Skip to main content

Emerging Threats

Cluttered computer workstation with laptop and cables in a small, cramped business office setting.

Hackers Exploit Tailscale for Persistent Access After C2 Takedown

Meet Poisson, a French-speaking hacker who left a digital trail of 339 commands over 33 days, revealing a clever exploit that allowed them to maintain persistent access to a small French automotive business even after a C2 takedown. The intruder's step-by-step playbook was surprisingly left in an open storage bucket, giving Cato Networks researchers a glimpse into their tactics.

Analyst 207
Cluttered room with stacked laptops and equipment, cables visible through laptop screen.

North Korean Hiring Scam Exposed with AI, US Laptop Farms

Meet the ingenious AI-powered sting operation that busted a North Korean hiring scam, exposing a massive laptop farm churning out fake remote IT workers. A suspicious resume sparked the investigation, leading to a shocking discovery of a closet full of machines impersonating candidates for Western companies.

Analyst 207
Rows of equipment racks and networking gear in a brightly-lit server room.

FortiBleed Exposes 73,000 Fortinet VPN Credentials Worldwide

A massive security breach has exposed a whopping 73,000 Fortinet VPN credentials worldwide, putting tens of thousands of firewall endpoints at risk, including those of major companies like Chevron, Samsung, and Mercedes-Benz. The alarming leak, discovered by security researcher Bob Diachenko, contains sensitive information like usernames, email addresses, and plaintext passwords.

Analyst 207
Cloud computing setup with laptop and servers in a bright office, hint of phishing activity.

GitHub Phishing Kit Targets Mexican Banks via Cloud Services

A sneaky GitHub phishing kit called "GitBait" has been targeting customers of 12 Mexican banks for three years, cleverly using cloud services like GitHub Pages and Google Sheets to stay under the radar. This cunning operation relied on over 100 GitHub-hosted domains to steal credentials, making it a challenging case for investigators.

Analyst 207
Cybersecurity team members look concerned and overwhelmed while analyzing data on a large screen.

AI-Powered Attacks Exacerbate Alert Fatigue in Cybersecurity Teams

Cybersecurity teams are drowning in data, but struggling to turn it into action - and AI-powered attacks are making alert fatigue worse. With AI-powered attacks topping the list of concerns for 41% of cybersecurity leaders, it's clear that teams need a new approach to stay ahead.

Analyst 207
Police officers raid a makeshift call centre, finding scattered laptops, phones, and bank cards amidst abandoned chairs.

Dutch Police Disrupt Helpdesk Scam Ring with In-Person Tactics

Dutch police stormed a makeshift call centre in Amsterdam, catching six suspects in the act of running a helpdesk scam ring and making off with multiple laptops, phones, and bank cards. The daring raid, which happened on June 10, has put a dent in the operation, but police warn that further arrests may be on the horizon.

Analyst 207
Developer workstation with laptop, monitor, and coding materials, surrounded by a potted plant and papers, with a JetBrains…

Malicious Plugins Exfiltrate AI API Keys

Beware of malicious AI plugins masquerading as coding assistants on the JetBrains Marketplace - they might just steal your AI API keys. These 15 sneaky plugins, active since October 2025, cleverly exfiltrate API keys to attacker-controlled servers, all while functioning as promised.

Analyst 207
Developer workstation with laptop, monitor, and notes in a bright office setting.

Malicious Plugins Exfiltrate AI API Keys on JetBrains Marketplace

Beware of malicious AI plugins on the JetBrains Marketplace that masquerade as helpful coding assistants but secretly steal your AI API keys. Over 70,000 installations have been recorded from at least 15 compromised plugins that have surprisingly evaded the marketplace's security checks.

Analyst 207
Software development workspace with multiple computer screens and scattered papers.

Mastra Packages Compromised in Software Supply Chain Attack

A massive software supply chain attack just hit Mastra, with over 140 malicious packages published in a single day by a compromised npm account. The swift and coordinated assault, dubbed easy-day-js, unfolded over just two days, catching defenders scrambling to respond.

Analyst 207
Security team works at computer screens with focused laptop display.

Microsoft Scrambles to Patch RoguePlanet Zero-Day in Defender

Microsoft is racing against the clock to fix a critical vulnerability in Defender, known as RoguePlanet, after a proof-of-concept exploit was released, allowing hackers to elevate privileges regardless of real-time protection settings. A patch is in the works, but no release date has been given.

Analyst 207
Institutional building entrance with subtle tech elements, hinting at digital breach.

Kodak Breach Exposes Sensitive Data After ShinyHunters Hack

Kodak recently suffered a data breach at the hands of hackers known as ShinyHunters, who gained temporary access to sensitive company data. The company has launched a swift investigation with external cybersecurity experts and is working closely with law enforcement to mitigate the impact.

Analyst 207
Blurred laptop screen showing Joomla Content Editor interface in a tech office setting.

CISA Warns of Actively Exploited Joomla Flaw Enabling PHP Code Execution

A critical Joomla flaw, tracked as CVE-2026-48907, is being actively exploited, allowing attackers to upload and execute PHP code - and the US Cybersecurity and Infrastructure Security Agency (CISA) is warning users to take immediate action. A patch is available in version 2.9.99.5 of the Widget Factory Joomla Content Editor.

Analyst 207
Workers stand in a sugarcane field with industrial equipment in the foreground under a clear Australian sky.

Cyberattack Disrupts Australian Sugar Production

Mackay Sugar is making a sweet recovery after a cyberattack halted operations, with significant progress made over the weekend in restoring systems and a staged restart of crushing operations on the horizon. The company is getting back on track, with manual crushing already underway at its Farleigh Mill and harvesting expected to resume soon.

Analyst 207
Developer workstation with laptop and monitor, surrounded by notes and coffee cups, in a modern office with natural light.

Malicious JetBrains plugins steal AI API keys

Beware of malicious JetBrains plugins masquerading as helpful tools - at least 15 have been detected stealing AI API keys from unsuspecting developers, with a staggering 70,000 installations. These fake plugins have been secretly siphoning off sensitive information since October 2025.

Analyst 207
Developer workstation with code review on laptop, terminal and phone nearby, under natural daylight.

AI Code Review Foils Malicious npm Supply Chain Attack

When Roman Imankulov asked his local AI agent to vet a suspicious code repository, it swiftly warned him away, saying "Don't run this code, just walk away - there's a trap." This near-instant response likely saved Imankulov from a malicious npm supply chain attack.

Analyst 207
Person holding smartphone with blank screen in public setting.

Rokarolla Malware Targets 217 Banking and Crypto Apps

Beware: the Rokarolla malware is targeting 217 banking and crypto apps, allowing hackers to seize near-total control of your Android phone. It disguises itself as legitimate apps, often sneaking in through malicious websites offering fake Chrome or TikTok downloads.

Analyst 207
Dimly lit university office with laptop, papers, and books, hinting at secretive activity.

ClickFix Campaigns Leverage New Loaders in Malware Delivery Push

Meet the BabaDeda Loader, a stealthy malware framework that's evolved to deliver a wider range of threats, including information stealers and remote access trojans, with alarming effectiveness. This revamped loader combines multiple evasion techniques to target vulnerable organizations, particularly in education and finance.

Analyst 207
Police officer surveils individual through Flock camera system in dimly lit area.

Police Misuse Flock Cameras for Illegal Stalking

Police officers across the US have been caught misusing Flock surveillance cameras to obsessively and illegally stalk over a dozen individuals nationwide. This shocking abuse of power raises serious concerns about the protection of citizens' privacy and safety.

Analyst 207
Network equipment racks with a single server in the foreground showing a subtle warning light.

Fortinet Sandbox Flaws Under Active Exploitation

Critical Fortinet Sandbox vulnerabilities are under active attack, with hackers exploiting flaws like CVE-2026-39813, a severe path traversal bug that allows authentication bypass. Fortinet patched these bugs in April, but users must upgrade ASAP to avoid being compromised.

Analyst 207
Person holding letter with puzzled expression in hospital setting.

Breach Notice Error Fuels Patient Skepticism

A simple mistake on breach notices sent by third-party vendor Xsolis sparked skepticism among patients when the letters misnamed Rochester Regional Health as "Rochester Regional Medical Center", leading many to dismiss them as scams. This misstep undermined trust and raised questions about the effectiveness of the breach notification process.

Analyst 207
Brightly-lit industrial control panel in a utility company's operations center.

Cal Water Probes Alleged Hacking by Iran-Linked Group

Cal Water is taking swift and decisive action to investigate allegations of a cybersecurity incident, swiftly activating its response plan and working around the clock to get to the bottom of the claim. The utility confirms that its probe, launched after learning of the alleged hacking by an Iran-linked group on June 11, 2026, is ongoing with no known operational disruptions reported so far.

Analyst 207
Laptop on office desk with Microsoft Teams on screen in brightly-lit room.

Ransomware Gang Exploits Microsoft Teams for C2 Traffic

Meet the sneaky ransomware gang that hijacked Microsoft Teams to secretly control its victims' systems for two whole months, using sophisticated cyber tradecraft to stay under the radar. They pulled off this impressive heist with a custom backdoor and some clever C2 traffic disguises.

Analyst 207
Smartphone on cluttered table with blurred screen, surrounded by scattered financial papers.

Rokarolla Malware Targets Android Banking Apps with 137 Commands

Meet Rokarolla, a sneaky Android banking trojan that's taking aim at 217 banking and cryptocurrency apps with an arsenal of 137 remote commands, giving attackers alarming control over infected phones. This malicious malware is designed to outsmart even Google's Play Protect defenses, putting your financial security at risk.

Analyst 207
Government agency office interior with computer workstations and a desk, featuring soft natural light and muted colors.

China-Linked Backdoor Expands to Windows with Kernel Stealth

A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.

Analyst 207