Skip to main content

Emerging Threats

Internet-exposed automatic tank gauge system at a gas station with pumps and convenience store in the background.

US Gas Station Tank Gauge Systems Vulnerable to Ongoing Attacks

US gas stations are under cyberattack, with hackers exploiting vulnerable tank gauge systems to gain control and wreak havoc. A joint advisory from top US agencies is urging critical infrastructure organizations to secure their internet-exposed systems ASAP.

Analyst 207
Employees work at desks with laptops and computers, some with blurred screens, in an office with a cityscape visible…

Verizon DBIR Exposes Growing Browser-Based Threats

Employees are unwittingly putting sensitive data at risk by using AI tools like ChatGPT and Gemini on corporate devices, with 67% accessing these services with personal accounts and 45% using them regularly. This Shadow AI phenomenon is rapidly escalating, with a fourfold year-over-year increase in insider risk.

Analyst 207
Compromised web server in a data center with a focus on the targeted server on a rack.

China-Linked OP-512 Targets IIS Servers with Custom Web Shells

Meet OP-512, a China-linked threat cluster with a taste for espionage, recently caught targeting IIS servers with custom web shells in a stealthy bid for sensitive intel. This sneaky operation aligns with China's intelligence priorities, putting certain sectors and geographies firmly in its crosshairs.

Analyst 207
Humanitarian aid distribution point with supplies and workers amidst a somber atmosphere, with a computer screen in the…

World Food Programme Breach Exposes 600k Gazan Family Records

A devastating data breach at the World Food Programme has left 600,000 vulnerable Gazan families exposed, with their personal records compromised - but thankfully, aid recipients have been assured that their support will continue uninterrupted.

Analyst 207
City council office with blurred computer screen and mobility aids in foreground.

UK Council Exposes Hundreds of Disabled Residents in Email Blunder

A simple email mistake by the City of York Council had serious consequences, exposing the identities of hundreds of disabled residents who hold Blue Badges. The blunder occurred when a BCC function failed, revealing the list of recipients in a message intended to be private.

Analyst 207
WordPress website backend dashboard on a laptop screen in a quiet workspace.

Hackers Exploit Everest Forms Pro Flaw to Compromise WordPress Sites

A critical vulnerability in Everest Forms Pro, affecting over 4,000 active WordPress installations, has been exploited by hackers to gain remote code execution, allowing them to take control of sites without authorization. A patch has been released, but sites remain at risk if not updated to version 1.9.13 or later.

Analyst 207
Long line of anxious fans waiting outside a ticketing booth, some visibly frustrated.

FIFA World Cup Scams Explode Ahead of 2026 Kickoff

As the 2026 FIFA World Cup approaches, scammers are kicking off their own game, with over 4,300 fraudulent domains and countless ticket scams, counterfeit merchandise, and banking malware already in circulation. With ticket requests exceeding 150 million and millions of fans eagerly awaiting kickoff, attackers are cashing in on scarcity and anxiety.

Analyst 207
Technicians examine a large router and network diagram in a control room with a map of network topology on a screen.

Cisco SD-WAN Zero-Day Exploited in Targeted Attacks

Cisco is warning of a high-severity zero-day vulnerability in its Catalyst SD-WAN Manager that is being actively exploited, allowing attackers to gain root privileges and execute arbitrary commands. This critical flaw affects all deployment types and could put your network at risk if left unpatched.

Analyst 207
Dimly lit cloud server room with rows of server racks and a single out-of-focus server screen in the foreground.

PCPJack Hijacks Cloud Servers for Covert SMTP Relay Network

Security firm Hunt.io uncovered a sneaky operation where hackers known as PCPJack hijacked cloud servers worldwide, turning them into secret SMTP relays that pumped out spam every five minutes. The stolen servers, found in major cloud platforms like AWS, Google Cloud, and Azure, were quietly converted into spam-spewing machines.

Analyst 207
Concerned person in a brightly-lit office setting with a sense of urgency and accelerated activity.

AI Agents Expose Hidden Risks as Insider Threats Evolve

The alarm bells are ringing: cyberattacks now unfold at breakneck speeds, with malicious actors able to wreak havoc in as little as 10-30 minutes, leaving defenders scrambling to keep up. This accelerated threat landscape is fueled by the growing sophistication of AI agents and their integration into business networks.

Analyst 207
Helpdesk workers surrounded by cubicles, phones, and fluorescent lighting, with an atmosphere of unease and vulnerability.

Ransomware Gang Pink Exploits Helpdesk Calls to Steal Credentials

Meet Pink, a notorious ransomware gang that's exploiting helpdesk calls to steal sensitive credentials using clever tactics like vishing and IT impersonation. They're using these stolen secrets to exfiltrate valuable data from enterprise cloud storage and productivity systems, leaving victims with a tough choice: pay up or face the consequences.

Analyst 207
Windows computer workstation with browser open, surrounded by technical books and office supplies.

Hola Browser Compromised to Deliver Cryptominer in Supply Chain Attack

Hola's CEO, Avi Raz Cohen, assured users that the company has taken swift action to prevent future breaches, rebuilding its distribution pipeline and implementing robust security measures. The move comes after a supply chain attack compromised the Hola Browser, secretly delivering a cryptominer to unsuspecting users.

Analyst 207
Laptop screen shows checkout page with subtle code hint in background, in neutral indoor setting.

Magecart Campaign Exploits Stripe to Host Stolen Payment Data

Meet the sneaky Magecart campaign that's exploiting Stripe to host stolen payment data, cleverly hiding its skimming code inside trusted domains like Google Tag Manager and Stripe's API. By using these legitimate-looking channels, the attack slips past security filters, putting online stores and customers at risk.

Analyst 207
Brightly-lit office setting with computer workstation in foreground and blurred screen.

Multiple Breaches Expose Sensitive Data Across Industries

Sensitive data has been compromised across various industries in a series of alarming breaches, including a clever social engineering scam that exposed info of 6 million Carnival Corporation customers and two incidents involving learning management company Instructure's Canvas platform. These breaches highlight the growing threat of cyber attacks and the importance of robust data protection measures.

Analyst 207
Dental office with scattered papers and blurred computer screen.

DentaQuest Breach Exposes 2.6 Million Accounts

A major data breach at DentaQuest has exposed a staggering 2.6 million accounts, after an extortion group called ShinyHunters claimed to have stolen over 234 GB of sensitive data. The breach was confirmed by DentaQuest on June 2, who assured customers they are actively managing the cybersecurity incident.

Analyst 207
Secure server room interior with highlighted network cable.

Secure Infrastructure Unlocks AI's Defense Potential

As Dave Wajsgras, chairman and CEO of Everfox, aptly puts it, AI's trustworthiness is only as strong as the security of its underlying data, networks, and access controls. A recent incident involving Anthropic's Claude Mythos model serves as a stark reminder of the risks, with an unauthorized group reportedly gaining access in mere hours.

Analyst 207
Crowded stadium concourse with people walking, some on phones, with a laptop on a food tray in the foreground.

Cybercriminals Target FIFA World Cup 2026 with Sophisticated Scams

As the 2026 FIFA World Cup approaches, cybercriminals are gearing up to scam unsuspecting fans with sophisticated ticketing scams, counterfeit sites, and panic-inducing mechanics. Experts warn that this major event has become a prime target for cyberattacks, with thousands of fraudulent domains and fake Facebook ads already circulating.

Analyst 207
Damaged computer screen on cluttered desk in WFP office with scattered papers and blurred cityscape background.

UN Food Agency Breach Exposes 600,000 Gaza Households' Data

Don't worry if you're a beneficiary of the World Food Programme's assistance programs - your registration remains valid and you don't need to take any action, even after a breach exposed the data of 600,000 Gaza households. You're still part of the program and will continue to receive support as usual.

Analyst 207
Laptop screen displays GitHub repository page with cityscape background, hinting at public online platform vulnerability.

Flaw in Claude Code GitHub Action Exposes Repositories to Hijacking

A security researcher discovered a logic hole in Anthropic's Claude Code GitHub Action that could let attackers hijack vulnerable public repositories with just a single opened GitHub issue. This flaw exploited broad read and write permissions, putting countless repositories at risk.

Analyst 207
A laptop with a blank screen sits amidst scattered papers and generic development tools in a well-lit workspace.

IronWorm Malware Infects 36 npm Packages in Supply-Chain Attack

Meet IronWorm, a sneaky Rust-based infostealer that's infected 36 npm packages, putting a wide range of sensitive credentials and secrets at risk of being harvested. This stealthy malware operates undetected, targeting everything from AWS and OpenAI credentials to cryptocurrency wallet files.

Analyst 207
Cluttered home office desk with Mac computer and blurred screen, suburban neighborhood visible through window.

Malvertising Campaign Spreads FlutterShell Backdoor to macOS Users

macOS users beware: a sneaky malware called FlutterShell is spreading through malicious ads and infected desktop apps, allowing hackers to take control of your device and steal sensitive data. This stealthy backdoor can execute commands, access files, and even siphon off browser session info - all while masquerading as legitimate software.

Analyst 207
Security expert standing in front of large screen display in a conference setting.

Microsoft Warns AI Adoption Exposes Organizations to New Malware Threats

Microsoft's senior security researcher warns that the AI tools making our jobs easier can also be exploited by threat actors, highlighting a new and urgent risk for organizations to manage. As AI adoption grows, companies must recognize it as both a valuable asset and a potential attack surface that requires careful protection.

Analyst 207
Laptop screen displays hacker forum on cluttered desk in home office setting.

Hackers Exploit Gaps in Vulnerability Programs with Simplified Playbook

Meet Hercules, the mastermind behind a notorious underground tutorial that spills the beans on how to turn vulnerability exploitation into cold, hard cash. With a refreshingly blunt approach, Hercules breaks down the process into simple, actionable steps that even novice attackers can follow.

Analyst 207
Generic office building with neutral-colored wall and glass façade.

Chinese Cybercrime Group TA4922 Expands Global Reach

Stay vigilant, organizations worldwide: a rapidly evolving Chinese cybercrime group, TA4922, is expanding its global footprint, rewriting the rules for corporate network exploitation and monetization. From East Asia to the UK, Germany, and beyond, this financially driven threat actor is localizing its attacks to hit closer to home.

Analyst 207