Skip to main content

Emerging Threats

Rack-mounted equipment and cables in a server room with a computer monitor in the background.

Mistic Backdoor Targets Multiple Sectors in KongTuke's Financially Motivated Attacks

Meet Mistic, a sneaky backdoor that's leaving a trail of financial chaos across multiple sectors, thanks to its ability to run quietly in memory with no digital fingerprints left behind. Its arsenal includes a range of remote-access capabilities, from file uploads and downloads to code execution, all designed to keep attackers in the driver's seat for the long haul.

Analyst 207
Futuristic tech facility with blurred AI servers and data storage.

Australia's Security Threats Converge as AI Compresses Risk Timeline

When Australia's critical infrastructure is disrupted, it will be a shock, but not a surprise - and with AI supercharging threats, that disruption may come sooner than we think. The warning signs are clear: AI is rapidly expanding the offensive toolkit, making threats more immediate, concurrent, and devastating.

Analyst 207
Network operations room with a central controller device on a desk amidst computer equipment.

Cisco SD-WAN Zero-Day Exploited for Root Access

A shocking new discovery reveals that a Cisco SD-WAN zero-day vulnerability, CVE-2026-20245, was exploited for root access at least two months before its public disclosure. This highly critical flaw, with a CVSS score of 7.8, allows attackers to execute arbitrary commands with elevated privileges.

Analyst 207
Technicians in a network equipment room, one concerned technician foreground checking a Cisco SD-WAN Manager device.

Hackers Exploit Cisco Zero-Day for High-Level Access at Telecom Provider

In a chilling cyberattack, hackers exploited a previously unknown Cisco zero-day vulnerability to gain unrestricted access to a major telecom provider's system, creating a rogue admin account with full control. The breach, detected in March, was carried out in two waves, allowing the attackers to infiltrate the provider's SD-WAN Manager devices.

Analyst 207
Industrial setting with machinery and equipment at a power plant or utility facility.

ASIO Disrupts Nation-State Cyber Sabotage Targeting Australian Infrastructure

ASIO director general Mike Burgess revealed that nation-state hackers had infiltrated a critical Australian infrastructure provider's network, gaining login credentials to sabotage it at will. The alarming breach was thwarted thanks to ASIO's swift action and dedicated response.

Analyst 207
Network equipment racks with Cisco device and cables, monitored by IT staff.

Cisco Vulnerabilities Targeted in String of Exploits

Hackers are actively exploiting a recently patched Cisco vulnerability, CVE-2026-20230, using a clever chain of attacks that can grant them root privileges on compromised devices. This alarming exploit activity was uncovered by threat-intel company Defused, highlighting the urgent need for robust security measures.

Analyst 207
Young man in courtroom with somber expression, laptop blurred in background.

DraftKings hacker sentenced to 18 months for $600,000 cyberattack

Meet Nathan Austad, a 21-year-old from Minnesota who pleaded guilty to masterminding a massive $600,000 cyberattack on DraftKings, compromising nearly 60,000 customer accounts with a clever alias and a crew of co-conspirators. He'll be serving 18 months for his role in the hack, which exploited weak passwords and left thousands of customers vulnerable.

Analyst 207
Network equipment and monitoring systems surround a central router in a typical operations room setting.

Mandiant Exposes Cisco SD-WAN Zero-Day Attacks' Root Access Methods

Cisco's SD-WAN system was exploited in active attacks using a high-severity flaw, allowing hackers to create a rogue root account and take full control of targeted devices. This vulnerability, tracked as CVE-2026-20245, was triggered through a simple tenant-upload feature in the command-line interface.

Analyst 207
Person looks concerned while interacting with fake Microsoft update on laptop at office desk.

Malicious Edge Extension Exploits Native Messaging for Malware Deployment

Beware of malicious Edge extensions that can deploy malware through native messaging, with attackers using social engineering tactics on Microsoft Teams to trick victims into installing fake updates. Once infected, victims are presented with a fake Outlook update page offering three options to deploy the Edgecution malware.

Analyst 207
Software development workspace with laptop, notes, and diagrams, set against a blurred office background.

Governments Struggle to Secure Open-Source Software

The alarming reality is that years of underinvestment in open-source software security are catching up with us, with a new supply chain compromise emerging almost every week. A recent scan by Project Glasswing found over 6,000 high-risk vulnerabilities in popular open-source projects, but only a tiny fraction have been patched.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room.

SharkLoader Targets Global Entities with Cobalt Strike Deployment

Kaspersky researchers have uncovered a sophisticated campaign, dubbed StrikeShark, where hackers exploited vulnerabilities like ProxyLogon to deploy SharkLoader malware and gain access to high-stakes targets worldwide. The attackers used multiple publicly disclosed flaws to compromise internet-facing services, hitting diplomatic entities, software vendors, and more.

Analyst 207
Microsoft Disrupts Dual Cybercrime Tools in Novel Court Takedown

Microsoft Disrupts Dual Cybercrime Tools in Novel Court Takedown

In a groundbreaking move, Microsoft led a global effort to dismantle two notorious cybercrime tools, Amadey and StealC, used by hackers to infect over 140,000 computers worldwide in just one week. This bold takedown marks a significant win in the fight against cybercrime.

Analyst 207
CISA Warns of Active Exploitation of Lantronix EDS5000 Flaw

CISA Warns of Active Exploitation of Lantronix EDS5000 Flaw

A critical code-injection flaw, CVE-2025-67038, has been discovered in Lantronix EDS5000 Series devices, allowing attackers to inject arbitrary OS commands with root privileges due to a lack of input sanitization in the HTTP RPC module. This vulnerability has a CVSS score of 9.8, indicating a high severity level.

Analyst 207
Malware Developers Embed Deceptive Text to Evade AI Analysis

Malware Developers Embed Deceptive Text to Evade AI Analysis

Malware developers are getting sneaky, hiding their spyware behind a façade of disturbing text about nuclear and biological weapons to throw AI analysis off their trail. By embedding this decoy content, they're making it harder for automated systems to detect their malicious code.

Analyst 207
Courtroom setting with documents and subtle malware concept representation.

Microsoft AI Disrupts Malware Operations in Novel Racketeering Suit

Microsoft is shaking up the fight against malware by harnessing the power of AI to disrupt cybercrime operations, as seen in a groundbreaking racketeering case that treats two separate malware operations as a single, unified threat. By combining AI analysis with a novel application of the Racketeer Influenced and Corrupt Organizations Act (RICO), Microsoft's Digital Crimes Unit is pioneering a new approach to tackling malicious software.

Analyst 207
Law enforcement officials from various countries gather around a console in a brightly-lit room.

Law Enforcement Disrupts Amadey Malware Network, Recovers 27M Stolen Credentials

In a major cybercrime crackdown, international law enforcement agencies and private sector partners joined forces to dismantle the Amadey malware network, recovering a staggering 27 million stolen login credentials. This huge blow to cybercriminals was delivered between June 15-19, 2026, as part of Operation Endgame.

Analyst 207
Law enforcement officers in a cybersecurity operation room surrounded by computer screens and network equipment.

Europol Operation Disrupts StealC and Amadey Infostealers

In a major win for cybersecurity, a coordinated international effort has dismantled the operations of two notorious malware families, StealC and Amadey, freezing a whopping €41m in crypto assets of criminal origin. This significant disruption was made possible through the collaboration of Europol, Germany's Federal Criminal Police Office, J-CAT, and Eurojust.

Analyst 207
Law enforcement officials from various agencies gather in a briefing room for a collaborative operation.

Microsoft-Led Operation Disrupts Amadey, StealC Malware Networks

In a major win for cybersecurity, a Microsoft-led operation has successfully disrupted the networks behind Amadey and StealC malware, significantly increasing friction for cybercriminals and making it harder for attacks to succeed. This collaborative effort between law enforcement and private sector partners marks a crucial step forward in the fight against cybercrime.

Analyst 207
Ubiquiti UniFi OS device in a small business office setting with ambient daylight.

CISA Warns of Actively Exploited Ubiquiti Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are actively exploiting security flaws in Ubiquiti UniFi OS devices, posing a significant threat to system security. Federal agencies have just three days to apply crucial updates or recommended fixes to avoid potential breaches.

Analyst 207
Dimly lit workspace with scattered notes and empty coffee cups, hinting at unease.

Cordyceps Flaws Compromise 300+ GitHub Repositories

A newly discovered flaw, dubbed Cordyceps, has left over 300 GitHub repositories vulnerable to exploitation by unauthenticated users, allowing for code execution, credential theft, and supply-chain compromise. This critical weakness can be easily exploited, putting countless open-source projects at risk.

Analyst 207
A dimly lit laboratory setting with a macOS laptop displaying a terminal window amidst technical equipment and papers.

North Korea-linked Backdoor Exploits AI Triage Tools

When building AI triage tools, it's crucial to treat sample contents as potentially hostile input, not instructions, to prevent malicious manipulation. Experts warn that failing to do so can allow attackers to sneak hostile content into your model.

Analyst 207
Customer service representative on phone call at retail service desk.

Social Engineering Attacks Target Service Desks

Service desks have become a prime target for cyber attackers, who often find it easier to manipulate staff into divulging sensitive information than to crack the technology itself. In a string of recent incidents, hackers have successfully impersonated employees to gain access to internal systems, as seen in the 2025 UK attacks on major retailers like Marks & Spencer, Co-op, and Harrods.

Analyst 207
Modern cityscape at dusk with glowing abstract computer screen.

AI-Powered Adversaries Compress Cyberattack Timeline

In early 2026, the emergence of advanced agentic AI models marked a chilling new era in cyber threats, enabling attackers to compress the time between discovery and weaponization to mere minutes. This means that the window for detecting and responding to breaches may soon be shorter than the time it takes to finish a cup of coffee.

Analyst 207
Blurred cityscape with office workstation and blank computer screen.

MuddyWater Exploits Ransomware Disguise for Cyber Espionage

The line between ransomware attacks and nation-state espionage is rapidly blurring, as cyber groups like MuddyWater now disguise their operations as financially motivated ransomware attacks to further their strategic objectives. MuddyWater, linked to Iran's Ministry of Intelligence and Security, has been caught posing as the Chaos ransomware group in a deliberate campaign.

Analyst 207