Emerging Threats

Nintendo Data Breach Exposes Employee Survey Information
Nintendo of America recently experienced a data breach through a third-party survey service, exposing limited employee survey information, but fortunately, no customer or financial data was compromised. The company is working to resolve the issue and has confirmed that its own systems remain secure.

TeamPCP Exploits Open-Source Trust Model in Mass Software Compromise
In a shocking display of cunning, TeamPCP has compromised over 1,000 software packages in under four months, injecting malicious code and redefining the notion of trust in open-source supply chains. This brazen attack has left a trail of destruction, with roughly 500 million weekly downloads affected across major registries like npm, PyPI, and GitHub.

Malware Developers Embed Deceptive Code to Evade AI Analysis
Malware developers are getting sneaky, hiding deceptive code in their spyware to throw off AI analysis - and it's working, with one developer adding text about nuclear and biological weapons to their malicious software. This clever trickery tricks AI systems into ignoring the real threat.

Cyber Trust Erodes as AI, Tools Enable New Attacks
Trust is crumbling in the digital world as hackers exploit AI and tools to launch devastating attacks, turning trusted platforms into malware delivery mechanisms. The latest threat: hijacked Google Ads and AI developer tools used to funnel over 2,000 victims to malicious download pages.

Chinese Hackers Infiltrate Defense Research with Custom Malware
Chinese hackers have launched a stealthy attack on defense research using custom malware, embedding it into upgrade workflows so it survives even when vulnerabilities are patched. This allows the malware to re-infect new versions, making it a persistent and concerning threat.

Malware Spreads via USB, Targets Crypto Wallets with Clipboard Theft
Beware of a sneaky malware that's spreading through USB drives and targeting crypto wallets by stealing sensitive info from your clipboard every half a second. This cunning threat replaces wallet addresses, harvests seed phrases and private keys, and even takes rapid screenshots to get its hands on your digital assets.

UK Watchdog Cautions Healthcare Worker Over Royal's Medical Records Breach
When trust in healthcare settings is broken and personal info is mishandled, swift action is taken - as seen in the ICO's recent decision to issue a formal caution to a former healthcare professional for misusing sensitive patient data. The watchdog is clear: people's personal info must be safe from exploitation.

INC Ransomware Targets 830+ Victims, Expands as Major RaaS Threat
The INC ransomware group has rapidly grown into a major threat, claiming over 830 victims since August 2023, with US organizations making up more than 65% of those affected. Sectors such as legal services, manufacturing, and healthcare are among the most targeted, as INC expands its reach as a prominent Ransomware as a Service (RaaS) operation.

Malware Campaign Exploits AI, Fake GitHub Stars to Spread Crypto Clipper
This sneaky malware uses AI and fake GitHub stars to spread a crypto clipper that can steal your cryptocurrency by swapping your wallet address with the attacker's - and it's been designed to harvest small, repeated thefts from over 15,500 cryptocurrency wallet addresses. The malware operates stealthily, watching your clipboard for crypto wallet addresses and replacing them with an attacker-controlled address.

Microsoft Exposes Windows Clipper Malware Campaign Using USB Worm.
Microsoft's security team has uncovered a sneaky malware campaign that's been secretly stealing cryptocurrency from Windows users since February 2026, using a clever combination of a USB worm and a stealthy Tor-based command center. The malware, known as a Windows Clipper, uses Windows Script Host and ActiveX to launch a Tor proxy and communicate with its command center.

Klue OAuth Breach Enables Icarus Extortion Attacks on Salesforce Data
A recent OAuth breach at market intelligence platform Klue has enabled a new extortion group called Icarus to steal sensitive Salesforce CRM data from multiple organizations, sparking a wave of ransom demands. Salesforce has swiftly responded by disabling the connection between Klue's Battlecards app and its platform to protect customers.

DragonForce Hackers Exploit Microsoft Teams to Conceal Backdoor Traffic
Meet Backdoor.Turn, a sneaky malware that uses Microsoft Teams to hide its secret communication with hackers, leveraging the platform's relay infrastructure to stay under the radar. By masquerading as a legitimate connection, it allows attackers to remotely control infected systems undetected.

Law Enforcement Disrupts SocGholish Botnet Linked to Evil Corp
In a major win for cybersecurity, an international coalition of law enforcement agencies has dismantled the notorious SocGholish botnet, liberating nearly 15,000 compromised WordPress sites and taking down 106 servers and domains used by cybercriminals. This bold operation has effectively cut off the cybercrime gang's access to thousands of infected computer systems.

Telco Exposes Customer Data in Cleartext, Ignoring Basic Security Protocols
A new hire was granted sudo-level access to a live production database on their first day, with management's casual instruction to "take a look" - and promptly uncovered customer records stored in easily accessible cleartext. This alarming lapse in security protocols left sensitive customer information, including full personal details and payment numbers, exposed and vulnerable.

Fortinet and Ivanti Exploits Fuel LATAM Infrastructure Attacks
In a shocking revelation, a coordinated campaign dubbed Operation Escaneo has been exposed, targeting critical infrastructure across Mexico, Ecuador, and Portugal, with a staggering 3,708 sessions recorded over just 13 days. The attackers exploited vulnerabilities in Fortinet and Ivanti perimeter appliances to gain entry into government, tax authorities, utilities, transport, telecoms, and banks.

Nation-States Drive 75% of UK Critical Infrastructure Cyber-Attacks, NCSC Warns
The UK's National Cyber Security Centre has warned that a staggering 75% of critical infrastructure cyber-attacks in the UK are driven by nation-states, with 200 incidents reported in the past year alone. This alarming trend highlights the growing threat of state-sponsored cybercrime, with countries like Russia, China, and Iran linked to many of these attacks.

Cybercrime Exploits APAC's Rapid Digitalization
Cybercrime is rapidly overtaking traditional crime in APAC, with nearly a third of crime in over half the region's countries now online, according to Interpol's latest report. The alarming trend highlights the urgent need for stronger cross-border collaboration to combat the evolving threat.

Cybercrime Surges Across Asia and South Pacific, Hits 30% of All Crime
Cybercrime is surging across Asia and the South Pacific, now accounting for over 30% of all recorded crime, with organised networks leveraging AI, ransomware, and social engineering on a massive scale. The rapid rise is driven by rapid digital adoption and new technologies.

Microsoft Tackles RoguePlanet Defender Flaw with Imminent Patch
Microsoft is working on a patch to fix a serious security flaw in Microsoft Defender, known as RoguePlanet, which could allow hackers to gain elevated privileges on affected systems. A high-quality security update is imminent to address this vulnerability and protect users.

Malware Campaign Exploits Fake Reviews to Spread Crypto Clipper
A single threat actor cleverly mimicked legitimate brands to spread Crypto Clipper Malware, using fake reviews, tutorial videos, and promotions on trusted platforms to manufacture credibility for a malicious crypto tool. They created a convincing illusion of a trusted product, complete with inflated download counts and coordinated five-star reviews.

Attackers Exploit Critical Fortinet Vulnerabilities Disclosed in April
Security researchers have confirmed that hackers are actively exploiting critical vulnerabilities in Fortinet's FortiSandbox product, first patched in April, with multiple independent groups jumping on the bandwagon. The exploitation attempts, observed as early as June 9, involve OS-command injection and path-traversal flaws.

Kodak Breach Exposes 2.2M Records to ShinyHunters Threat Group
Kodak has confirmed a major data breach, with the ShinyHunters threat group claiming to have stolen 2.2 million records, including sensitive customer information. The company is working closely with law enforcement and cybersecurity experts to address the breach.

Fortinet Firewalls Compromised in Massive Password-Stealing Attack
A massive password-stealing attack has compromised around 75,000 Fortinet firewall devices, putting credentials of major corporations across 194 countries at risk and leaving a trail of full network compromises in its wake. The breach, dubbed FortiBleed, has created a verified database of working credentials for some of the world's largest enterprises, threatening nearly every sector of the global economy.

Hackers Exploit Tailscale for Persistent Access After C2 Takedown
Meet Poisson, a French-speaking hacker who left a digital trail of 339 commands over 33 days, revealing a clever exploit that allowed them to maintain persistent access to a small French automotive business even after a C2 takedown. The intruder's step-by-step playbook was surprisingly left in an open storage bucket, giving Cato Networks researchers a glimpse into their tactics.