Emerging Threats

FBI Disrupts Online Child Abuse Ring Linked to Violent Extremist Collective
The feds have taken down a predator, arresting a Tennessee man linked to a violent extremist collective for exploiting vulnerable children online. Zachary Sweeney, 30, faces up to 50 years in prison for his heinous crimes, including sexual exploitation and distributing child abuse material.

Malicious npm Packages Target Cloud Credentials
Malicious actors are targeting cloud credentials by publishing fake npm packages that mimic popular projects, allowing them to infiltrate developer environments and gain access to sensitive AWS and Elastic credentials. In just four hours, a single attacker published 14 malicious packages using cleverly disguised names.

Gogs Vulnerability Exposes Open-Source Git Service to RCE Attacks
A critical vulnerability in Gogs, an open-source Git service, has been exposed, leaving users open to remote code execution (RCE) attacks - and an exploit module is already available. The flaw was reported as early as March, but shockingly, the project's maintainers have failed to respond to the researcher ever since.

Threat Actors Exploit ChatGPT Sharing Feature to Deliver Malware
Malicious actors are exploiting ChatGPT's sharing feature to spread malware, using convincing fake outage messages to trick users into downloading malicious desktop applications. They even hijacked Google ads to make their scam look legit.

California AG Sues 23andMe Over Data Breach Handling
California's top law enforcement official is taking on 23andMe for its botched handling of a massive data breach that exposed the sensitive genetic and personal info of nearly 7 million customers - including over 855,000 Californians. The lawsuit claims the company's lax security and software quality allowed hackers to get away with highly sensitive data.

California Sues 23andMe Over Data Breach Security Failings
California's top lawyer, Rob Bonta, is taking on 23andMe for allegedly failing to protect millions of people's sensitive genetic data and downplaying the severity of a massive 2023 data breach. The lawsuit claims the company broke California law by not keeping personal info safe and lying to customers about the breach.

LLM Agent Enables Rapid Post-Exploitation in Marimo Networks
On May 10, 2026, a savvy attacker used a large language model agent to rapidly exploit a vulnerable Marimo instance, leveraging CVE-2026-39987 to spark a swift and damaging breach. This critical vulnerability allowed the attacker to execute arbitrary system commands, paving the way for cloud credential theft and further malicious activity.

Dutch Authorities Disrupt Massive Botnet of 17 Million Devices
In a major cybercrime crackdown, Dutch authorities have successfully dismantled a massive botnet comprising 17 million infected devices, seizing over 200 servers used to host its infrastructure. This significant takedown was made possible through a collaborative effort between the Police and the National Cyber Security Centre (NCSC).

Dutch Police Disrupt Mystery Botnet, Seize 17M Devices
Dutch police have successfully dismantled a massive mystery botnet, freeing a staggering 17 million devices from its control. This significant disruption was made possible by tracing around 200 servers to the Netherlands and having the hosting provider shut them down.

Silent Ransom Group Escalates Tactics with In-Person IT Impersonation
The FBI warns that the notorious Silent Ransom Group is taking a more aggressive approach, impersonating IT staff in person to infiltrate corporate systems, targeting US law firms, insurance, finance, and healthcare companies since 2023. This new tactic marks a significant escalation from their previous remote trickery methods.

Russia-linked Group Leverages ChatGPT in Cyberattacks on Ukraine
Meet GREYVIBE, a Russia-linked cyber group that's taking its attacks on Ukraine to the next level with the help of AI tools like ChatGPT, targeting the country's military and government. This sinister crew is leveraging cutting-edge tech to supercharge its cyberattacks.

Russia-Linked GREYVIBE Exploits AI in Ukraine Cyberattacks
Discover how the Russia-linked group GREYVIBE is using AI to launch sophisticated cyberattacks on Ukraine, leveraging tactics like spear-phishing emails and fake websites to spread malware. WithSecure researchers have tracked GREYVIBE's activities back to August 2025, revealing a pattern of attacks targeting Ukraine's military, government, and civilian sectors.

ChatGPT Exposes Users to Prompt Injection Attacks via Browser Content
Researchers have uncovered a vulnerability in ChatGPT that leaves users open to prompt injection attacks, where malicious content is embedded into web pages and then summarized by the AI system as legitimate information. This loophole could put users at risk of falling prey to spoofed security alerts and other online threats.

ShinyHunters Breaches Charter, Exposes 4.9M Customer Records
A massive data breach at Charter has exposed a whopping 4.9 million customer records, with hackers from the notorious ShinyHunters group proudly adding the telco to their "trophy shelf" and making sensitive info like names, addresses, and phone numbers publicly available. Charter has downplayed the incident, claiming no sensitive data was taken, but the reality is that millions of customers are now at risk.

Shadow AI Exposes 2,000 Vibe-Coded Apps with Sensitive Data
A shocking discovery by Red Access revealed over 2,000 apps with sensitive corporate, operational, or personal data exposed online, leaving countless organizations vulnerable to risk. These apps, found on popular vibe-coding platforms, were often deployed without basic security controls, granting open access to sensitive information.

Elder Data Trafficker Draws 10-Year Sentence
A massive data scam that compromised the personal info of over 7 million elderly Americans has landed its mastermind, 57-year-old Troy Murray, a 10-year prison sentence - a major victory in the fight against these heartless crimes. Murray, who went by the alias "Steve Dixon," was found guilty of running a scheme that sold sensitive data, including names, phone numbers, and addresses, to overseas scammers.

Malicious NuGet Package Exfiltrates Sicoob Banking Credentials
A malicious NuGet package, masquerading as a C# SDK for a major Brazilian financial system, was designed to steal sensitive banking credentials, including client IDs, PFX passwords, and certificate bytes, from unsuspecting developers. This rogue package, downloaded nearly 500 times, put automation and security at risk.

Chinese Hackers Exploit Middle East War to Target Energy, Maritime Firms
Chinese-aligned hackers are intensifying their attacks on maritime and energy companies in the Gulf region, exploiting the Middle East conflict to expand their espionage operations and gain a strategic advantage for Beijing. This alarming surge in cyber threats has been flagged by cybersecurity researchers at ESET.

Charter Communications Breach Exposes 4.9 Million Accounts
A shocking data breach at Charter Communications has left 4.9 million customer accounts vulnerable, with hackers gaining access to sensitive information including names, email addresses, phone numbers, and physical addresses. The breach occurred after a clever voice phishing attack on April 1 allowed cybercriminals to tap into the company's Salesforce database.

AI-Generated Malware Exposes Operator's GitHub Token
A malicious npm package, disguised as a harmless sync utility called "mouse5212-super-formatter", was downloaded 676 times before it was caught stealing sensitive data and exposing its creator's GitHub token. This AI-generated malware cleverly hid its true intentions, uploading stolen files to a fake repository and covering its tracks.

Kimsuky Expands Malware Arsenal with HTTPSpy, HelloDoor
Kimsuky, a notorious North Korean hacking group, has upgraded its malware arsenal with HTTPSpy and HelloDoor, using clever tactics like fake installation pages and a spoofed Webex meeting to infiltrate targets. The group's latest attacks involve highly tailored social engineering and real-time infection verification to maximize success.

Cybercrime Gang Targets Fans with Miner Malware via Pirated Media Sites
Millions of fans are unwittingly getting hacked when they visit popular pirated media sites, with a staggering 40 million visits to infected sites in April alone. A sneaky malware campaign is using fake video player updates to infect devices with cryptomining and remote-access malware.

GreyVibe hackers wield AI tools to fuel multi-sector cyberattacks
Meet GreyVibe, a likely Russian threat group that's been wreaking havoc across multiple sectors in Ukraine since at least August 2025, using AI-generated social engineering and custom malware to fuel its attacks. WithSecure researchers uncovered the group's activities, revealing a surprisingly unsophisticated approach despite its use of advanced AI tools like ChatGPT and Google Gemini.

Microsoft Faces Backlash Over Zero-Day Disclosure Feud
A researcher known as Nightmare Eclipse has unleashed a series of six Windows zero-day vulnerabilities, with working exploit code for at least three, and has threatened to release another on July 14, sparking a public feud with Microsoft. The ominous warning, which has left Microsoft speaking out against uncoordinated disclosures, has security experts on high alert.