Skip to main content

Emerging Threats

Smartphone on a plain surface with subtle screen reflection in natural light.

NSO Group Defies Court Order, Continues Targeting WhatsApp Users

Despite a court order blocking it from doing so, NSO Group continues to target WhatsApp users, defying the ruling and putting users at risk. The company is fighting to overturn the order, claiming it will suffer harm if it's forced to comply.

Analyst 207
Dimly lit server room with rows of computer servers, one device highlighted in brighter light.

Ransomware Gang 'The Gentlemen' Traced to Suspected Russian Operator

Meet The Gentlemen, a notorious ransomware gang that's rapidly growing in power thanks to its unusually generous 90/10 affiliate revenue split, outshining the industry standard 80/20 and attracting top talent from rival groups. This bold move has catapulted them to become the second most active ransomware group, with over 332 reported victims since mid-2025.

Analyst 207
Satellite dish on a rooftop with subtle radio frequency interference under a clear blue sky.

Russia's Satellite Exposes GPS Vulnerability with Targeted Bursts

Researchers have uncovered a concerning pattern of targeted GPS disruptions, with at least 75 brief outages detected across northern Europe between 2019 and 2026, all triggered by high-powered radio energy bursts. These 10-second jamming events, occurring at a frequency used by GPS and European navigation satellites, coincided with navigation antenna failures from Romania to Greenland.

Analyst 207
Developer workstation with laptop, code, notes, and coffee cups, set against a blurred office or city backdrop.

AI Coding Agents Exposed to 'Agentjacking' Attacks

Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

Analyst 207
Blurred university building with subtle digital elements hinting at cyber breach.

ShinyHunters Breach Exposes 454,600 University of Nottingham Records

The University of Nottingham has confirmed a major data breach, with a notorious cybercriminal group gaining access to a massive 454,600 student records, affecting both current students and alumni. The university is working closely with authorities and experts to investigate the incident and mitigate its impact.

Analyst 207
Secure mobile gateway device on a rack with cables, set against a neutral background with a cityscape.

Ivanti Sentry vulnerability exploited in attacks

Within 24 hours of Ivanti releasing a patch for a high-severity vulnerability in its Sentry software, attackers began exploiting it in real-world attacks, with a large number of exploitation attempts detected. The flaw, tracked as CVE-2026-10520, allows hackers to execute code with root privileges on vulnerable mobile gateways.

Analyst 207
Rack-mounted router surrounded by devices and cables in a network closet overlooking an urban area.

China Exposes Botnet Resurgence, AI Influence Ops Targeting US

A botnet once dismantled by US law enforcement has made a stunning comeback, with over 1,500 compromised routers and IoT devices now under the control of China-nexus actors, who are using it to fuel influence campaigns and recruitment scams. This resurgence poses a significant threat, with the same group of actors still active and causing chaos.

Analyst 207
Analysts monitor online activity on a large screen displaying a US map with indicators and markers.

OpenAI Exposes Chinese Influence Operation Using ChatGPT

OpenAI has uncovered a sneaky Chinese influence operation that used ChatGPT to spread disinformation, posing as American voices to manipulate online debates. The operation, tracked by OpenAI's threat intelligence team, appears to be a classic case of foreign meddling.

Analyst 207
Blurred laptop screen and server rack in a brightly-lit workstation setting.

Attackers Exploit Langflow Path Traversal Flaw in Active Attacks

A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, a popular AI development platform, allowing attackers to write arbitrary files to its filesystem. This is made possible by a path traversal vulnerability, CVE-2026-5027, which can be easily triggered due to Langflow's default unauthenticated auto-login feature.

Analyst 207
Disrupted open-source workspace with laptop, notes, and coding materials amidst blurred cityscape background.

Miasma Worm Source Code Leaked, Threatens Open-Source Ecosystem

The Miasma worm's source code leak is a game-changer, putting the entire open-source ecosystem at risk after already infiltrating 73 Microsoft repositories on GitHub. This credential-stealing attack framework operates autonomously, spreading rapidly by infecting developer machines and compromising legitimate repositories.

Analyst 207
Rows of computer servers and equipment in a brightly-lit server room with a single out-of-focus laptop screen in the…

ShinyHunters Targets Oracle PeopleSoft Servers in Widespread Data Theft Attacks

ShinyHunters, a notorious extortion group, has launched a massive data theft campaign targeting Oracle PeopleSoft servers, compromising over 300 instances across 100+ organizations, with a significant impact on the education sector. The attackers have brazenly claimed responsibility, boasting of their exploits in a chilling conversation with BleepingComputer.

Analyst 207
Windows laptop on a clean surface with a blank screen in a brightly-lit room.

Disgruntled Bug Hunter Exposes New Windows 0-Day Vulnerability

A disgruntled bug hunter, known as Nightmare Eclipse, has revealed a new zero-day vulnerability called RoguePlanet, which can give attackers SYSTEM-level control over fully patched Windows 10 and 11 systems. The exploit, fueled by a grudge against Microsoft, targets a weakness in Windows Defender.

Analyst 207
Person sitting at desk with laptop open, hands poised over keyboard in a brightly-lit office setting.

Cybercriminals Exploit AI Hype in Social Engineering Attacks

Cybercriminals are cleverly exploiting our curiosity about AI to launch sophisticated social engineering attacks, using trusted AI names and urgent lures to trick victims into divulging sensitive info or downloading malware. By tapping into our desire to stay ahead of the curve, attackers are able to bypass our usual caution and catch us off guard.

Analyst 207
A dimly lit home office with scattered IoT devices, routers, and computers, hinting at network connections.

China-Linked JDY Botnet Surges to 1,500 Devices for Cyber Reconnaissance

A covert network of over 1,500 devices, linked to China, has been uncovered, feeding sensitive data to nation-state actors in a massive cyber reconnaissance operation. This JDY botnet has rapidly expanded, scanning and mapping vulnerable infrastructure on a massive scale.

Analyst 207
Smartphone with social media interface on screen surrounded by fake software packaging in a dimly lit room.

TikTok Tutorials Spread Vidar Stealer via Fake Software Lures

Cybercriminals are using TikTok and Instagram Reels to spread the Vidar infostealer by disguising it as free software tutorials, tricking viewers into downloading malware. By reporting these accounts, users can help take them down and slow down the attackers' momentum.

Analyst 207
Technicians work in a brightly lit network operations room with a central router or switch surrounded by equipment and…

CISA Flags Cisco, Chrome, Arista Flaws as Actively Exploited

Stay safe online: CISA has flagged serious vulnerabilities in Cisco, Chrome, and Arista that are being actively exploited by hackers, so take action now to protect your systems. These flaws could let attackers gain unauthorized access, making it crucial to update your software ASAP.

Analyst 207
Brightly-lit tech setting with rows of equipment in the background and an unoccupied computer terminal in the foreground.

Langflow Vulnerability Exploited for Unauthenticated Remote Code Execution

A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, allowing attackers to execute remote code without needing any login credentials. This vulnerability, tracked as CVE-2026-5027, enables malicious actors to write files to any location on a host filesystem.

Analyst 207
Cluttered home office with laptop and scattered papers in dim light.

SilabRAT Trojan Targets Crypto Wallets with Session Hijacking

Meet SilabRAT, a sneaky Trojan that's been sold as a malware-as-a-service on dark web forums since late 2025, allowing cybercrooks to hijack crypto wallet sessions and swipe funds. For just $5,000 a month, attackers can get their hands on this powerful tool and start targeting unsuspecting crypto wallet users.

Analyst 207
US military base with networking gear and a router on a table.

China-linked JDY botnet targets US military networks with expanded reconnaissance.

The JDY botnet, linked to China, has more than doubled its malicious reach since January 2024, growing from 650 to over 1,500 compromised devices, with a significant focus on infiltrating US military networks and associated targets. This expanding reconnaissance capability poses a concerning threat to US cybersecurity.

Analyst 207
Person holding smartphone stands before secure door with keycard reader and biometric scanner.

Credential Theft Spurs Demand for Secure Identity Verification

Credential theft skyrocketed 160% in 2025, fueling a critical need for secure identity verification solutions that can outsmart AI-driven attacks. To stay ahead, robust multi-factor authentication is a must-have, combining unique factors like something you know, have, and are to fortify defenses.

Analyst 207
Office setting with laptop showing blurred email inbox on screen.

Microsoft Fixes Zero-Day Flaw in Exchange Server Exploited in Attacks

Microsoft has patched a high-severity flaw in Exchange Server, known as CVE-2026-42897, which allowed hackers to execute malicious JavaScript in victims' browsers simply by sending a specially crafted email. This zero-day vulnerability was actively exploited in attacks, putting Outlook Web Access users at risk.

Analyst 207
Modern network hub with sleek architecture symbolizing tech and security intersection.

AI-Fueled Attacks Prompt Enterprises to Overhaul Security Architecture

Enterprises in APAC are scrambling to revamp their security architecture as AI-fueled attacks exploit new vulnerabilities at lightning-fast speed, making rapid containment more crucial than ever. Automation is now a vital defense against these accelerated threats.

Analyst 207
Modern office workstation with laptop and computer setup amidst blurred server room equipment.

ServiceNow Warns of Flaw Exploited for Unauthorized Access

ServiceNow has issued a security update to fix a flaw that could allow unauthorized users to gain excessive access to customer instances, and the company is urging users to take action to protect their systems. The update was applied to hosted customer instances on June 5, 2026.

Analyst 207
Windows laptop on a plain surface with a blank system interface on screen, nearby USB drive and scattered notes.

Microsoft Defender Zero-Day Exploited for SYSTEM Access

A security researcher, known as Chaotic Eclipse, has discovered a Microsoft Defender zero-day exploit, dubbed RoguePlanet, that can give attackers unrestricted access to compromised machines. The proof-of-concept exploit, released under the handle MSNightmare, can yield a shell with SYSTEM-level privileges, allowing hackers to run arbitrary code and perform unauthorized actions.

Analyst 207