Emerging Threats

NSO Group Defies Court Order, Continues Targeting WhatsApp Users
Despite a court order blocking it from doing so, NSO Group continues to target WhatsApp users, defying the ruling and putting users at risk. The company is fighting to overturn the order, claiming it will suffer harm if it's forced to comply.

Ransomware Gang 'The Gentlemen' Traced to Suspected Russian Operator
Meet The Gentlemen, a notorious ransomware gang that's rapidly growing in power thanks to its unusually generous 90/10 affiliate revenue split, outshining the industry standard 80/20 and attracting top talent from rival groups. This bold move has catapulted them to become the second most active ransomware group, with over 332 reported victims since mid-2025.

Russia's Satellite Exposes GPS Vulnerability with Targeted Bursts
Researchers have uncovered a concerning pattern of targeted GPS disruptions, with at least 75 brief outages detected across northern Europe between 2019 and 2026, all triggered by high-powered radio energy bursts. These 10-second jamming events, occurring at a frequency used by GPS and European navigation satellites, coincided with navigation antenna failures from Romania to Greenland.

AI Coding Agents Exposed to 'Agentjacking' Attacks
Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

ShinyHunters Breach Exposes 454,600 University of Nottingham Records
The University of Nottingham has confirmed a major data breach, with a notorious cybercriminal group gaining access to a massive 454,600 student records, affecting both current students and alumni. The university is working closely with authorities and experts to investigate the incident and mitigate its impact.

Ivanti Sentry vulnerability exploited in attacks
Within 24 hours of Ivanti releasing a patch for a high-severity vulnerability in its Sentry software, attackers began exploiting it in real-world attacks, with a large number of exploitation attempts detected. The flaw, tracked as CVE-2026-10520, allows hackers to execute code with root privileges on vulnerable mobile gateways.

China Exposes Botnet Resurgence, AI Influence Ops Targeting US
A botnet once dismantled by US law enforcement has made a stunning comeback, with over 1,500 compromised routers and IoT devices now under the control of China-nexus actors, who are using it to fuel influence campaigns and recruitment scams. This resurgence poses a significant threat, with the same group of actors still active and causing chaos.

OpenAI Exposes Chinese Influence Operation Using ChatGPT
OpenAI has uncovered a sneaky Chinese influence operation that used ChatGPT to spread disinformation, posing as American voices to manipulate online debates. The operation, tracked by OpenAI's threat intelligence team, appears to be a classic case of foreign meddling.

Attackers Exploit Langflow Path Traversal Flaw in Active Attacks
A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, a popular AI development platform, allowing attackers to write arbitrary files to its filesystem. This is made possible by a path traversal vulnerability, CVE-2026-5027, which can be easily triggered due to Langflow's default unauthenticated auto-login feature.

Miasma Worm Source Code Leaked, Threatens Open-Source Ecosystem
The Miasma worm's source code leak is a game-changer, putting the entire open-source ecosystem at risk after already infiltrating 73 Microsoft repositories on GitHub. This credential-stealing attack framework operates autonomously, spreading rapidly by infecting developer machines and compromising legitimate repositories.

ShinyHunters Targets Oracle PeopleSoft Servers in Widespread Data Theft Attacks
ShinyHunters, a notorious extortion group, has launched a massive data theft campaign targeting Oracle PeopleSoft servers, compromising over 300 instances across 100+ organizations, with a significant impact on the education sector. The attackers have brazenly claimed responsibility, boasting of their exploits in a chilling conversation with BleepingComputer.

Disgruntled Bug Hunter Exposes New Windows 0-Day Vulnerability
A disgruntled bug hunter, known as Nightmare Eclipse, has revealed a new zero-day vulnerability called RoguePlanet, which can give attackers SYSTEM-level control over fully patched Windows 10 and 11 systems. The exploit, fueled by a grudge against Microsoft, targets a weakness in Windows Defender.

Cybercriminals Exploit AI Hype in Social Engineering Attacks
Cybercriminals are cleverly exploiting our curiosity about AI to launch sophisticated social engineering attacks, using trusted AI names and urgent lures to trick victims into divulging sensitive info or downloading malware. By tapping into our desire to stay ahead of the curve, attackers are able to bypass our usual caution and catch us off guard.

China-Linked JDY Botnet Surges to 1,500 Devices for Cyber Reconnaissance
A covert network of over 1,500 devices, linked to China, has been uncovered, feeding sensitive data to nation-state actors in a massive cyber reconnaissance operation. This JDY botnet has rapidly expanded, scanning and mapping vulnerable infrastructure on a massive scale.

TikTok Tutorials Spread Vidar Stealer via Fake Software Lures
Cybercriminals are using TikTok and Instagram Reels to spread the Vidar infostealer by disguising it as free software tutorials, tricking viewers into downloading malware. By reporting these accounts, users can help take them down and slow down the attackers' momentum.

CISA Flags Cisco, Chrome, Arista Flaws as Actively Exploited
Stay safe online: CISA has flagged serious vulnerabilities in Cisco, Chrome, and Arista that are being actively exploited by hackers, so take action now to protect your systems. These flaws could let attackers gain unauthorized access, making it crucial to update your software ASAP.

Langflow Vulnerability Exploited for Unauthenticated Remote Code Execution
A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, allowing attackers to execute remote code without needing any login credentials. This vulnerability, tracked as CVE-2026-5027, enables malicious actors to write files to any location on a host filesystem.

SilabRAT Trojan Targets Crypto Wallets with Session Hijacking
Meet SilabRAT, a sneaky Trojan that's been sold as a malware-as-a-service on dark web forums since late 2025, allowing cybercrooks to hijack crypto wallet sessions and swipe funds. For just $5,000 a month, attackers can get their hands on this powerful tool and start targeting unsuspecting crypto wallet users.

China-linked JDY botnet targets US military networks with expanded reconnaissance.
The JDY botnet, linked to China, has more than doubled its malicious reach since January 2024, growing from 650 to over 1,500 compromised devices, with a significant focus on infiltrating US military networks and associated targets. This expanding reconnaissance capability poses a concerning threat to US cybersecurity.

Credential Theft Spurs Demand for Secure Identity Verification
Credential theft skyrocketed 160% in 2025, fueling a critical need for secure identity verification solutions that can outsmart AI-driven attacks. To stay ahead, robust multi-factor authentication is a must-have, combining unique factors like something you know, have, and are to fortify defenses.

Microsoft Fixes Zero-Day Flaw in Exchange Server Exploited in Attacks
Microsoft has patched a high-severity flaw in Exchange Server, known as CVE-2026-42897, which allowed hackers to execute malicious JavaScript in victims' browsers simply by sending a specially crafted email. This zero-day vulnerability was actively exploited in attacks, putting Outlook Web Access users at risk.

AI-Fueled Attacks Prompt Enterprises to Overhaul Security Architecture
Enterprises in APAC are scrambling to revamp their security architecture as AI-fueled attacks exploit new vulnerabilities at lightning-fast speed, making rapid containment more crucial than ever. Automation is now a vital defense against these accelerated threats.

ServiceNow Warns of Flaw Exploited for Unauthorized Access
ServiceNow has issued a security update to fix a flaw that could allow unauthorized users to gain excessive access to customer instances, and the company is urging users to take action to protect their systems. The update was applied to hosted customer instances on June 5, 2026.

Microsoft Defender Zero-Day Exploited for SYSTEM Access
A security researcher, known as Chaotic Eclipse, has discovered a Microsoft Defender zero-day exploit, dubbed RoguePlanet, that can give attackers unrestricted access to compromised machines. The proof-of-concept exploit, released under the handle MSNightmare, can yield a shell with SYSTEM-level privileges, allowing hackers to run arbitrary code and perform unauthorized actions.