting a growing concern about cyber risk in the professional sports industry. The breach, which included over 26 million records, is a stark reminder of the importance of robust cybersecurity measures.

Analyst 207
Empty hospital corridor with people in distance, blurred laptop screen on nearby desk, conveying concern and unease.

Ransomware Attacks Surge Across Europe

Ransomware attacks are surging across Europe, with a staggering 55.1% year-over-year increase in just the first four months of 2026, averaging 171 incidents per month. Five key countries - Germany, the UK, France, Italy, and Spain - are bearing the brunt, accounting for 70% of all recorded attacks.

Analyst 207
Dimly lit workspace with laptop screen showing system failure messages, surrounded by clutter and blurred office background.

Gaslight Malware Exposes AI-Assisted Analysis Limits

Meet Gaslight, a sneaky new macOS malware that uses fake system-failure messages to trick AI-powered analysis tools into doubting themselves. Created by North Korea-aligned threat actors, this Rust-based implant is a clever and concerning threat to cybersecurity.

Analyst 207