Skip to main content

Emerging Threats

Law enforcement officials in a federal courthouse or facility with daylight streaming through tall windows.

FBI Disrupts Online Child Abuse Ring Linked to Violent Extremist Collective

The feds have taken down a predator, arresting a Tennessee man linked to a violent extremist collective for exploiting vulnerable children online. Zachary Sweeney, 30, faces up to 50 years in prison for his heinous crimes, including sexual exploitation and distributing child abuse material.

Analyst 207
Developer workspace with laptop, terminal, and notes, hint of cloud diagram in background.

Malicious npm Packages Target Cloud Credentials

Malicious actors are targeting cloud credentials by publishing fake npm packages that mimic popular projects, allowing them to infiltrate developer environments and gain access to sensitive AWS and Elastic credentials. In just four hours, a single attacker published 14 malicious packages using cleverly disguised names.

Analyst 207
Dimly lit server room with rows of computer servers, one server highlighted with a faint red glow.

Gogs Vulnerability Exposes Open-Source Git Service to RCE Attacks

A critical vulnerability in Gogs, an open-source Git service, has been exposed, leaving users open to remote code execution (RCE) attacks - and an exploit module is already available. The flaw was reported as early as March, but shockingly, the project's maintainers have failed to respond to the researcher ever since.

Analyst 207
Person sitting at laptop with browser window open showing fake ChatGPT outage message.

Threat Actors Exploit ChatGPT Sharing Feature to Deliver Malware

Malicious actors are exploiting ChatGPT's sharing feature to spread malware, using convincing fake outage messages to trick users into downloading malicious desktop applications. They even hijacked Google ads to make their scam look legit.

Analyst 207
Courthouse exterior with subtle DNA elements in foreground.

California AG Sues 23andMe Over Data Breach Handling

California's top law enforcement official is taking on 23andMe for its botched handling of a massive data breach that exposed the sensitive genetic and personal info of nearly 7 million customers - including over 855,000 Californians. The lawsuit claims the company's lax security and software quality allowed hackers to get away with highly sensitive data.

Analyst 207
Genetic testing lab with equipment and blurred DNA data on a computer screen.

California Sues 23andMe Over Data Breach Security Failings

California's top lawyer, Rob Bonta, is taking on 23andMe for allegedly failing to protect millions of people's sensitive genetic data and downplaying the severity of a massive 2023 data breach. The lawsuit claims the company broke California law by not keeping personal info safe and lying to customers about the breach.

Analyst 207
Automation symbol superimposed over network equipment and cables.

LLM Agent Enables Rapid Post-Exploitation in Marimo Networks

On May 10, 2026, a savvy attacker used a large language model agent to rapidly exploit a vulnerable Marimo instance, leveraging CVE-2026-39987 to spark a swift and damaging breach. This critical vulnerability allowed the attacker to execute arbitrary system commands, paving the way for cloud credential theft and further malicious activity.

Analyst 207
Dutch police officials stand in front of rows of computer servers and networking equipment in a brightly-lit server room.

Dutch Authorities Disrupt Massive Botnet of 17 Million Devices

In a major cybercrime crackdown, Dutch authorities have successfully dismantled a massive botnet comprising 17 million infected devices, seizing over 200 servers used to host its infrastructure. This significant takedown was made possible through a collaborative effort between the Police and the National Cyber Security Centre (NCSC).

Analyst 207
Dimly lit server room with brightly lit devices in the foreground.

Dutch Police Disrupt Mystery Botnet, Seize 17M Devices

Dutch police have successfully dismantled a massive mystery botnet, freeing a staggering 17 million devices from its control. This significant disruption was made possible by tracing around 200 servers to the Netherlands and having the hosting provider shut them down.

Analyst 207
Person in fake IT uniform stands near reception desk in corporate office.

Silent Ransom Group Escalates Tactics with In-Person IT Impersonation

The FBI warns that the notorious Silent Ransom Group is taking a more aggressive approach, impersonating IT staff in person to infiltrate corporate systems, targeting US law firms, insurance, finance, and healthcare companies since 2023. This new tactic marks a significant escalation from their previous remote trickery methods.

Analyst 207
Dimly lit Ukrainian government office with laptop showing chatbot interface on screen.

Russia-linked Group Leverages ChatGPT in Cyberattacks on Ukraine

Meet GREYVIBE, a Russia-linked cyber group that's taking its attacks on Ukraine to the next level with the help of AI tools like ChatGPT, targeting the country's military and government. This sinister crew is leveraging cutting-edge tech to supercharge its cyberattacks.

Analyst 207
Laptop on a cluttered wooden desk in a small Ukrainian office with blurred screen.

Russia-Linked GREYVIBE Exploits AI in Ukraine Cyberattacks

Discover how the Russia-linked group GREYVIBE is using AI to launch sophisticated cyberattacks on Ukraine, leveraging tactics like spear-phishing emails and fake websites to spread malware. WithSecure researchers have tracked GREYVIBE's activities back to August 2025, revealing a pattern of attacks targeting Ukraine's military, government, and civilian sectors.

Analyst 207
Laptop on a desk with a browser window open, hinting at a security threat.

ChatGPT Exposes Users to Prompt Injection Attacks via Browser Content

Researchers have uncovered a vulnerability in ChatGPT that leaves users open to prompt injection attacks, where malicious content is embedded into web pages and then summarized by the AI system as legitimate information. This loophole could put users at risk of falling prey to spoofed security alerts and other online threats.

Analyst 207
Retail setting with subtle tech hints, blurred customer service area.

ShinyHunters Breaches Charter, Exposes 4.9M Customer Records

A massive data breach at Charter has exposed a whopping 4.9 million customer records, with hackers from the notorious ShinyHunters group proudly adding the telco to their "trophy shelf" and making sensitive info like names, addresses, and phone numbers publicly available. Charter has downplayed the incident, claiming no sensitive data was taken, but the reality is that millions of customers are now at risk.

Analyst 207
Dimly lit server room with rows of computer servers and storage equipment, some screens displaying abstract interfaces.

Shadow AI Exposes 2,000 Vibe-Coded Apps with Sensitive Data

A shocking discovery by Red Access revealed over 2,000 apps with sensitive corporate, operational, or personal data exposed online, leaving countless organizations vulnerable to risk. These apps, found on popular vibe-coding platforms, were often deployed without basic security controls, granting open access to sensitive information.

Analyst 207
Elderly man stands somberly in front of a nondescript government building backdrop.

Elder Data Trafficker Draws 10-Year Sentence

A massive data scam that compromised the personal info of over 7 million elderly Americans has landed its mastermind, 57-year-old Troy Murray, a 10-year prison sentence - a major victory in the fight against these heartless crimes. Murray, who went by the alias "Steve Dixon," was found guilty of running a scheme that sold sensitive data, including names, phone numbers, and addresses, to overseas scammers.

Analyst 207
Cluttered developer's workstation with coding interface on screen.

Malicious NuGet Package Exfiltrates Sicoob Banking Credentials

A malicious NuGet package, masquerading as a C# SDK for a major Brazilian financial system, was designed to steal sensitive banking credentials, including client IDs, PFX passwords, and certificate bytes, from unsuspecting developers. This rogue package, downloaded nearly 500 times, put automation and security at risk.

Analyst 207
Workers inspect a shipping container at a busy Gulf port with cargo ships and cranes in the background.

Chinese Hackers Exploit Middle East War to Target Energy, Maritime Firms

Chinese-aligned hackers are intensifying their attacks on maritime and energy companies in the Gulf region, exploiting the Middle East conflict to expand their espionage operations and gain a strategic advantage for Beijing. This alarming surge in cyber threats has been flagged by cybersecurity researchers at ESET.

Analyst 207
Concerned customer surrounded by paperwork and communication equipment.

Charter Communications Breach Exposes 4.9 Million Accounts

A shocking data breach at Charter Communications has left 4.9 million customer accounts vulnerable, with hackers gaining access to sensitive information including names, email addresses, phone numbers, and physical addresses. The breach occurred after a clever voice phishing attack on April 1 allowed cybercriminals to tap into the company's Salesforce database.

Analyst 207
Cluttered computer terminal room with cables and equipment, laptop in center, faint GitHub logo on blurred screen.

AI-Generated Malware Exposes Operator's GitHub Token

A malicious npm package, disguised as a harmless sync utility called "mouse5212-super-formatter", was downloaded 676 times before it was caught stealing sensitive data and exposing its creator's GitHub token. This AI-generated malware cleverly hid its true intentions, uploading stolen files to a fake repository and covering its tracks.

Analyst 207
Laptop screen on cluttered office desk with subtle hint of fake installation page.

Kimsuky Expands Malware Arsenal with HTTPSpy, HelloDoor

Kimsuky, a notorious North Korean hacking group, has upgraded its malware arsenal with HTTPSpy and HelloDoor, using clever tactics like fake installation pages and a spoofed Webex meeting to infiltrate targets. The group's latest attacks involve highly tailored social engineering and real-time infection verification to maximize success.

Analyst 207
Dimly lit home entertainment room with laptop surrounded by pirated media items.

Cybercrime Gang Targets Fans with Miner Malware via Pirated Media Sites

Millions of fans are unwittingly getting hacked when they visit popular pirated media sites, with a staggering 40 million visits to infected sites in April alone. A sneaky malware campaign is using fake video player updates to infect devices with cryptomining and remote-access malware.

Analyst 207
Empty office interior with a single open laptop on a desk.

GreyVibe hackers wield AI tools to fuel multi-sector cyberattacks

Meet GreyVibe, a likely Russian threat group that's been wreaking havoc across multiple sectors in Ukraine since at least August 2025, using AI-generated social engineering and custom malware to fuel its attacks. WithSecure researchers uncovered the group's activities, revealing a surprisingly unsophisticated approach despite its use of advanced AI tools like ChatGPT and Google Gemini.

Analyst 207
Researcher's workstation with laptop, notes, and papers, overlooking office building.

Microsoft Faces Backlash Over Zero-Day Disclosure Feud

A researcher known as Nightmare Eclipse has unleashed a series of six Windows zero-day vulnerabilities, with working exploit code for at least three, and has threatened to release another on July 14, sparking a public feud with Microsoft. The ominous warning, which has left Microsoft speaking out against uncoordinated disclosures, has security experts on high alert.

Analyst 207