Skip to main content

Emerging Threats

Server room with rows of computer servers and cables, laptops in foreground with some monitors displaying code or data.

Malware Worms Red Hat npm Packages, Targets Cloud Credentials

A single compromised Red Hat employee's GitHub account was used to seed dozens of Red Hat npm package releases with a self-propagating credential-stealer, putting cloud credentials at risk. The malicious packages, downloaded around 80,000 times a week, are still considered a live threat.

Analyst 207
Software development workspace with laptop and papers, subtle coding environment in background.

Red Hat npm Packages Compromised in Supply-Chain Attack

A recent supply-chain attack compromised 32 Red Hat npm packages, affecting 117,000 weekly downloads, after attackers backdoored 96 package versions under the @redhat-cloud-services namespace. The breach occurred when a Red Hat employee's GitHub account was compromised, allowing malicious commits to be pushed.

Analyst 207
Government office setting with subtle digital infrastructure in background.

Phishers Target Midterm Elections With 5K+ Domain Registrations

Scammers are ramping up their efforts to deceive voters with over 5,000 election-themed domains registered in just two months, providing a fertile ground for phishing, impersonation, and misinformation campaigns to manipulate the midterm elections. This alarming surge in domain registrations has already exposed around 17,000 credentials linked to sensitive organizations and services.

Analyst 207
Developer workstation with open laptop showing code, surrounded by empty coffee cups and scattered notes, hinting at a…

Miasma Supply Chain Attack Targets Red Hat npm Packages

A new supply-chain campaign, codenamed Miasma, has compromised multiple Red Hat npm packages to steal sensitive credentials and deliver a self-propagating worm, putting developer machines at risk. This sneaky attack uses clever tactics like install-time execution and encrypted exfiltration to harvest secrets and spread its reach.

Analyst 207
Senior director stands in a brightly-lit security operations center with computer screens and keyboards.

Dashlane Bolsters Defenses After Brute Force Attacks Lock Out Users

Dashlane recently thwarted a brute force attack that temporarily locked out some users, but swift action ensured their accounts were quickly restored. The company has since bolstered its defenses and is closely monitoring the situation to prevent future incidents.

Analyst 207
Modern sports stadium with ticketing booth, broadcast control room, and concourse, set against a blurred city skyline.

World Cup Faces New Cyber Threats in AI-Driven Era

As the World Cup kicks off on June 11, it's not just a sporting spectacle - it's a high-stakes target for cyber threats, with billions of people, devices, and transactions converging online at once. This massive influx creates a perfect storm of vulnerability, exposing ticketing, payments, broadcasts, and infrastructure to unprecedented risk.

Analyst 207
WordPress website backend on a laptop in a cluttered home office setting.

WordPress Sites Targeted in Steam Profile Malware Campaign

A massive malware campaign has infected nearly 2,000 WordPress websites, using a sneaky tactic of hiding command-and-control data within Steam Community profile comments. The attack, first detected in July 2025, has left security experts scrambling to uncover its entry point.

Analyst 207
Government building with subtle cyber activity hints in bright daylight.

China-Aligned Hackers Target Czech Republic, Taiwan in Cyber Espionage Push

China-aligned hackers have launched a sneaky cyber espionage campaign, dubbed Operation Dragon Weave, targeting officials and citizens in the Czech Republic and Taiwan with a cunning malware that masquerades as a legitimate cloud storage service. The malware ultimately delivers an AdaptixC2 agent, putting sensitive information at risk.

Analyst 207
Rows of computer equipment racks and industrial controllers in a dimly lit network operations center with a sense of…

Cyberattacks Accelerate as AI Lowers Bar for Threat Actors

Defaults and automation are handing attackers cheap, fast entry points, making it alarmingly easy for them to wreak havoc - just like in the case of Gogs, where open registration and unlimited repository creation allow unauthenticated attackers to create an account and repository with ease. This vulnerability is being exploited, along with a critical authentication bypass flaw in PAN-OS and Prisma Access, underscoring the urgent need for heightened cybersecurity measures.

Analyst 207
Office workers look at laptops and papers with concern, a large monitor in center displays error message.

Microsoft Probes Office Apps, Teams File Access Outage

Microsoft is currently investigating an issue that's preventing some users from accessing files in Office for the web and Microsoft Teams, with affected users seeing an error message stating that Office Online services are temporarily unavailable. The company is working to restore services as soon as possible.

Analyst 207
Gaming setup with computer and monitor on a desk, cityscape blurred in background.

Atlas Menu Hack Exposes 64,000 User Records

A shocking security breach has hit Atlas Menu, a popular cheat service for Grand Theft Auto, with an attacker claiming to have fully compromised the system and leaked 64,000 user records online. The hacker also made the disturbing allegation that Atlas Menu was secretly taking screenshots of users' machines.

Analyst 207
Network device in a generic technology environment with bright indoor lighting.

Palo Alto VPN Bug Sees Active Exploitation

Security experts at Rapid7 have confirmed that hackers are actively exploiting a critical authentication bypass flaw in Palo Alto Networks' VPN, putting PAN-OS users at risk of targeted attacks. This urgent development means users must patch their systems ASAP to prevent exploitation.

Analyst 207
Windows domain controller setup in a corporate network environment with blurred screen.

Windows Netlogon flaw exploited in attacks after patch release

A critical Windows Netlogon flaw, patched just last month, is now being actively exploited in attacks, putting vulnerable systems at risk of remote code execution. This severe vulnerability, rated 9.8 out of 10 in severity, allows attackers to gain control of targeted domain controllers with just a specially crafted network request.

Analyst 207
Blurred laptop screen on a cluttered desk with scattered papers, hinting at digital disruption.

Dashlane Disrupts Service Amid Brute-Force Attacks

Dashlane recently took swift action to protect its users, suspending customer accounts in response to a surge of brute-force attacks that triggered the company's automatic defenses, putting engineers' weekends on hold. This decisive move showcases the password manager's commitment to safeguarding user security.

Analyst 207
Person struggles to access laptop with multi-factor authentication prompt on screen amidst subtle hints of technical issues.

Microsoft Outage Disrupts Multi-Factor Authentication Setup, My Sign-Ins Platform

Microsoft is currently investigating an outage that's preventing users from setting up multi-factor authentication and accessing the My Sign-Ins platform, with the issue confirmed around 5 AM ET. The company is actively working to resolve the disruption, urging affected customers to monitor its Microsoft 365 Status account for updates.

Analyst 207
Windows desktop with File Explorer partially open, showing blurred files and a hint of a hidden folder in the background.

FSB-Linked Worm Exploits Windows Flaw to Evade Detection

Cyber attackers have cleverly exploited a known Windows flaw, CVE-2025-8088, to sneak a malicious payload into victims' systems, allowing them to gain access and lay the groundwork for further attacks. This stealthy move was uncovered by Sekoia, which tracked the initial access stage as GammaPhish.

Analyst 207
Developer workstation with laptop, terminal, and smartphone in a brightly-lit home office setting.

OpenAI Codex Tokens Exfiltrated in Malicious npm Supply Chain Attack

For a month, a malicious npm package called codexui-android secretly stole OpenAI Codex authentication tokens from over 29,000 weekly users, sending them to an attacker-controlled server. The package, masquerading as a remote web UI for OpenAI Codex, had gained user trust through active development before being compromised.

Analyst 207
Laptop screen shows ChatGPT-like interface with suspicious URL and blurred malware prompt.

Hackers Exploit ChatGPT Features in Malware Phishing Campaigns

Hackers are exploiting ChatGPT's features to create convincing phishing pages that trick victims into downloading malware, using the platform's code-rendering feature to build fake pages that appear legitimate. These attacks cleverly use trusted ChatGPT domains to evade detection, making them harder to spot.

Analyst 207
WordPress dashboard on a laptop screen amidst a cluttered home office, symbolizing vulnerability.

WP Maps Pro Flaw Exploited to Create Admin Accounts

A critical vulnerability in the popular WP Maps Pro plugin, used by over 15,000 WordPress sites, has been exploited to create admin accounts, putting countless websites at risk of complete takeover. This high-severity flaw, tracked as CVE-2026-8732, allows attackers to escalate privileges and gain unrestricted access.

Analyst 207
Network equipment and servers in a brightly-lit IT hub with a laptop screen displaying a blurred VPN configuration in the…

Palo Alto Networks Warns of Active Exploitation of High-Severity VPN Bug

Palo Alto Networks has issued a warning about active exploitation of a high-severity VPN bug, urging users to patch their systems ASAP to avoid falling prey to potential security breaches. The vulnerability, CVE-2026-0257, allows attackers to bypass security restrictions and establish unauthorized VPN connections.

Analyst 207
Person typing on laptop with blurred map interface on screen, symbolizing WordPress site security breach.

Hackers Exploit WP Maps Pro Bug to Hijack WordPress Sites

In just 24 hours, over 3,600 hacking attempts were made to exploit a critical flaw in the WP Maps Pro plugin, allowing attackers to create admin accounts and log in without a password. This vulnerability, affecting version 6.1.0 and older, puts countless WordPress sites at risk.

Analyst 207
Dutch police officers inspect server equipment in a brightly-lit facility.

Dutch Police Disrupt Major Botnet Linked to 17 Million Infected Devices

Dutch authorities have successfully dismantled a massive botnet that had infected a staggering 17 million devices worldwide, turning everyday gadgets into a global attack platform. The operation, led by the Dutch Police and National Cyber Security Center, seized key servers and brought the botnet's infrastructure offline.

Analyst 207
Network security appliance on a rack in a brightly-lit data center.

Hackers Exploit Palo Alto GlobalProtect VPN Auth Bypass Flaw in Attacks

Hackers are actively exploiting a critical flaw in Palo Alto's GlobalProtect VPN, known as CVE-2026-0257, to gain unauthorized access to corporate networks. This alarming vulnerability allows attackers to bypass security restrictions and establish fake VPN connections.

Analyst 207
Network operations center with laptop, city view, and VPN diagram on whiteboard.

Palo Alto Networks Warns of Active Exploitation of GlobalProtect Flaw

Palo Alto Networks has issued a warning about a critical GlobalProtect flaw, CVE-2026-0257, that is being actively exploited, allowing attackers to bypass security restrictions and establish unauthorized VPN connections. This vulnerability affects specific PAN-OS and Prisma Access deployments with certain configurations.

Analyst 207