Skip to main content

Emerging Threats

Smartphone with blank screen on a neutral table in a quiet room.

Meta Accuses NSO Group of Breaching WhatsApp Injunction

Meta is taking a stand against NSO Group, accusing the Israeli spyware vendor of breaching a WhatsApp injunction by targeting users with social engineering attempts. The company claims it successfully thwarted these malicious efforts, but is now asking a federal judge to hold NSO Group in contempt.

Analyst 207
University office with computer on desk, blurred to highlight background.

Oxford University Exposes Data Breach After Career Platform Hack

The University of Oxford recently alerted users to a data breach on its CareerConnect platform, which occurred on May 28 when attackers gained access to sensitive information, including names, email addresses, and encrypted passwords. To protect users, locally set passwords have been invalidated and affected users will be prompted to reset their passwords upon next login.

Analyst 207
Server equipment sits on a rack in a data center with cables and networking gear surrounding it.

VerdantBamboo Targets Linux Systems with Customized Malware Arsenal

Meet VerdantBamboo, a stealthy threat actor that infiltrated Linux and BSD systems, hiding in plain sight for 18 months by cleverly evading detection and morphing its malware arsenal to blend in. Its sophisticated attacks went undetected until Volexity's incident response team uncovered the intrusion, revealing a complex trail that led from Egnyte appliances into Microsoft 365 environments.

Analyst 207
Smartphone with Instagram login screen on display, set against a blurred cityscape background.

Meta AI Flaw Compromises 20,000 Instagram Accounts

A bug in Meta's AI-powered support feature, High Touch Support, allowed outsiders to access nearly 20,000 Instagram accounts by exploiting a flaw that failed to verify email addresses for password reset requests. This oversight enabled hackers to bypass security checks and gain unauthorized account access.

Analyst 207
Brightly-lit office setting with phone on desk, blurred background, and corporate elements.

Threat Actors Exploit Vishing, Physical Intrusions in US Data Extortion Campaign

Meet UNC3753, a notorious group of threat actors using clever voice phishing and social engineering tactics to infiltrate US corporate environments and steal sensitive data. Their deceitfully simple attacks start with a phone call or email and quickly escalate into rapid data theft and ransom demands.

Analyst 207
Smartphone on a neutral surface with blurred cityscape or office background.

Meta Exposes Flaw in AI Support System Used to Hijack 20,000 Instagram Accounts

Meta revealed that over 20,000 Instagram accounts were hijacked after attackers exploited a vulnerability in its AI-powered support system, allowing them to reset passwords and gain unauthorized access. The flaw was found in a system called High Touch Support, an AI-assisted account recovery tool designed to help users regain control of their accounts.

Analyst 207
Law firm's reception desk with phone, notepad, and pen, and blurred office workers or files in the background.

Silent Ransom Group Exploits Law Firms with Fake IT Support Scams

Law firms are being targeted by the Silent Ransom Group through clever fake IT support scams, putting sensitive client information at risk. This sophisticated attack starts with innocent-looking invoice emails that trick victims into calling a phone number, initiating a chain of events that can lead to devastating consequences.

Analyst 207
Cluttered router configuration room with networking equipment and devices scattered across shelves and tables.

C0XMO Botnet Exploits DD-WRT Flaw to Spread, Disrupts Rival Malware

Meet C0XMO, a highly sophisticated botnet malware that's disrupting the status quo with its advanced architecture and modular design, allowing it to spread rapidly by exploiting flaws like the DD-WRT vulnerability CVE-2021-27137. Its operators can easily update and adapt the malware to launch devastating DDoS attacks.

Analyst 207
A WordPress dashboard screen with a cracked laptop keyboard in the foreground, symbolizing site vulnerability.

Hackers Exploit Everest Forms Pro Flaw to Hijack WordPress Sites

More than 29,300 attempted hacks have been blocked by Wordfence, revealing a surge in automated attacks exploiting a critical flaw in the Everest Forms Pro plugin, tracked as CVE-2026-3300. This alarming number highlights the urgent need for WordPress site owners to safeguard against this vulnerability.

Analyst 207
Networked server equipment and cabling in a brightly-lit data center with a blurred background.

CISA Flags SolarWinds Serv-U Flaw as Actively Exploited

A critical flaw in SolarWinds Serv-U is being actively exploited, allowing attackers to crash the service with a specially crafted POST request - no authentication required. This denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered by a simple HTTP POST request with a malicious Content-Encoding header.

Analyst 207
Smart TV on a media console in a living room with subtle hints of a vast network connection in the background.

Free Apps Turn Smart TVs Into AI Web-Scraping Proxies

Free apps can secretly turn your smart TV into a powerful tool for web scraping, unknowingly contributing to a massive residential proxy network of over 400 million IPs. This startling reality raises questions about consumer data and the hidden use of their devices.

Analyst 207
GitHub repository page on laptop screen with error message and blurred software development workspace background.

Miasma Worm Targets Microsoft GitHub Repositories in Supply Chain Attack

GitHub has taken swift action, disabling access to 73 Microsoft repositories across four organizations after a sneaky supply chain attack by the Miasma Worm compromised code on the platform. The disruption was triggered when the malware targeted Microsoft's GitHub repositories, prompting site-wide warnings and restricted access.

Analyst 207
University career services area with students and laptop.

Oxford Uni Student Data Breached Through Career Platform

Oxford University student data has been breached once again, this time through a career platform compromise, leaving records exposed. The incident is a separate attack from a break-in that occurred just last month.

Analyst 207
Network equipment and router on a rack with technician checking a laptop in the background.

Cisco SD-WAN Manager Flaw Actively Exploited

Cisco is warning of a high-severity vulnerability in its Catalyst SD-WAN Manager that allows attackers to execute commands as root, and it's already being exploited by hackers. This flaw, rated 7.8 on the CVSS scale, could give attackers control over your system if they're able to upload a malicious file.

Analyst 207
Network device with cables on a rack in a well-lit technology room.

Palo Alto Networks Warns of Active PAN-OS Vulnerability Exploitation

Palo Alto Networks has sounded the alarm on a critical PAN-OS vulnerability, CVE-2026-0257, that's being actively exploited by threat actors to bypass authentication and gain unauthorized access to VPN connections. This security gap could allow attackers to circumvent controls and initiate their own VPN sessions, putting your network at risk.

Analyst 207
Blurred computer workstation and file cabinet in a brightly-lit office interior, with a cityscape visible through the window.

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics

Beware of UNC3753, a notorious group that's been stealing sensitive data from US law firms and other professional services, using clever vishing tactics and lightning-fast intrusions to extort their victims. In some cases, they can go from initial contact to data theft in under an hour.

Analyst 207
Person in a corporate office hallway holds a small device, looking concerned.

Extortion Gang Exploits Corporate Networks with In-Person Visits

Meet UNC3753, a notorious extortion gang that's taking corporate hacking to a whole new level - from deceitful phone calls to in-person visits, where they show up at companies' doorsteps with thumb drives, targeting dozens of US banks, law firms, and professional services firms in just a few short months. Their tactics have evolved from fake emails to help-desk calls and now, brazen doorstep drop-offs.

Analyst 207
Laptop screen displays rogue login prompt with generic logo and username field.

Polyfill Compromise Targets Major Websites with Rogue Login Prompts

Major websites, including Toshiba and Muji, have been compromised by a rogue login prompt scam through polyfill.io, tricking visitors into entering sensitive information. If you encountered the fake sign-in screen, be sure to cancel and change your password to protect your account.

Analyst 207
Server room with networked equipment and a single server in the foreground.

Hackers Actively Exploit SolarWinds Serv-U Flaw to Crash Servers

SolarWinds has issued an emergency hotfix to address a critical flaw in its Serv-U file transfer product, which hackers are actively exploiting to crash servers with specially crafted POST requests. A denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered without authentication, posing a significant threat to users.

Analyst 207
Dimly lit software development workspace with laptop, notes, and coffee cups.

Malware Worms Infect npm Ecosystem in Dual Supply Chain Attacks

Meet IronWorm, a sneaky Rust-based malware that's infecting the npm ecosystem by scraping sensitive secrets from developers' machines and spreading through poisoned packages. This stealthy threat hides behind an eBPF kernel rootkit and communicates with its operators over Tor.

Analyst 207
Rows of equipment racks and patch panels in a brightly-lit office network closet.

Chinese APT Exploits New Malware to Prolong Network Access

A Chinese-linked espionage group, tracked as UNC5221 or VerdantBamboo, exploited new malware to secretly maintain access to US networks for over 18 months, evading detection by blending in with legitimate traffic. The attackers used a sophisticated backdoor called Brickstorm to prolong their stay undetected.

Analyst 207
Network router in a dimly lit server room setting.

Cisco SD-WAN Zero-Day Under Active Attack

Cisco SD-WAN is under siege from a zero-day vulnerability that's being actively exploited - and there's no patch in sight, leaving sys admins scrambling to protect their networks.

Analyst 207
Smartphone on cluttered desk in Middle Eastern-style room with Arabic patterns, beside newspapers and manual.

ESET Exposes Android Spyware Asin Targeting Arabic Users

Malicious apps masquerading as legitimate tools have been targeting Arabic-speaking Android users, packing stealthy spyware capabilities that allow them to siphon off sensitive information. These fake apps, part of a spyware cluster called Asin, are being spread through fraudulent websites and social accounts.

Analyst 207
Dental professional looks concerned while viewing laptop in a brightly-lit healthcare setting.

DentaQuest Breach Exposes 2.6M Accounts

A massive data breach at dental benefits provider DentaQuest has exposed a staggering 2.6 million accounts, after hackers stole over 234 GB of sensitive information and released it following failed negotiations with the company.

Analyst 207