Skip to main content

Emerging Threats

Blurred computer workstation in foreground, network equipment rack in background.

Mistic Backdoor Enables Long-Term Access in Ransomware Attacks

Cyber attackers have deployed a sneaky backdoor called Mistic, allowing them to maintain long-term access to infected systems during ransomware attacks, all while staying remarkably under the radar. This stealthy threat uses clever tactics like running payloads in memory and mimicking legitimate Microsoft security tools to evade detection.

Analyst 207
Server equipment in a clean, clinical data center environment with ambient daylight.

US Seizes Huione Cloud Account Tied to $31 Billion Cyber Scam Laundering

The US Department of Justice has seized a cloud account linked to a staggering $31 billion cyber scam laundering operation, disrupting a vast online marketplace for fraud and money laundering. This massive crackdown targeted HuiOne Group, a Cambodia-based company accused of helping scammers launder billions through its subsidiaries.

Analyst 207
Darkened hacker workstation with laptop, code on screen, and scattered notes and hardware.

AI Enables Faster, Cheaper Cyber-Attacks

Cyber attacks just got a whole lot faster, cheaper, and sneakier thanks to AI, which is now a key player in the cybercrime world, enabling attackers to launch more sophisticated and elusive threats. ReliaQuest reports that AI is revolutionizing the attack workflow, making it easier for attackers to scale, customize, and slip past traditional defenses.

Analyst 207
Rack-mounted router in a network closet with a blurred city transit platform visible through a nearby window.

Cisco Unified CM Flaw Exploited in Active Attacks

Hackers are actively exploiting a high-severity flaw in Cisco Unified CM, tracked as CVE-2026-20230, which allows them to send malicious HTTP requests and potentially take control of affected devices. This vulnerability, with a CVSS score of 8.6, could enable attackers to write files to the underlying operating system and escalate their privileges.

Analyst 207
Cluttered marketplace shelf with scattered AI devices, some hidden or obscured, conveying evasion and malicious activity.

Malicious AI Skills Evade Detection on ClawHub Marketplace

Malicious AI skills are slipping through the cracks on ClawHub, with nearly 1 in 5 skills analyzed carrying hidden threats, and a recent audit found a thriving marketplace for bad actors to exploit. Unit 42 uncovered alarming trends, including infostealers and evasion techniques, highlighting the need for vigilance in this rapidly evolving threat landscape.

Analyst 207
Rows of computer servers and equipment in a secure, institutional data center setting.

US Seizes Infrastructure Tied to Huione Cybercrime Marketplace

The US Justice Department has seized a crucial cloud computing account linked to Huione Group, a key player in a massive cybercrime operation that funneled billions in stolen funds through Southeast Asian scam centers. This significant takedown disrupted the technological backbone that allowed the illicit money to be transferred, moved, and concealed.

Analyst 207
Rows of computer servers in a brightly-lit Japanese internet service provider's server room.

KDDI Breach Exposes 14.2 Million Email Credentials

A massive data breach at KDDI has potentially exposed a staggering 14.2 million email addresses and passwords, putting countless users at risk of cyber threats. The breach was detected on June 17, and although KDDI quickly took action to prevent further intrusion, the full extent of the incident is still under investigation.

Analyst 207
Technicians work in a network operations room with rows of server racks and equipment.

Cisco Unified CM flaw exploited in targeted attacks

Hackers are actively exploiting a high-severity flaw in Cisco Unified Communications Manager, allowing them to gain unauthorized access and control over vulnerable systems. This newly discovered vulnerability, tracked as CVE-2026-20230, has a CVSS score of 8.6, indicating a significant threat to security.

Analyst 207
Manufacturing floor with industrial equipment and computer workstations.

Tata Electronics Hit by Cyberattack, Data Leaked

Tata Electronics recently fell victim to a cyberattack, but swift action was taken to contain the breach and minimize disruption, with the company confirming that its operations remained uninterrupted. The incident affected parts of its IT infrastructure, but established response protocols were activated to mitigate the impact.

Analyst 207
Rows of computer servers and networking equipment fill a brightly-lit network operations center, conveying a sense of…

FortiBleed Exposes 110 Million Credentials in Global Firewall Hack

A recent global firewall hack, dubbed FortiBleed, has exposed a staggering 110 million credentials, putting countless individuals and organizations at risk. This massive breach was made possible by a sophisticated five-stage pipeline that allowed hackers to capture sensitive information, including cleartext and hashed credentials, from compromised devices.

Analyst 207
Concerned medical staff in a brightly-lit hospital corridor with a foreground computer terminal.

Xsolis Data Breach Exposes 1.4 Million People's Sensitive Information

A targeted phishing attack on January 20, 2026, led to a massive data breach at Xsolis, exposing sensitive information of 1.4 million people after the company detected unauthorized activity on its network two days later. Xsolis quickly sprang into action, containing the breach and launching a thorough investigation with cybersecurity experts.

Analyst 207
Mac computer on cluttered desk with Terminal app open, displaying blurred commands.

MacOS ClickFix Attack Exploits Terminal Commands to Spread Infostealer

Beware of a sneaky new attack on macOS, known as ClickFix, that tricks you into pasting a Terminal command, allowing hackers to silently download and launch info-stealing malware on your device. This cleverly crafted scam starts with a fake CAPTCHA page, convincing victims to unwittingly give attackers a backdoor to their sensitive data.

Analyst 207
Dark laptop on a cluttered surface with scattered papers and coins, cityscape visible through a large window in the…

Algerian Man Charged with Running Cybercrime Marketplaces

Meet the Algerian man behind a daring cybercrime scheme that swindled hundreds of thousands of dollars from thousands of victims - all from the safety of his anonymous online hideout. He allegedly ran two illicit marketplaces, selling stolen bank account and credit card numbers, phishing kits, and other tools of financial fraud.

Analyst 207
Two young men stand in a London courtroom, hands cuffed behind their backs, with somber expressions as they face the…

Scattered Spider Members Plead Guilty Over Major Cyberattacks

Two young members of the notorious Scattered Spider group have pleaded guilty to cyberattack charges in London, admitting to crippling Transport for London's computer systems and putting human welfare at risk. The guilty pleas come as prosecutors reveal the group's victims paid a staggering $115 million in ransom payments.

Analyst 207
Two young people in hoodies stand on a dimly lit city transit platform at night with scattered papers and a laptop nearby.

Scattered Spider hackers plead guilty to TfL cyberattack

Two young hackers, part of the notorious Scattered Spider group, have pleaded guilty to orchestrating a devastating cyberattack on Transport for London, causing millions in losses and disrupting the lives of countless commuters. The breach, which lasted several days in September 2024, forced TfL to acknowledge that sensitive customer data had been stolen.

Analyst 207
A cluttered workstation with a laptop, programming books, and notes in a well-lit office setting.

Malicious npm Package Exploits Supply Chain with Multi-Stage Windows RAT

Beware of sneaky impostors in your build dependencies - a recent discovery by JFrog revealed a malicious npm package masquerading as a popular JavaScript tool, hiding a multi-stage Windows remote access trojan. Treat similar-sounding package names with caution, as they could be potential delivery mechanisms for threats.

Analyst 207
Worker's desk with desktop computer, papers, and blurred screen in bright office setting.

LastPass Breach Exposes Customer Data in Supply Chain Hack

LastPass recently discovered a security incident at Klue, a third-party platform they use, which led to an unauthorized actor accessing some customer data through its Salesforce environment. Fortunately, customer vaults and core products remain secure, and swift action has been taken to mitigate the breach.

Analyst 207
Fake pre-order website on a computer screen in a dimly lit room with cityscape view.

Scammers Exploit GTA 6 Hype with Fake Pre-Order Sites

Don't fall for fake GTA 6 pre-order sites promising early access - any unofficial offer is likely a scam, and Rockstar Games will only announce legitimate pre-orders through official channels. Scammers are using professional-looking sites to trick victims into paying hundreds of dollars in cryptocurrency for a fake VIP experience.

Analyst 207
People work in a modern lab with a futuristic robotic arm in the foreground.

Agentic AI Reshapes Offensive Operations

Meet the "script kiddie as a service" era, where AI has erased the old skill barrier, allowing attackers with just intent and access to capable tools to launch sophisticated, autonomous attacks. Agentic AI has made it possible for previously unskilled actors to plan and execute campaigns without needing to pull the trigger themselves.

Analyst 207
Software development workstation with laptop, coding tools, and notes in a brightly-lit neutral environment.

Malicious npm Packages Deliver Windows RAT via PostCSS Tooling

Beware of malicious npm packages masquerading as popular tools like PostCSS - researchers have uncovered three fake packages that have racked up over 1,000 downloads and deliver a sneaky Windows remote access trojan. These lookalike packages, published just over a month ago, have been cleverly designed to fly under the radar.

Analyst 207
Two handcuffed teenagers sit somberly in a courtroom with a judge's bench and law enforcement officer in the background.

Scattered Spider Teens Plead Guilty to TfL Cyberattack

Two British teenagers, Thalha Jubair and Owen Flowers, have pleaded guilty to infiltrating Transport for London's systems, causing a £29m hit and disrupting public services in a stark reminder that cybercrime has very real-world consequences. The breach, which occurred in late August 2024, highlights the significant impact of cyberattacks on everyday life.

Analyst 207
Modern briefing room with podium and large window, suggesting a technological focus.

Five Eyes Agencies Warn of AI-Driven Cyber Threat Surge

The Five Eyes cybersecurity agencies are sounding the alarm: AI-driven cyber threats are no longer a future threat, but a present danger that businesses and governments must tackle urgently. Frontier AI will revolutionize the threat landscape in months, not years, and malicious actors are already seizing the advantage.

Analyst 207
Smartphone with WhatsApp conversation on screen sits on cluttered desk near open file folder, with cityscape in background.

WhatsApp Targeted in VBScript Campaign Installing ManageEngine RMM Tool

Malicious actors are using WhatsApp to trick victims into downloading and executing a Visual Basic Script (VBScript) file, disguised as a business or financial document, which ultimately installs a legitimate Remote Monitoring and Management (RMM) tool. The campaign has been detected in multiple countries worldwide, with Malaysia being the hardest hit.

Analyst 207
Government building facade with people walking nearby, hint of tension.

Hacktivism Surges as Geopolitical Crises Expose Cybersecurity Gaps

Hacktivist attacks have skyrocketed amid rising geopolitical tensions, with over 149 incidents reported in just three days - a stark reminder of the growing cybersecurity gaps. This alarming surge is part of a larger trend that began in February 2022, with hacktivist groups increasingly targeting critical infrastructure during times of conflict.

Analyst 207