Skip to main content

Emerging Threats

Technicians work in a network operations center with a prominent server in the foreground.

Vulnerability Exploitation Surges in Data Breaches

Vulnerability exploitation is now the top attack vector, responsible for a staggering one-third of all data breaches. This alarming trend highlights the urgent need for robust patch management and cybersecurity measures to stay ahead of threats.

Analyst 207
Person sitting at laptop with unease, surrounded by office environment.

OAuth Grants Expose Hidden Risk Below MFA Perimeter

In just five weeks, a phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organizations across five countries by exploiting a clever trick: instead of stealing passwords, it convinced users to hand over OAuth refresh tokens, granting attackers long-term access to sensitive data like mailboxes, drives, and calendars. This sneaky tactic allowed hackers to bypass traditional security measures, including multi-factor authentication.

Analyst 207
Laptop screen displays blurred code in a coding environment on a plain surface with papers and a notebook nearby.

Grafana Labs Discloses Source Code Theft by Hackers

Hackers recently breached Grafana Labs' security, gaining unauthorized access to a GitHub token that allowed them to download the company's source code, and subsequently attempting to extort payment to keep it under wraps. The incident was swiftly investigated, and the compromised token was promptly invalidated.

Analyst 207
Mobile app development environment with smartphone on cluttered desk and cityscape in background.

Agentic AI Turbo Boosts Mobile App Attacks

The alarming rise of mobile app attacks is no longer looming on the horizon - it's here, with a staggering 87% of monitored apps facing threats in 2026, a drastic jump from 55% in 2022, fueled by the rapid adoption of AI models. This explosive growth in attacks is a wake-up call for businesses to bolster their mobile app security.

Analyst 207
Code editor interface with open plugin panel, generic computer screen and daylight in background.

Nx Console Extension Exploited to Steal Developer Credentials

A malicious version of the popular Nx Console Extension was published to the VS Code Marketplace, compromising over 2.2 million installations and putting developer credentials at risk. Within seconds of opening a workspace, the extension silently fetched and executed a hidden payload, allowing attackers to steal sensitive information.

Analyst 207
Person sitting at desk with concerned expression, staring at blank laptop screen.

Hackers Exploit Human Behavior to Bypass Security Tools

As cyber threats evolve at an alarming rate, hackers are exploiting human behavior to outsmart security tools, forcing organizations to rethink their defensive strategies. With identity abuse and data extortion on the rise, businesses must stay ahead of the game to protect themselves.

Analyst 207
Software development workspace with a computer screen displaying a blurred graph, surrounded by cables and development tools.

Mini Shai-Hulud Campaign Targets npm Ecosystem with Malicious AntV Packages

A large-scale attack has infected hundreds of popular npm packages, including widely-used data visualization and React components, with malicious updates, putting a vast number of projects and applications at risk. The attackers published 639 malicious versions across 323 unique packages in a fast-moving supply chain operation.

Analyst 207
Blurred computer terminal surrounded by development notes and empty coffee cups in a brightly-lit coding environment.

GitHub Actions Supply Chain Attack Exfiltrates CI/CD Credentials

A sneaky supply chain attack on GitHub Actions has led to the theft of CI/CD credentials, with hackers using a clever trick to redirect tags to fake commits that hide malicious code. By masquerading as legitimate commits, attackers were able to execute arbitrary code and evade pull request reviews.

Analyst 207
Seized computer equipment on a table in a law enforcement facility.

Interpol Disrupts Cybercrime Ops Across 13 Countries

In a major win against cybercrime, Interpol's Operation Ramz has resulted in 201 arrests, 53 servers seized, and nearly 4,000 victims identified across 13 countries in the Middle East and North Africa. This groundbreaking four-month sweep marks a significant milestone in the fight against online crime.

Analyst 207
Empty computer workstation with laptop and papers in a neutral office setting, hint of coding workspace in background.

CISA Contractor Exposes AWS GovCloud Keys in GitHub Leak

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) made a critical mistake by exposing sensitive AWS GovCloud keys, plaintext passwords, and internal files in a public GitHub repository. The leak, described as one of the worst ever witnessed, included highly privileged credentials and build artifacts for numerous internal CISA systems.

Analyst 207
Laptop on a clean workspace with a USB drive nearby, screen displaying nothing.

BitLocker Vulnerability Exposed in Zero-Day Windows Exploit

A newly discovered zero-day exploit, dubbed YellowKey, can bypass Windows 11's standard BitLocker encryption - but don't panic, as it requires physical access to the computer. This vulnerability was recently published by a researcher known as Nightmare-Eclipse on GitHub.

Analyst 207
Dimly lit Apple laptop on cluttered desk with crypto wallet and password notes nearby, hint of backdoor vulnerability in…

Reaper Stealer Targets macOS Users with Password, Wallet Theft and Backdoor Attacks

macOS users beware: Reaper Stealer malware is on the loose, stealing passwords, crypto-wallets, and installing backdoors on infected machines. This triple-threat attack puts Apple platform users and their defenders on high alert.

Analyst 207
Law enforcement officers in uniform gather around a table and map of the Middle East and North Africa, discussing and…

INTERPOL Disrupts Cybercrime Networks with 'Operation Ramz' Arrests

In a major crackdown on cybercrime, INTERPOL's Operation Ramz has led to over 200 arrests and identified 382 suspects across 13 countries in the Middle East and North Africa, disrupting phishing, malware, and online fraud networks that cost the region dearly. The operation resulted in the seizure of 53 servers and uncovered nearly 8,000 intelligence packages linked to over 3,800 victims.

Analyst 207
Developer workstation in shared office with laptop and large monitor displaying signs of GitHub Actions shared-cache…

Shai-Hulud worm infects another npm package

A copycat of the notorious Shai-Hulud worm has struck again, infecting another npm package by exploiting a GitHub Actions misconfiguration. This latest attack follows a similar pattern that recently prompted TanStack to rethink its approach to accepting outside code contributions.

Analyst 207
Cluttered home office desk with Mac laptop showing AppleScript code and fake app installer in background.

SHub Infostealer Variant Reaper Exploits macOS Security Updates

Researchers at SentinelOne have uncovered a sneaky new variant of the SHub macOS infostealer, called Reaper, which cleverly bypasses Apple's latest security updates by using a malicious AppleScript to trick users. This crafty malware uses fake installers to lure victims in, making it a serious threat to macOS users.

Analyst 207
Law enforcement officers gather around a conference table with a large MENA map on the wall.

INTERPOL Disrupts MENA Cybercrime Networks with 201 Arrests

In a major crackdown on cybercrime, INTERPOL's Operation Ramz has led to 201 arrests and identified 382 more suspects across 13 countries in the Middle East and North Africa. The operation, which ran from October 2025 to February 2026, dealt a significant blow to malicious cyber networks, also seizing 53 servers and helping 3,867 victims.

Analyst 207
Blurred computer screen amidst software development environment with hint of unease.

Shai-Hulud Malware Fuels npm Infostealer Campaign

Malicious actors have unleashed a new wave of chaos with the Shai-Hulud malware, using typosquatting tactics to spread four malicious npm packages that can steal sensitive info and wreak havoc on systems. The packages, published under the account deadcode09284814, masquerade as legitimate tools, but are actually designed to siphon off credentials, cloud configs, and more.

Analyst 207
A dimly lit, disrupted computer server room with rows of equipment racks and monitors, some server casings and cables…

Ransomware Attacks Surge as Clop Gang Dominates Threat Landscape

Ransomware attacks have skyrocketed, with over 343 million blocked by Kaspersky products in just the first quarter of 2026 alone, highlighting a surge in threats from the notorious Clop gang and other malicious players. This alarming trend underscores a quarter marked by intensified ransomware activity and rapidly evolving cyber threats.

Analyst 207
Person holds smartphone with blurred screen in crowded urban area.

Mobile Malware Attacks Drop, Banking Trojans Surge.

Mobile malware attacks may be on the decline, but banking Trojans are surging, with over 162,000 malicious packages detected in Q1 2026, putting your financial security at risk. Kaspersky's Q1 2026 report reveals a concerning shift in mobile threats, with 306,070 Android malware samples and 439 mobile ransomware Trojans also discovered.

Analyst 207
Brightly-lit computer lab with laptops and computers, hinting at disruption.

SaaS Breaches Expose Gaps in Enterprise Security Thinking

In a shocking display of vulnerability, ShinyHunters breached Instructure's Canvas platform not once, but twice in a single week, siphoning off a staggering 3.65 terabytes of data from 275 million users across 8,000 institutions. The brazen attacks left hundreds of schools reeling during final exams, forcing Canvas offline and lining the attackers' pockets with a ransom payment.

Analyst 207
Blurred office setting with computer workstation and file cabinet in background.

Ransomware Breach Exposes 123,000 at American Lending Center

A ransomware attack on American Lending Center compromised the personal data of 123,000 individuals after a threat actor infiltrated the company's internal network and accessed sensitive files. The breach was discovered nine months prior to notification, on July 27, 2025, but consumers weren't alerted until April 28, 2026.

Analyst 207
Server room with a prominent Microsoft Exchange Server setup under ordinary lighting.

Microsoft Exchange Servers Targeted in Active Exploitation

Microsoft has sounded the alarm on a critical vulnerability in on-premise Exchange Servers, known as CVE-2026-42897, that's currently being exploited by hackers - and the company is urging affected users to act fast. A temporary fix is in place, with a permanent patch on the way.

Analyst 207
Officials in formal attire gather in a briefing room, signaling a coordinated law enforcement effort.

MENA Region Launches Landmark Cybercrime Crackdown

In a groundbreaking move, the MENA region has launched a historic crackdown on cybercrime, resulting in the arrest of 201 individuals in a multi-month operation hailed as a first-of-its-kind success. This major milestone marks a significant victory in the fight against online crime.

Analyst 207
Developer workspace with laptop, terminal, and blurred background of software development area, featuring a subtle network…

TanStack Mulls Invitation-Only Pull Requests After Supply Chain Breach

The TanStack project is weighing a drastic measure to protect its code: switching to invitation-only pull requests, after a sneaky Shai-Hulud worm exploited a GitHub Actions misconfiguration to contaminate a shared cache. This supply chain breach has raised red flags about the integrity of downstream code.

Analyst 207