Emerging Threats

Europol Disrupts Major Crypto Laundering Service Linked to Ransomware Gangs
Europol's operation has cut off a major crypto laundering service linked to ransomware gangs, freezing hundreds of millions in illicit profits and disrupting a key financial pipeline used by criminals. The crackdown seized over €86,000 in cash, froze €692,000 in cryptocurrency, and took down 25 domains and 30 servers.

French Govt Breach Exposes 73,000 Employees' Data
A major data breach at France's digital affairs directorate, DINUM, has exposed the sensitive information of 73,000 public-sector employees, affecting nearly 9% of the Tchap instant messaging platform's users. The breach compromised public chat rooms, user metadata, and shared files, but thankfully, private conversations remained encrypted and secure.

Japanese Utility Exposes 10.9 Million Client Records in Data Loss Incident
A shocking data loss incident has hit Japanese utility company Kyushu Electric Power Co., Inc., with a staggering 10.9 million client records exposed after an external storage device went missing. The device, last seen on April 27, was found to be missing on May 26, sparking a frantic investigation.

Maine Breach Portal Exposed to Fake Data Breach Disclosures
A fake data breach notice was recently submitted to Maine's breach disclosure portal using VRChat's name, but the company quickly reassured fans that their data and systems are safe. The incident highlights a vulnerability in the portal's submission process, which allows anyone to post a breach notice without verification.

ShinyHunters Exploits Oracle PeopleSoft Vulnerability in Education Sector Attacks
ShinyHunters hackers have exploited a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, to launch targeted attacks on US organizations, particularly in the higher education sector. The attacks, which involved data theft and extortion, hit a whopping 68% of US higher education institutions.

ShinyHunters Breaches Universities via Oracle PeopleSoft Zero-Day Exploit
Hackers have struck 68% of breached organizations in the higher education sector, with a whopping majority being US universities, by exploiting a critical zero-day vulnerability in Oracle PeopleSoft. This severe flaw, rated 9.8/10, allows for remote code execution with no login or user interaction required.

Russian national charged in Void Blizzard cyber-espionage scheme
A Russian national, Denis Nikolayevich Obrezko, has been charged with helping facilitate a massive cyber-espionage scheme that infiltrated at least 11 US companies, with authorities suspecting many more victims nationwide. Obrezko allegedly played a key role in the Void Blizzard campaign by buying a virtual private server and registering domain names used in the intrusions.

Oracle Discloses Zero-Day Flaw in PeopleSoft Exploited in Data Theft Attacks
A critical zero-day flaw in Oracle PeopleSoft, known as CVE-2026-35273, has been exploited by hackers to steal sensitive data from over 100 organizations, with a staggering 300 instances affected. Oracle has issued emergency mitigations and is working on a patch to address this highly vulnerable issue.

ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach 100 Orgs
ShinyHunters, a notorious data theft group, claims to have exploited a critical Oracle PeopleSoft zero-day vulnerability, CVE-2026-35273, to breach over 100 organizations, including the University of Nottingham. The group allegedly stole sensitive data, posting some of it on their leak site.

Microsoft Zero-Day Exploit Bypasses BitLocker Encryption
A security researcher known as Nightmare Eclipse has made a startling discovery, unveiling exploit code called GreatXML that can bypass Microsoft's BitLocker encryption on systems that have run a Microsoft Defender Offline scan. This accidental find took just four hours to uncover, leaving many to wonder about potential vulnerabilities.

Gentlemen Ransomware Spreads Globally, Targets 478 Victims
Meet The Gentlemen, a notorious ransomware group with a sprawling affiliate program that's left 478 victims in its wake, exploiting modern vulnerabilities with alarming speed and flexibility. Led by a single Russian-language operator, LARVA-368, this cybercrime powerhouse has been wreaking havoc since March 2025.

VRChat Breach Exposes Data of 2.4M Users
A massive data breach at VRChat has exposed the sensitive information of over 2.4 million users, leaving them vulnerable to potential cyber threats. This alarming incident highlights the importance of online security and data protection.

Europol Disrupts AudiA6 Crypto-Laundering Service Linked to $380 Million Ransomware Scheme
Europol has dismantled a massive cryptocurrency laundering operation, known as AudiA6, that handled over $380 million in illicit funds for ransomware actors and cybercriminals. The service promised anonymity, but actually took a 3-10% cut to clean and return tainted assets in just an hour.

Malware Campaign Exploits AI Demand with Fake Guides and Dev Tools
Cyber attackers are now disguising malware as legitimate AI learning guides and developer tools, tricking professionals into opening malicious files that look like trusted educational content. They've been distributing booby-trapped archives labeled as AI study guides and developer tools, such as fake AI-ready PostgreSQL and agentic coding guides.

Identity Crimes Evolve into Multi-Layered Fraud Schemes
Identity crimes are no longer standalone incidents, but rather gateways to multiple, simultaneous frauds that can wreak havoc on victims' lives. A staggering 25.6% of victims now face two or more concurrent events, a 23.5% surge from the previous year.

VRChat Breach Exposes 2.4M User Records
A recent data breach at VRChat has compromised 2.4 million user accounts, exposing sensitive info like usernames, email addresses, and login histories, which could be used to target users with malicious attacks. Fortunately, passwords, payment details, and government IDs appear to be safe, but users are still advised to be cautious.

Cyberattacks Expose AI Agents' Vulnerability to Phishing Risks
A staggering 3.3 billion identity records are now circulating on illicit markets, thanks to a whopping 11.1 million devices infected with infostealers last year - a digital threat landscape that's more vulnerable than ever. This alarming trend highlights the urgent need for robust protection against AI agents' vulnerability to phishing risks.

Coupang Fines $409 Million for Massive Data Breach
Coupang has been slapped with a whopping $409 million fine for a massive data breach that exposed the personal info of 37.55 million people, due to a lax safety management system and negligence in key security measures. The hefty penalty is part of a landmark enforcement action by South Korea's Personal Information Protection Commission.

Interpol Disrupts SniperDz Phishing-as-a-Service Platform
In a major blow to cybercrime, Interpol has dismantled the notorious SniperDz Phishing-as-a-Service platform, a significant player in the global phishing landscape. This success is a testament to the power of cross-border collaboration, with 13 countries joining forces to bring down the operation.

OceanLotus Targets Vietnam Investors with SPECTRALVIPER Backdoor
The notorious 15-year-old APT group, OceanLotus, is now setting its sights on Vietnam's investors with a cunning new backdoor attack called SPECTRALVIPER, showcasing their relentless adaptability and aggressive tactics. This latest move has left experts wondering if it's a temporary shift or a long-term strategy.

Ransomware Attacks Shift to Data Theft Tactics
Ransomware attacks have taken a sinister turn, with a growing number of hackers ditching decryption keys and instead using stolen data to extort their victims. In fact, a recent report found that a whopping 87% of ransomware claims now involve data theft, with encryption becoming a thing of the past.

FBI Disrupts Chinese Spy Websites Targeting US Security Clearance Holders
The FBI and Justice Department have shut down 13 fake websites pretending to be legitimate consulting firms, targeting US security clearance holders with lucrative job offers that aimed to extract sensitive information for the Chinese government. These seized domains were part of a sophisticated intelligence collection campaign that began in November 2023.

NSO Group Defies Court Order, Continues Targeting WhatsApp Users
Despite a court order blocking it from doing so, NSO Group continues to target WhatsApp users, defying the ruling and putting users at risk. The company is fighting to overturn the order, claiming it will suffer harm if it's forced to comply.

Ransomware Gang 'The Gentlemen' Traced to Suspected Russian Operator
Meet The Gentlemen, a notorious ransomware gang that's rapidly growing in power thanks to its unusually generous 90/10 affiliate revenue split, outshining the industry standard 80/20 and attracting top talent from rival groups. This bold move has catapulted them to become the second most active ransomware group, with over 332 reported victims since mid-2025.