Skip to main content

Emerging Threats

Modern bank lobby with customer service desk and banking terminals.

Malware Campaigns Target Windows, Android Users in Global Finance Sector

Global finance sector faces a double threat as malware campaigns target Windows and Android users, with attackers using clever tactics like hiding in trusted traffic and selling mobile RATs as turnkey services. Two recent campaigns, one using Grandoreiro malware in Portugal, Spain, and Mexico, and another using a new BTMOB trojan in Brazil, highlight the evolving threat landscape.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room.

CrowdStrike dismantles Glassworm botnet targeting open-source supply chain

In a major win for cybersecurity, CrowdStrike has successfully dismantled the notorious Glassworm botnet, crippling its ability to target the open-source supply chain. By taking down four key servers, CrowdStrike has forced the attackers to regroup and rebuild, buying time for the industry to stay one step ahead.

Analyst 207
Office worker sits at desk with laptop and printer in background.

FortiGuard Labs Exposes Sophisticated Phishing Campaign Targeting Windows Users

Beware of a sneaky phishing campaign that's targeting Windows users with a multi-stage attack chain, starting with a seemingly harmless email attachment that unleashes a powerful malware. This stealthy threat uses clever tactics like process hollowing to inject malicious code into trusted Windows processes.

Analyst 207
Concerned office worker sits at desk, staring at paper or laptop screen with blurred cityscape in background.

FBI Warns Law Firms of In-Person Extortion Tactics by Silent Ransom Group

The FBI is sounding the alarm for US law firms, warning them of a growing threat from the Silent Ransom Group, which targets the legal industry for its highly sensitive data and uses in-person extortion tactics. This group has been linked to a string of incidents, and the FBI is urging law firms to be vigilant.

Analyst 207
Network operations center with large map display and staff working at computer terminals.

CrowdStrike and Google Disrupt Glassworm Botnet Infrastructure

In a major win for cybersecurity, a powerful collaboration between CrowdStrike, Google, and the Shadowserver Foundation successfully dismantled the Glassworm botnet by simultaneously taking down all four of its command-and-control channels. This bold move cut off the botnet's operators from infected devices, preventing further malicious activity.

Analyst 207
Tangled fiber optic cables in a data center, disrupted and severed.

Glassworm botnet disrupted by takedown of resilient C2 infrastructure

In a major win for cybersecurity, researchers from CrowdStrike, Google, and The Shadowserver Foundation have successfully disrupted the Glassworm botnet by dismantling its complex command-and-control infrastructure. This takedown cuts off the lifelines of the threat actors, halting their campaigns that had been ongoing since October 2025.

Analyst 207
Brightly-lit software development workspace with multiple workstations and monitors.

CrowdStrike Disrupts GlassWorm Malware's Global Supply Chain Attack Infrastructure

In a major win for cybersecurity, CrowdStrike teamed up with Google and the Shadowserver Foundation to dismantle the global infrastructure behind the GlassWorm malware attack, crippling its ability to issue commands or deliver new payloads to infected machines. This coordinated operation targeted and neutralized the malware's command-and-control channels, protecting software developers from further exploitation.

Analyst 207
Crowded stadium exterior at night with subtle shadows hinting at online threats.

Fraudsters Target World Cup Fans with 4300 Fake FIFA Domains

Scammers are gearing up to target FIFA World Cup fans with a massive network of over 4,300 fake domains, a recent analysis revealed. These fraudulent sites, linked to six distinct scams and four threat actors, are currently dormant but ready to be activated as the 2026 tournament approaches.

Analyst 207
Person in business casual clothes approaches a cubicle, blending in with office surroundings.

FBI Warns of In-Person Data Theft Attacks by Extortion Gang

The FBI has issued a warning about a sneaky new tactic used by the notorious Silent Ransom Group: showing up in person to steal sensitive data, after gaining trust through clever phishing and phone scams. This brazen approach combines remote access tricks with physical presence at victim sites, marking a chilling evolution in their extortion methods.

Analyst 207
Server room with rows of equipment, focusing on a single server screen displaying a plugin interface.

CISA Mandates Emergency Patch for Exploited cPanel Plugin Flaw

A critical vulnerability in the LiteSpeed cPanel plugin, known as CVE-2026-48172, is being actively exploited by remote attackers, allowing them to execute arbitrary scripts with root privileges. CISA has issued an emergency patch, giving affected users just four days to update and protect themselves.

Analyst 207
Dutch police officer stands outside residential home with hint of computer in background.

Dutch Police Apprehends Suspect in Ajax Football Club Hack

Dutch police have arrested a 35-year-old man from Buren for repeatedly hacking into Ajax football club's computer systems, granting himself unauthorized access. The suspect's identity and motives are still under investigation.

Analyst 207
Laptop screen displays chatbot interface with blurred office background and smartphone shows warning message.

Microsoft Warns of AI-Driven Cryptojacking Campaign Targeting High-Performance GPUs

Beware of a sneaky new cryptojacking scam that's using AI chatbots to trick you into downloading malicious software - hackers are now hiding in plain sight, serving up poisoned links in chatbot responses that seem like harmless software recommendations. This cunning tactic is a game-changer for cyber threats, making it even harder to spot danger online.

Analyst 207
Office worker's desk with laptop, purchase order, and suspicious files.

PureLogs Infostealer Exploits Purchase Order Phishing Lures

Beware of purchase order phishing scams that can deliver a powerful infostealer, capable of stealing sensitive credentials and cryptocurrency keys, via a simple yet cleverly disguised email with a malicious RAR attachment. Even security software can be fooled, as one campaign was only flagged as a threat after it was already sent.

Analyst 207
Server room with rows of equipment and a blurred laptop screen in the foreground.

Hackers Exploit KnowledgeDeliver Flaw to Install Web Shells

Hackers have exploited a critical flaw in KnowledgeDeliver, using it as a zero-day to sneakily install a powerful .NET web shell called Godzilla on vulnerable servers. This sneaky attack was made possible by a deserialization vulnerability, CVE-2026-5426, that allowed threat actors to execute code at the operating-system level.

Analyst 207
Rows of cubicles with employees working on computers surrounded by papers and office supplies near a large window.

Charter Breach Exposes Millions of Customer Records

Millions of customer records have been exposed in a shocking data breach at Charter Communications, with the company swiftly confirming the incident and assuring customers that sensitive personal info remains safe. The breach, reportedly involving 40 million records, has triggered a thorough investigation and cooperation with authorities.

Analyst 207
Sensitive documents labeled Confidential and Financial scattered on a table in a brightly-lit office setting.

MyPillow Targeted in Play Ransomware Attack

MyPillow has been hit by a ransomware attack, with hackers claiming to have stolen highly sensitive data including private documents, financial information, and employee details. The attackers are demanding a ransom and threatening to publish the stolen data unless paid.

Analyst 207
Close-up of computer circuit board with exposed casing revealing abstract malicious code in background.

MuddyWater Exploits DLL Side-Loading in Global Espionage Push

MuddyWater hackers have launched a massive global espionage campaign, infiltrating at least nine organizations across four continents by cleverly disguising malicious code as legitimate software. They used a sneaky trick called DLL side-loading to quietly steal credentials and browser data.

Analyst 207
Person's hand holds smartphone in brightly-lit urban setting with subtle hint of unease.

Chinese Phishing Services Shift to Live Credential Interception Tactics

Cyber attackers are now using live administration panels to interact with victims in real-time, capturing one-time passcodes and instantly bypassing multifactor authentication protections. This new tactic allows them to neutralize security measures and steal sensitive information more effectively.

Analyst 207
Government office interior with filing cabinets in background.

Lithuania's National Register Breached, 600,000 Entries Exposed

A massive data breach has hit Lithuania's national registers, exposing over 600,000 sensitive entries, including records of legal entities and real estate holdings. The breach has prompted swift action from authorities, who have restricted access and blocked suspected accounts to mitigate the damage.

Analyst 207
Smartphone on cluttered desk with login prompt on screen.

BTMOB Android RAT Exploits No-Code Tools in Global Phishing Campaigns

A single malicious download can put an entire company's sensitive data at risk, so it's crucial for corporate security teams to educate employees on the dangers of rogue apps.

Analyst 207
Person sitting at desk, confused, looking at smartphone with multiple push notifications.

MFA Prompt Bombing Exposes Weakness in Two-Factor Security

A shocking 2.8GB of data was stolen from Cisco after a clever attacker tricked an employee into approving a push-based MFA prompt, highlighting a disturbing vulnerability in two-factor security. This brazen hack, linked to the Yanluowang ransomware group, shows how attackers can exploit the very security measures meant to protect us.

Analyst 207
Concerned office worker examines laptop with blurred screen amidst office supplies and city view.

Iranian Hackers Deploy AI-Backed MiniFast Backdoor via Phishing and SEO Poisoning

Iranian hackers have escalated their cyber attacks, leveraging AI-powered tools to craft malware and targeting key sectors like aviation, defense, and telecommunications across the US, Europe, and the Middle East. Their sophisticated tactics, including phishing and SEO poisoning, have allowed them to spy on organizations with alarming speed and efficiency.

Analyst 207
US airport terminal with check-in counter and departure board, laptops and phone on counter.

Iran-Linked Hackers Target US Aviation with Sophisticated Phishing and SEO Poisoning

Meet Nimbus Manticore, an Iran-linked hacking group that's back with a vengeance, using clever phishing and SEO poisoning tactics to target the US aviation industry in a series of sophisticated attacks. Their latest campaign, which ran from February to April 2026, marked a significant expansion into aviation, defense, and telecommunications.

Analyst 207
7-Eleven store interior with disorganized papers near employee.

7-Eleven Data Breach Compromises 185,000 People's Personal Info

A recent 7-Eleven data breach has put the personal info of 185,000 people at risk, exposing sensitive details like names, addresses, birthdays, and phone numbers. The breach, which occurred on April 8, 2026, is still shrouded in mystery, with 7-Eleven only confirming that certain systems storing franchisee documents were compromised.

Analyst 207