Skip to main content

Emerging Threats

Developer workstation with laptop, monitor, and office supplies in a neutral background.

GitHub Breach Exposes 3800 Internal Repositories to Malicious VS Code Extension

GitHub's security team swiftly contained a breach that exposed 3,800 internal repositories to a malicious VS Code extension, and immediately took action to prevent further damage. The company has completed critical secret rotations and is now meticulously analyzing logs to ensure the incident is fully resolved.

Analyst 207
Concerned office worker holding smartphone with tense face and body language.

Barracuda Warns of CypherLoc Scareware Targeting Millions

Millions of users are under attack by the CypherLoc scareware, with Barracuda researchers tracking around 2.8 million attacks since January 2026 alone. This staggering number reveals a coordinated and widespread campaign that's putting tens of millions of people at risk.

Analyst 207
Developer workstation with laptop, monitor, and coding tools in a modern office space.

GitHub Breach Exposes 3,800 Repos via Malicious VSCode Extension

GitHub recently uncovered a sneaky attack involving a tainted VS Code extension that compromised an employee's device, putting 3,800 repositories at risk. The breach was quickly contained, but not before some internal repositories were exfiltrated.

Analyst 207
Laptop screen displays GitHub repository page on a clean workspace surface.

Grafana GitHub Breach Exposes Source Code in TanStack npm Attack

Grafana Labs recently reported a security breach that exposed source code and internal data, but fortunately, there's no evidence that customer production systems were compromised. The breach, detected on May 11, was confined to the company's GitHub environment and involved both public and private source code and internal repositories.

Analyst 207
Blurred office scene with employees working, a faintly glowing laptop in the foreground.

GitHub Probes Internal Breach Claimed by TeamPCP Hackers

GitHub is investigating a possible internal breach after a hacking group claimed unauthorized access to its repositories. The company says it has no evidence that customer data has been compromised so far.

Analyst 207
Brightly-lit tech office interior with employees at desks and a large window in the background.

GitHub Probes Breach Claim by TeamPCP Hackers

GitHub is investigating a security breach claim by hackers TeamPCP, who allegedly stole around 4,000 of the platform's internal repositories and put the source code up for sale for a hefty $50,000. The company has already sprung into action, detecting and containing the breach and taking steps to mitigate the risk.

Analyst 207
Disorganized cables and patch cords in a network operations room with rows of computer servers and monitoring screens.

Exploits Emerge as Top Breach Entry Point

With attackers exploiting vulnerabilities at an alarming rate, it's clear that organizations are struggling to keep up with the pace of security defects - and it's leaving them exposed. Exploits have now become the top breach entry point, accounting for 31% of all known initial access vectors.

Analyst 207
Blurred code on a laptop screen in a brightly-lit workspace with a coding environment in the background.

CISA Credentials Exposed in GitHub Leak

A security researcher has uncovered a public GitHub repository exposing sensitive credentials tied to the Cybersecurity and Infrastructure Security Agency, sparking fears that malicious actors could exploit the data for nefarious purposes. The leak, linked to a contractor-maintained repository called "Private-CISA," reportedly included privileged AWS GovCloud accounts and internal CISA systems.

Analyst 207
Person holding smartphone surrounded by fake software update prompts and alerts.

Malicious Android Apps Fuel 659M Daily Ad Fraud Bid Requests

Meet Trapdoor, a massive ad fraud scam driven by 455 malicious Android apps that generated a whopping 659 million daily bid requests at its peak, all while hiding in plain sight as harmless utilities like PDF viewers and file managers. These fake apps tricked users into installing malware, unleashing a hidden ad fraud operation controlled by 183 threat actor-owned domains.

Analyst 207
Rows of computer servers and equipment in a well-lit server room or data center.

ChromaDB Flaw Enables Server Hijacking via AI Model Exploit

A newly discovered vulnerability, CVE-2026-45829, in ChromaDB's Python FastAPI variant allows hackers to hijack servers by exploiting AI models, with a security expert noting that authentication is present but poorly placed. This flaw lets unauthenticated attackers run arbitrary code on exposed servers by cleverly manipulating API endpoints.

Analyst 207
Hospital corridor with patients and staff, laptop screen in foreground, conveying concern.

NYC Health Breach Exposes 1.8M Patients' Sensitive Data

A massive data breach at NYC Health + Hospitals has exposed the sensitive information of 1.8 million patients, highlighting the alarming vulnerability of personal data in the healthcare system. This incident serves as a stark reminder of the devastating consequences of a breach, especially when it comes to biometric data that can never be truly reset.

Analyst 207
Law enforcement officials in a secure facility render code-signing credentials invalid.

Microsoft Disrupts Cybercrime Service Selling Code-Signing Certificates to Ransomware Gangs

Microsoft has disrupted a notorious cybercrime operation, dubbed Fox Tempest, that sold code-signing certificates to ransomware gangs, allowing them to disguise malware as legitimate Windows software. The operation, which created over 580 fake Microsoft accounts, has been linked to two individuals, John Doe 1 and John Doe 2, who allegedly traded in real, Microsoft-issued code-signing credentials.

Analyst 207
Brightly-lit server rack in a cybersecurity operations center against a mid-tone background.

Microsoft Disrupts Malware-Signing Service Used by Ransomware Gangs

Microsoft cracked down on a notorious malware-signing service used by ransomware gangs, disrupting the operations of Fox Tempest, a financially motivated group that generated millions of dollars in profits by selling trust to cybercriminals. The group had created over 1,000 code-signing certificates and hundreds of Azure tenants to support its industrial-scale scheme.

Analyst 207
Cryptocurrency kiosk in a public place with a blank screen.

FBI Warns of $388 Million Lost to Crypto ATM Scams

The FBI's Internet Crime Complaint Center received over 13,400 complaints about crypto ATM scams in 2025, with victims losing a staggering $388 million - a 58% jump in losses from the previous year. This alarming trend is part of a broader surge in cybercrime, with over 1 million complaints filed and nearly $21 billion in losses reported last year.

Analyst 207
Brightly lit computer workstation with Microsoft interface and cityscape background.

Microsoft Abuses Self-Service Password Reset in Azure Data Theft Attacks

Microsoft warns that hackers are using clever social engineering tactics and exploiting self-service password reset features to drain sensitive data from high-value Azure assets. By tricking users into approving multi-factor authentication prompts, attackers can gain access to production Microsoft 365 and Azure environments.

Analyst 207
7-Eleven store interior with customers shopping and a franchisee near a filing cabinet.

7-Eleven Breach Exposes Franchisee Data to Cyber Risk

A recent 7-Eleven data breach has put franchisee information at risk, with sensitive documents accessed by an unauthorized party, potentially exposing names, addresses, and other personal data. Fortunately, customers who used their credit cards to make purchases can breathe a sigh of relief, as their payment info appears to be safe.

Analyst 207
Laptop screen displays GitHub repository in a bright, minimalist workspace.

CISA Exposes Security Lapse with Open GitHub Repository

The US's leading cyber-defense agency, CISA, made a shocking security blunder by leaving a GitHub repository open, exposing sensitive passwords, keys, and tokens with alarmingly obvious filenames. This careless mistake raises serious concerns about the agency's ability to protect itself and the nation from cyber threats.

Analyst 207
Smartphone lies on a park bench surrounded by scattered papers and app icons, with a city street in the background.

Trapdoor Android Ad Fraud Scheme Exposes 455 Malicious Apps

Meet Trapdoor, a massive Android ad fraud scheme that used 455 malicious apps to generate a staggering 659 million daily bid requests, fueling a self-sustaining machine that turned innocent installs into big bucks. This complex operation was uncovered by HUMAN's Satori Threat Intelligence and Research Team, shedding light on a pipeline for multi-stage fraud.

Analyst 207
Law enforcement operation room with a large, dismantled computer setup symbolizing disrupted malware signing service.

Microsoft Disrupts Malware Signing Service Used by Ransomware Groups

Microsoft cracked down on a sophisticated malware signing service run by a group called Fox Tempest, which helped ransomware gangs disguise their malicious programs as legitimate software. This service was like a master forgery operation, creating counterfeit digital signatures that even experts struggled to spot.

Analyst 207
Brightly-lit coding workstation with laptop, notes, and software materials scattered around.

Malware Campaign Compromises Hundreds of npm Packages

A new, highly aggressive malware campaign, linked to the notorious TeamPCP group, has infected hundreds of npm packages, putting countless environments at risk of exposure. If you're concerned about potential damage, take immediate action to rotate secrets, remove persistence artifacts, and review recent publish activity.

Analyst 207
Brightly-lit courthouse conveys sense of institutional action and cyber enforcement.

Microsoft Disrupts Fox Tempest's Ransomware-Enabling Code-Signing Service

Microsoft's Digital Crimes Unit has successfully disrupted a notorious code-signing service used by cybercriminals, including the group behind Fox Tempest, to create fake IDs and gain easy access to systems. This operation has effectively shut down a key tool used by hackers to spread ransomware and malware.

Analyst 207
Concerned 7-Eleven employee or franchisee looks at document near blurred POS terminal.

7-Eleven Breach Exposes Franchisee Data After ShinyHunters Attack

7-Eleven recently confirmed a data breach that exposed sensitive franchisee information after a cyberattack by the group ShinyHunters, with unauthorized access detected on April 8. The company swiftly launched an investigation and began notifying affected individuals on May 1.

Analyst 207
Coding environment with lines of code on screen, surrounded by notes and diagrams.

Shai-Hulud Malware Targets 600 Npm Packages in Supply-Chain Attack

In a shocking supply-chain attack, malicious Shai-Hulud malware targeted a staggering 600 npm packages, with researchers uncovering nearly 640 tainted versions across 323 unique libraries in just one hour. The assault hit popular ecosystems like @antv and spread to widely-used packages, leaving a trail of poisoned code in its wake.

Analyst 207
Windows desktop with MSHTA process active, surrounded by blurred office equipment.

Microsoft Utility MSHTA Fuels Malware Surge via Lumma Stealer Campaigns

Malware campaigns are on the rise, fueled by the Microsoft Utility MSHTA, which is being exploited to spread info stealers like Lumma Stealer and Amatera. This sneaky tactic is just the latest example of how cybercriminals are abusing a long-standing Windows feature to wreak havoc.

Analyst 207