Emerging Threats

Hackers Exploit Tailscale for Persistent Access After C2 Takedown
Meet Poisson, a French-speaking hacker who left a digital trail of 339 commands over 33 days, revealing a clever exploit that allowed them to maintain persistent access to a small French automotive business even after a C2 takedown. The intruder's step-by-step playbook was surprisingly left in an open storage bucket, giving Cato Networks researchers a glimpse into their tactics.

North Korean Hiring Scam Exposed with AI, US Laptop Farms
Meet the ingenious AI-powered sting operation that busted a North Korean hiring scam, exposing a massive laptop farm churning out fake remote IT workers. A suspicious resume sparked the investigation, leading to a shocking discovery of a closet full of machines impersonating candidates for Western companies.

FortiBleed Exposes 73,000 Fortinet VPN Credentials Worldwide
A massive security breach has exposed a whopping 73,000 Fortinet VPN credentials worldwide, putting tens of thousands of firewall endpoints at risk, including those of major companies like Chevron, Samsung, and Mercedes-Benz. The alarming leak, discovered by security researcher Bob Diachenko, contains sensitive information like usernames, email addresses, and plaintext passwords.

GitHub Phishing Kit Targets Mexican Banks via Cloud Services
A sneaky GitHub phishing kit called "GitBait" has been targeting customers of 12 Mexican banks for three years, cleverly using cloud services like GitHub Pages and Google Sheets to stay under the radar. This cunning operation relied on over 100 GitHub-hosted domains to steal credentials, making it a challenging case for investigators.

AI-Powered Attacks Exacerbate Alert Fatigue in Cybersecurity Teams
Cybersecurity teams are drowning in data, but struggling to turn it into action - and AI-powered attacks are making alert fatigue worse. With AI-powered attacks topping the list of concerns for 41% of cybersecurity leaders, it's clear that teams need a new approach to stay ahead.

Dutch Police Disrupt Helpdesk Scam Ring with In-Person Tactics
Dutch police stormed a makeshift call centre in Amsterdam, catching six suspects in the act of running a helpdesk scam ring and making off with multiple laptops, phones, and bank cards. The daring raid, which happened on June 10, has put a dent in the operation, but police warn that further arrests may be on the horizon.

Malicious Plugins Exfiltrate AI API Keys
Beware of malicious AI plugins masquerading as coding assistants on the JetBrains Marketplace - they might just steal your AI API keys. These 15 sneaky plugins, active since October 2025, cleverly exfiltrate API keys to attacker-controlled servers, all while functioning as promised.

Malicious Plugins Exfiltrate AI API Keys on JetBrains Marketplace
Beware of malicious AI plugins on the JetBrains Marketplace that masquerade as helpful coding assistants but secretly steal your AI API keys. Over 70,000 installations have been recorded from at least 15 compromised plugins that have surprisingly evaded the marketplace's security checks.

Mastra Packages Compromised in Software Supply Chain Attack
A massive software supply chain attack just hit Mastra, with over 140 malicious packages published in a single day by a compromised npm account. The swift and coordinated assault, dubbed easy-day-js, unfolded over just two days, catching defenders scrambling to respond.

Microsoft Scrambles to Patch RoguePlanet Zero-Day in Defender
Microsoft is racing against the clock to fix a critical vulnerability in Defender, known as RoguePlanet, after a proof-of-concept exploit was released, allowing hackers to elevate privileges regardless of real-time protection settings. A patch is in the works, but no release date has been given.

Kodak Breach Exposes Sensitive Data After ShinyHunters Hack
Kodak recently suffered a data breach at the hands of hackers known as ShinyHunters, who gained temporary access to sensitive company data. The company has launched a swift investigation with external cybersecurity experts and is working closely with law enforcement to mitigate the impact.

CISA Warns of Actively Exploited Joomla Flaw Enabling PHP Code Execution
A critical Joomla flaw, tracked as CVE-2026-48907, is being actively exploited, allowing attackers to upload and execute PHP code - and the US Cybersecurity and Infrastructure Security Agency (CISA) is warning users to take immediate action. A patch is available in version 2.9.99.5 of the Widget Factory Joomla Content Editor.

Cyberattack Disrupts Australian Sugar Production
Mackay Sugar is making a sweet recovery after a cyberattack halted operations, with significant progress made over the weekend in restoring systems and a staged restart of crushing operations on the horizon. The company is getting back on track, with manual crushing already underway at its Farleigh Mill and harvesting expected to resume soon.

Malicious JetBrains plugins steal AI API keys
Beware of malicious JetBrains plugins masquerading as helpful tools - at least 15 have been detected stealing AI API keys from unsuspecting developers, with a staggering 70,000 installations. These fake plugins have been secretly siphoning off sensitive information since October 2025.

AI Code Review Foils Malicious npm Supply Chain Attack
When Roman Imankulov asked his local AI agent to vet a suspicious code repository, it swiftly warned him away, saying "Don't run this code, just walk away - there's a trap." This near-instant response likely saved Imankulov from a malicious npm supply chain attack.

Rokarolla Malware Targets 217 Banking and Crypto Apps
Beware: the Rokarolla malware is targeting 217 banking and crypto apps, allowing hackers to seize near-total control of your Android phone. It disguises itself as legitimate apps, often sneaking in through malicious websites offering fake Chrome or TikTok downloads.

ClickFix Campaigns Leverage New Loaders in Malware Delivery Push
Meet the BabaDeda Loader, a stealthy malware framework that's evolved to deliver a wider range of threats, including information stealers and remote access trojans, with alarming effectiveness. This revamped loader combines multiple evasion techniques to target vulnerable organizations, particularly in education and finance.

Police Misuse Flock Cameras for Illegal Stalking
Police officers across the US have been caught misusing Flock surveillance cameras to obsessively and illegally stalk over a dozen individuals nationwide. This shocking abuse of power raises serious concerns about the protection of citizens' privacy and safety.

Fortinet Sandbox Flaws Under Active Exploitation
Critical Fortinet Sandbox vulnerabilities are under active attack, with hackers exploiting flaws like CVE-2026-39813, a severe path traversal bug that allows authentication bypass. Fortinet patched these bugs in April, but users must upgrade ASAP to avoid being compromised.

Breach Notice Error Fuels Patient Skepticism
A simple mistake on breach notices sent by third-party vendor Xsolis sparked skepticism among patients when the letters misnamed Rochester Regional Health as "Rochester Regional Medical Center", leading many to dismiss them as scams. This misstep undermined trust and raised questions about the effectiveness of the breach notification process.

Cal Water Probes Alleged Hacking by Iran-Linked Group
Cal Water is taking swift and decisive action to investigate allegations of a cybersecurity incident, swiftly activating its response plan and working around the clock to get to the bottom of the claim. The utility confirms that its probe, launched after learning of the alleged hacking by an Iran-linked group on June 11, 2026, is ongoing with no known operational disruptions reported so far.

Ransomware Gang Exploits Microsoft Teams for C2 Traffic
Meet the sneaky ransomware gang that hijacked Microsoft Teams to secretly control its victims' systems for two whole months, using sophisticated cyber tradecraft to stay under the radar. They pulled off this impressive heist with a custom backdoor and some clever C2 traffic disguises.

Rokarolla Malware Targets Android Banking Apps with 137 Commands
Meet Rokarolla, a sneaky Android banking trojan that's taking aim at 217 banking and cryptocurrency apps with an arsenal of 137 remote commands, giving attackers alarming control over infected phones. This malicious malware is designed to outsmart even Google's Play Protect defenses, putting your financial security at risk.

China-Linked Backdoor Expands to Windows with Kernel Stealth
A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.