Skip to main content

Emerging Threats

Dimly lit control room with computer screens and industrial systems hinting at hidden network presence.

Chinese Hackers Maintain Decade-Long Spy Operation in Isolated Network

Chinese hackers pulled off a stunning 10-year cyber-espionage heist, infiltrating a supposedly airtight network and gaining unfettered access to every login, command, and secret. The masterminds behind Operation Highland, linked to the Velvet Ant cluster, expertly embedded their digital fingerprints into the network's authentication process.

Analyst 207
Law enforcement officials stand near a podium with symbolic objects, including a laptop and papers, in a brightly-lit…

FBI dismantles $1.9B China cybercrime network

In a major breakthrough, the FBI, with the help of Google and Lumen Technologies, has dismantled a massive $1.9 billion China-based cybercrime network that impersonated trusted brands to scam hundreds of thousands of victims. This coordinated takedown, part of Operation Riptide, seized key infrastructure and domains used by the group.

Analyst 207
University campus scene with students walking near a building, laptop on a bench.

ShinyHunters Exploits Oracle Flaw to Breach Universities

A zero-day flaw in Oracle PeopleSoft PeopleTools, known as CVE-2026-35273, has been exploited by ShinyHunters, potentially infiltrating over 100 organizations, with universities being the hardest hit. This vulnerability allows attackers to execute remote code and take over affected servers, posing a significant threat to higher education institutions.

Analyst 207
Defendant sits in federal court with blurred face, hands visible, in front of judge's bench and US flag.

Conti Ransomware Member Pleads Guilty to Cybercrimes

A longtime member of the notorious Conti ransomware group has pleaded guilty to cybercrimes in federal court, marking a major win for justice after the defendant's attacks caused millions of dollars in damage to people and businesses worldwide. Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, admitted to developing malware and participating in Conti's ransomware campaign.

Analyst 207
Federal officials stand near a large screen in a government briefing room.

Authorities Disrupt Massive Deepfake Porn Site in Global Operation

In a major global crackdown, authorities have shut down a notorious deepfake porn site that was profiting from the humiliation, exploitation, and violation of personal privacy of thousands of women, including celebrities and public figures. The site's massive collection of AI-altered images and videos has been seized, putting an end to its large-scale trafficking of digital forgeries.

Analyst 207
Rows of computer servers and networking equipment in a server room with a focus on a specific device showing a subtle hint…

China-Linked Hackers Infiltrate Linux Login Software with Decade-Long Backdoor

A stealthy China-linked hacking group, tracked as Velvet Ant, has been quietly infiltrating Linux login software since 2016, embedding a decade-long backdoor that evades routine security cleanups and password resets. This sophisticated operation, dubbed Operation Highland, has allowed the group to fly under the radar and maintain persistent access to targeted systems.

Analyst 207
Mobile phone on a plain surface with a blurred text message interface and a blurred cityscape in the background.

Google Disrupts Chinese Smishing Network Tied to AI-Generated Phishing Attacks

Google just took down a massive Chinese smishing network that used AI-generated phishing pages to scam millions of mobile users, and is now suing to dismantle the operation for good. The tech giant is teaming up with major carriers like AT&T, T-Mobile, and Verizon to block the fraudulent texts and shut down the Phishing-as-a-Service business.

Analyst 207
Government office setting with computer screen and partially visible foreground object.

Maine Disables Breach Portal After Hoax Submissions

Maine has temporarily shut down its public data breach reporting portal after being hit with a series of false reports, or hoaxes, submitted through the system. The state's Attorney General's Office is reviewing the situation and has removed the fraudulent filings from its database.

Analyst 207
Dimly lit computer terminal in a quiet workspace with blurred background elements.

Arch Linux AUR Packages Targeted in Credential Stealer Campaign

Malicious actors have hijacked over 400 Arch Linux AUR packages, quietly altering their build scripts to deploy a sneaky Rust credential stealer in a campaign dubbed Atomic Arch. By targeting abandoned packages and preserving their original names and histories, the attackers cleverly evaded detection.

Analyst 207
Blurred computer screen and security emblem in background of courtroom or IT office setting.

Disgruntled IT worker sabotages school district systems, jailed 21 months

A disgruntled IT worker wreaked havoc on a school district's systems for over a year and a half, causing chaos and destruction, after being terminated from his job. The sabotage spree, which included deleting crucial data and altering systems, earned him a 21-month jail sentence.

Analyst 207
Formal proceedings setting with podium, laptop, and blurred emblem in daylight.

Ukrainian Hacker Pleads Guilty in Conti Ransomware Case

Meet Oleksii Lytvynenko, a Ukrainian hacker who just pleaded guilty to his role in the notorious Conti ransomware case, which targeted over 1,000 victims worldwide and raked in a staggering $150 million in ransom payments. He's now facing up to 20 years in prison for his involvement.

Analyst 207
A cluttered home office workspace with an open laptop showing a terminal window, surrounded by papers and coffee cups.

Malware Exploits Arch Linux Packages to Spread Rootkit, Infostealer

Over 400 Arch Linux packages were compromised in a shocking discovery, distributing a sneaky Linux rootkit and infostealer to unsuspecting users through the Arch User Repository (AUR). A cleverly spoofed maintainer account was used to modify the packages and download malicious code.

Analyst 207
Water treatment plant interior showing operational equipment and controls.

Experts Cast Doubt on Handala's US Water Hacking Claims

Experts are debunking Handala's claims of being able to shut off water in US cities, with no evidence to back up the group's bold assertions. According to Sean Malone, Chief Information Security Officer at BeyondTrust, the breach appears to be limited to non-critical systems, with no impact on water treatment or distribution.

Analyst 207
Law enforcement officials surround a dismantled cryptocurrency symbol.

FBI and Europol dismantle major crypto laundering platform

In a major crackdown, the FBI and Europol have dismantled AudiA6, a massive cryptocurrency laundering operation that helped cybercriminals move a whopping $389m in illicit funds between 2022 and 2025. The service was linked to at least 15 ransomware operations and multiple cryptocurrency theft schemes, making it a key player in the digital underworld.

Analyst 207
Hospital corridor with people in background, medical device and laptop on table.

Novo Nordisk Discloses Cyberattack, Patient Data Stolen

Novo Nordisk revealed that a cyberattack has compromised patient data, specifically information related to clinical-trial participants, though assured that the data is not directly linked to patients by name or other identifiers. The company is working with outside experts to investigate and contain the breach.

Analyst 207
Dimly lit, cluttered table with scattered computers and laptops in a cramped underground setting.

Dark Web Exposes Early Warning Signs of Supply-Chain Attacks

Attackers are quietly buying and selling access to trusted integrations, developer accounts, and unattended credentials on the dark web, revealing early warning signs of supply-chain attacks. Monitoring underground forums for these subtle signals can help flag potential risks long before a breach makes headlines.

Analyst 207
Cluttered modern office workstation with blurred screens and scattered papers.

AI Coding Agents Exposed to Agentjacking Attack

Imagine a sneaky new attack that tricks AI coding assistants into doing an attacker's bidding - without ever touching the victim's infrastructure. This clever hack, dubbed Agentjacking, uses a sneaky sequence of steps to get AI tools to execute malicious code on developers' machines.

Analyst 207
A cluttered workspace with a smartphone, papers, and scribbled notes, set against a blurred cityscape or office background.

Google Sues Alleged Chinese Phishers Over AI-Powered Fraud Ops

Google is taking a stand against scammers, suing a Telegram-based group called "Outsider Enterprise" for allegedly sending millions of AI-powered scam texts and impersonating trusted brands. The lawsuit aims to put a stop to their large-scale fraud operations.

Analyst 207
Brightly-lit sports stadium interior with scoreboard and tiered seating.

Cyber-Attacks Infiltrate 84% of Sports Organizations

Cyber-attacks have hit a staggering 84% of sports organizations in the past year, with over half of those being targeted multiple times - a worrying trend in an industry where timing and spectacle are everything. This alarming statistic highlights the vulnerability of professional sports teams, venues, and event bodies to cyber threats.

Analyst 207
Law enforcement officers conduct a daytime operation with a blurred emblem in the background.

INTERPOL Disrupts Sniper Dz Phishing Platform in Global Operation

In a major global crackdown, INTERPOL dismantled the notorious Sniper Dz phishing platform, a hub for cybercriminals to buy and use ready-made phishing kits, in a coordinated effort that resulted in 201 arrests across 13 countries. The operation, dubbed Operation Ramz, dealt a significant blow to the phishing-as-a-service industry.

Analyst 207
Laptop screen on cluttered desk shows blurred email inbox with one message.

Plymouth Council Breach Exposes 500 Home-Schooling Families' Email Addresses

A careless mistake by Plymouth City Council's Elective Home Education team has led to a data breach, exposing the email addresses of around 500 home-schooling families after a single email was sent with all recipient addresses visible. The council is now dealing with the fallout after compromising the personal email addresses of hundreds of families.

Analyst 207
Hospital corridor with healthcare professionals, laptop screen, and large windows, conveying a sense of unease.

Novo Nordisk Discloses Clinical Trials Data Breach

Novo Nordisk revealed a clinical trials data breach, confirming that hackers accessed and copied sensitive personal data, including patient information and healthcare professional records, from its internal IT systems without authorization. The stolen data includes patient IDs, trial details, and health information such as biomarkers, lifestyle factors, and more.

Analyst 207
Network device on a rack in a brightly-lit IT infrastructure room.

CISA Mandates Patching of Actively Exploited Ivanti Flaw

Federal agencies are on high alert: a severe vulnerability in Ivanti's Sentry gateway, already exploited by attackers, must be patched within three days to prevent further backdoor attacks. CISA's urgent directive demands swift action to secure vulnerable devices and shield against malicious cyber threats.

Analyst 207
Law enforcement officers surround seized luxury vehicles in a daylight scene.

Europol Disrupts Major Crypto Laundering Service Linked to Ransomware Gangs

Europol's operation has cut off a major crypto laundering service linked to ransomware gangs, freezing hundreds of millions in illicit profits and disrupting a key financial pipeline used by criminals. The crackdown seized over €86,000 in cash, froze €692,000 in cryptocurrency, and took down 25 domains and 30 servers.

Analyst 207