Emerging Threats

China-Linked Backdoor Expands to Windows with Kernel Stealth
A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.

FTC Warns of $3.5 Billion Losses to Imposter Scams
The Federal Trade Commission is sounding the alarm on imposter scams, which have led to a staggering $3.5 billion in losses - nearly triple the amount reported in 2020. This pervasive form of fraud has become the most reported category, accounting for almost a third of all fraud reports filed with the FTC.

Rokarolla Trojan Enables Unseen Banking Fraud via Device Takeover
Meet Rokarolla, a sneaky Android banking trojan that's taking device takeover to a whole new level, allowing scammers to isolate and exploit victims like never before. This malicious malware doesn't just steal credentials - it gives attackers total control over your phone.

Cardiac Monitor Maker's Data Breach Exposes Security Gaps
A recent report has exposed a shocking security gap in a leading cardiac monitor manufacturer's system, leaving sensitive clinical monitoring data vulnerable to data thieves. This alarming breach highlights the urgent need for enhanced medical-device security and protection of patient information.

DragonForce Ransomware Exploits Microsoft Teams to Facilitate Months-Long Breach
Meet Backdoor.Turn, a sneaky new threat that uses Microsoft Teams to hide its tracks and wreak havoc on your network for months on end - and it's surprisingly sophisticated. This Go-based RAT masquerades as legit traffic by exploiting Teams' TURN relay servers.

CISA Warns of Actively Exploited cPanel Plugin Flaw
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical cPanel plugin flaw, CVE-2026-54420, that's being actively exploited by hackers, posing a significant risk to all user-end plugin versions prior to 2.4.8. This vulnerability allows attackers to escalate privileges to root, putting your online security at risk.

China-Linked SprySOCKS Backdoor Targets Windows with Driver-Based Stealth
ESET has uncovered a Windows variant of the SprySOCKS backdoor, previously thought to only affect Linux, marking a significant expansion of its capabilities. This new variant, version 1.8, uses driver-based stealth and can communicate through TCP, UDP, and WebSocket channels.

Fortinet FortiSandbox Flaws Targeted by Attackers in Wide-Ranging Exploits
Cyber attackers are actively exploiting three high-severity Fortinet FortiSandbox vulnerabilities, CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, which were patched just last month and carry a near-critical CVSS score of 9.1. These flaws have been targeted in wide-ranging exploits over the past 24 hours, according to threat intelligence firm Defused Cyber.

Ransomware Gang Exploits Microsoft Teams to Conceal Malicious Traffic
Meet Backdoor.Turn, a sneaky new malware that's abusing Microsoft Teams to hide its malicious activities - and it's a game-changer for cyber threats. This clever RAT uses Teams' own infrastructure against us, making it harder to spot its secret communications.

Fortinet Flaws Exposed to Active Exploitation
Critical vulnerabilities in Fortinet's FortiSandbox platform are under active attack, with multiple flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, being exploited by hackers just 24 hours after security updates were issued.

Earth Lusca Expands Arsenal with Windows SprySOCKS Malware
Chinese threat actor Earth Lusca has upgraded its malware arsenal with Windows SprySOCKS, a sneaky tool that lets hackers secretly send commands to compromised devices, allowing them to fly under the radar. This latest move has been linked to a string of high-profile attacks on government organizations worldwide.

ScarCruft Targets Microsoft Users with NarwhalRAT Malware
Beware of fake Microsoft account alerts! A sneaky North Korean hacking group, ScarCruft, is sending phishing emails that mimic Microsoft security notifications to trick you into downloading the NarwhalRAT malware.

FBI Warns of Courier Cash Scams Fueling Crypto Investment Fraud
Beware of scammers who are using couriers to collect cash from victims, often under the guise of required investments or fines to withdraw from a fake crypto investment firm. The FBI warns that these scammers will instruct victims to hand over cash to a courier, often using verification tactics like sharing a dollar bill serial number or password to gain trust.

CISA Warns of LiteSpeed cPanel Plugin Flaw Exploited for Root Access
A critical vulnerability in the LiteSpeed cPanel Plugin, known as CVE-2026-54420, has been flagged by CISA for its high risk of exploitation, with a CVSS score of 8.5, and federal agencies have until June 18, 2026, to apply the necessary fix. This flaw allows for privilege escalation and has been added to the Known Exploited Vulnerabilities catalog, requiring swift action to prevent potential root access attacks.

iRhythm Breach Exposes Patient Data in Cardiac Monitoring Hack
A recent data breach at iRhythm exposed sensitive patient information, compromising personal and health data from over 12 million patients whose heartbeat data was analyzed through the company's cardiac monitoring service. The breach was discovered after a ransomware-style intrusion hit third-party business applications used by iRhythm.

Cisco Disrupts Active Exploitation of SD-WAN Manager Flaw
Cisco is taking swift action to combat the active exploitation of a medium-severity flaw in its SD-WAN Manager, known as CVE-2026-20262, which could let hackers create or overwrite files on affected systems. Federal agencies have until June 29, 2026 to remediate the vulnerability.

Google Uncovers China Espionage Group UNC6508 Lurking Undetected Since 2023
Google's Threat Intelligence Group has uncovered a stealthy Chinese espionage group, UNC6508, that had been secretly lurking in networks since 2023, targeting key sectors in the US and Canada. The full extent of the damage is still unknown, leaving experts concerned about potential long-term security breaches.

US Seizes Deepfake Nude Sites in First TAKE IT DOWN Act Enforcement Action
In a groundbreaking move, the US Department of Homeland Security has seized two notorious deepfake nude sites, CFAKE.com and SOCFAKE.com, in the first-ever enforcement action under the TAKE IT DOWN Act. This bold operation, carried out in collaboration with Italy and France, has taken a significant step towards protecting online victims and holding perpetrators accountable.

Chinese Hackers Exploit Google Workspace to Siphon Research and Defense Emails
Chinese hackers have been secretly siphoning off sensitive emails from research and defense organizations using a clever exploit of Google Workspace, with a long-running campaign that spanned over two years. The threat actors, tracked as UNC6508, used custom malware called INFINITERED to breach externally facing servers and steal valuable intel.

North Korean Hackers Exploit Developer Tools in Malware Campaigns
North Korean hackers have launched a sneaky malware campaign, tricking victims into executing cross-platform malware for macOS, Linux, and Windows through malicious scripts hidden in GitHub repositories. Their latest tactic, dubbed UNK_DeadDrop, uses recruitment lures to deliver self-running code to over 75% of targeted organizations across various sectors.

China-linked UNC6508 Targets Medical Research Institutions
A sophisticated cyber threat group linked to China, known as UNC6508, has launched a targeted attack on medical research institutions in North America, exploiting vulnerabilities in REDCap servers to gain a foothold. The intrusions, which began in September 2023, aim to compromise sensitive research data.

OptinMonster Plugin Compromised in Supply-Chain Attack
A critical security breach has hit the popular OptinMonster plugin, used by over 1.2 million websites, which delivered malicious JavaScript to unsuspecting users via a compromised content distribution network. The attack, detected by ecommerce security firm Sansec, injected harmful code into websites for a brief but perilous window of time.

ShinyHunters Breach Council of Europe in Oracle PeopleSoft Heist
The Council of Europe has fallen victim to a massive data breach, with hackers claiming to have stolen a whopping 297 GB of sensitive information, including HR records, payslips, and medical data, by exploiting a zero-day flaw in Oracle PeopleSoft. The ShinyHunters extortion group is behind the breach, boasting a haul of 429,000 files from the attack.

Cisco Patches SD-WAN Flaw Exploited in Zero-Day Attacks
Cisco has patched a high-risk SD-WAN flaw, known as CVE-2026-20262, that was being exploited in zero-day attacks to gain root privileges. The vulnerability allowed attackers to create or overwrite files on affected systems, and Cisco has now released security updates to fix the issue.