Skip to main content

Emerging Threats

Government agency office interior with computer workstations and a desk, featuring soft natural light and muted colors.

China-Linked Backdoor Expands to Windows with Kernel Stealth

A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.

Analyst 207
Concerned person sits at desk with laptop and papers, surrounded by signs of a modest home office.

FTC Warns of $3.5 Billion Losses to Imposter Scams

The Federal Trade Commission is sounding the alarm on imposter scams, which have led to a staggering $3.5 billion in losses - nearly triple the amount reported in 2020. This pervasive form of fraud has become the most reported category, accounting for almost a third of all fraud reports filed with the FTC.

Analyst 207
Person holds smartphone with blurred screen in a public area, expression neutral.

Rokarolla Trojan Enables Unseen Banking Fraud via Device Takeover

Meet Rokarolla, a sneaky Android banking trojan that's taking device takeover to a whole new level, allowing scammers to isolate and exploit victims like never before. This malicious malware doesn't just steal credentials - it gives attackers total control over your phone.

Analyst 207
Cardiac monitor on hospital trolley in brightly lit corridor with slightly ajar door in background.

Cardiac Monitor Maker's Data Breach Exposes Security Gaps

A recent report has exposed a shocking security gap in a leading cardiac monitor manufacturer's system, leaving sensitive clinical monitoring data vulnerable to data thieves. This alarming breach highlights the urgent need for enhanced medical-device security and protection of patient information.

Analyst 207
Office workers at desks with laptops and phones, Microsoft Teams logo visible in background.

DragonForce Ransomware Exploits Microsoft Teams to Facilitate Months-Long Breach

Meet Backdoor.Turn, a sneaky new threat that uses Microsoft Teams to hide its tracks and wreak havoc on your network for months on end - and it's surprisingly sophisticated. This Go-based RAT masquerades as legit traffic by exploiting Teams' TURN relay servers.

Analyst 207
Rack of computer servers in a data center with a server control panel interface on screen.

CISA Warns of Actively Exploited cPanel Plugin Flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical cPanel plugin flaw, CVE-2026-54420, that's being actively exploited by hackers, posing a significant risk to all user-end plugin versions prior to 2.4.8. This vulnerability allows attackers to escalate privileges to root, putting your online security at risk.

Analyst 207
Cluttered office desk with a Windows laptop, papers, and supplies, near a window with a blurred network router in the…

China-Linked SprySOCKS Backdoor Targets Windows with Driver-Based Stealth

ESET has uncovered a Windows variant of the SprySOCKS backdoor, previously thought to only affect Linux, marking a significant expansion of its capabilities. This new variant, version 1.8, uses driver-based stealth and can communicate through TCP, UDP, and WebSocket channels.

Analyst 207
Security device on a rack surrounded by networking equipment in a well-lit IT room.

Fortinet FortiSandbox Flaws Targeted by Attackers in Wide-Ranging Exploits

Cyber attackers are actively exploiting three high-severity Fortinet FortiSandbox vulnerabilities, CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, which were patched just last month and carry a near-critical CVSS score of 9.1. These flaws have been targeted in wide-ranging exploits over the past 24 hours, according to threat intelligence firm Defused Cyber.

Analyst 207
Blurred laptop screen showing Microsoft Teams on a plain surface with office supplies nearby.

Ransomware Gang Exploits Microsoft Teams to Conceal Malicious Traffic

Meet Backdoor.Turn, a sneaky new malware that's abusing Microsoft Teams to hide its malicious activities - and it's a game-changer for cyber threats. This clever RAT uses Teams' own infrastructure against us, making it harder to spot its secret communications.

Analyst 207
Blurred server room background with a prominent, illuminated network switch or router in sharp focus in the foreground.

Fortinet Flaws Exposed to Active Exploitation

Critical vulnerabilities in Fortinet's FortiSandbox platform are under active attack, with multiple flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, being exploited by hackers just 24 hours after security updates were issued.

Analyst 207
Government agency office interior with laptop, papers, and network diagram on wall.

Earth Lusca Expands Arsenal with Windows SprySOCKS Malware

Chinese threat actor Earth Lusca has upgraded its malware arsenal with Windows SprySOCKS, a sneaky tool that lets hackers secretly send commands to compromised devices, allowing them to fly under the radar. This latest move has been linked to a string of high-profile attacks on government organizations worldwide.

Analyst 207
Concerned office worker or home user sits at desk, scrutinizing laptop screen with a wary expression.

ScarCruft Targets Microsoft Users with NarwhalRAT Malware

Beware of fake Microsoft account alerts! A sneaky North Korean hacking group, ScarCruft, is sending phishing emails that mimic Microsoft security notifications to trick you into downloading the NarwhalRAT malware.

Analyst 207
Concerned older adult holding cash in a bank lobby with blurred ATM screen.

FBI Warns of Courier Cash Scams Fueling Crypto Investment Fraud

Beware of scammers who are using couriers to collect cash from victims, often under the guise of required investments or fines to withdraw from a fake crypto investment firm. The FBI warns that these scammers will instruct victims to hand over cash to a courier, often using verification tactics like sharing a dollar bill serial number or password to gain trust.

Analyst 207
Server room with rows of equipment and a single cPanel interface on a monitor.

CISA Warns of LiteSpeed cPanel Plugin Flaw Exploited for Root Access

A critical vulnerability in the LiteSpeed cPanel Plugin, known as CVE-2026-54420, has been flagged by CISA for its high risk of exploitation, with a CVSS score of 8.5, and federal agencies have until June 18, 2026, to apply the necessary fix. This flaw allows for privilege escalation and has been added to the Known Exploited Vulnerabilities catalog, requiring swift action to prevent potential root access attacks.

Analyst 207
Cardiac monitor on a hospital bedside table with a faint shadow of a hacker in the background.

iRhythm Breach Exposes Patient Data in Cardiac Monitoring Hack

A recent data breach at iRhythm exposed sensitive patient information, compromising personal and health data from over 12 million patients whose heartbeat data was analyzed through the company's cardiac monitoring service. The breach was discovered after a ransomware-style intrusion hit third-party business applications used by iRhythm.

Analyst 207
Technician in a network operations room checking equipment surrounding a central router.

Cisco Disrupts Active Exploitation of SD-WAN Manager Flaw

Cisco is taking swift action to combat the active exploitation of a medium-severity flaw in its SD-WAN Manager, known as CVE-2026-20262, which could let hackers create or overwrite files on affected systems. Federal agencies have until June 29, 2026 to remediate the vulnerability.

Analyst 207
Government building stands under bright sunlight with a hint of unease.

Google Uncovers China Espionage Group UNC6508 Lurking Undetected Since 2023

Google's Threat Intelligence Group has uncovered a stealthy Chinese espionage group, UNC6508, that had been secretly lurking in networks since 2023, targeting key sectors in the US and Canada. The full extent of the damage is still unknown, leaving experts concerned about potential long-term security breaches.

Analyst 207
Law enforcement setting with seized computer and monitor displaying a blank screen.

US Seizes Deepfake Nude Sites in First TAKE IT DOWN Act Enforcement Action

In a groundbreaking move, the US Department of Homeland Security has seized two notorious deepfake nude sites, CFAKE.com and SOCFAKE.com, in the first-ever enforcement action under the TAKE IT DOWN Act. This bold operation, carried out in collaboration with Italy and France, has taken a significant step towards protecting online victims and holding perpetrators accountable.

Analyst 207
Empty university hallway with slightly ajar doors, computer terminals, and research equipment.

Chinese Hackers Exploit Google Workspace to Siphon Research and Defense Emails

Chinese hackers have been secretly siphoning off sensitive emails from research and defense organizations using a clever exploit of Google Workspace, with a long-running campaign that spanned over two years. The threat actors, tracked as UNC6508, used custom malware called INFINITERED to breach externally facing servers and steal valuable intel.

Analyst 207
People work at computer workstations in a dimly lit indoor software development workspace.

North Korean Hackers Exploit Developer Tools in Malware Campaigns

North Korean hackers have launched a sneaky malware campaign, tricking victims into executing cross-platform malware for macOS, Linux, and Windows through malicious scripts hidden in GitHub repositories. Their latest tactic, dubbed UNK_DeadDrop, uses recruitment lures to deliver self-running code to over 75% of targeted organizations across various sectors.

Analyst 207
Medical staff walk down a hospital corridor with a computer in the background.

China-linked UNC6508 Targets Medical Research Institutions

A sophisticated cyber threat group linked to China, known as UNC6508, has launched a targeted attack on medical research institutions in North America, exploiting vulnerabilities in REDCap servers to gain a foothold. The intrusions, which began in September 2023, aim to compromise sensitive research data.

Analyst 207
Server room with rows of blinking equipment, indicating a compromised network setup.

OptinMonster Plugin Compromised in Supply-Chain Attack

A critical security breach has hit the popular OptinMonster plugin, used by over 1.2 million websites, which delivered malicious JavaScript to unsuspecting users via a compromised content distribution network. The attack, detected by ecommerce security firm Sansec, injected harmful code into websites for a brief but perilous window of time.

Analyst 207
Government office interior with computer screen displaying abstract database representation.

ShinyHunters Breach Council of Europe in Oracle PeopleSoft Heist

The Council of Europe has fallen victim to a massive data breach, with hackers claiming to have stolen a whopping 297 GB of sensitive information, including HR records, payslips, and medical data, by exploiting a zero-day flaw in Oracle PeopleSoft. The ShinyHunters extortion group is behind the breach, boasting a haul of 429,000 files from the attack.

Analyst 207
Network management system interface on a laptop screen in a modern office space.

Cisco Patches SD-WAN Flaw Exploited in Zero-Day Attacks

Cisco has patched a high-risk SD-WAN flaw, known as CVE-2026-20262, that was being exploited in zero-day attacks to gain root privileges. The vulnerability allowed attackers to create or overwrite files on affected systems, and Cisco has now released security updates to fix the issue.

Analyst 207