Skip to main content

Emerging Threats

Brightly-lit workspace with Jenkins server and plugin on computer screen.

Checkmarx Disrupts TeamPCP Intrusion via Sabotaged Jenkins Plugin

Checkmarx sprang into action to stop a TeamPCP intrusion after a Jenkins plugin was sabotaged, ruining engineers' weekend plans with a Saturday attack. The swift response thwarted another attempted breach by the same cyber actor.

Analyst 207
Students and faculty walk down a brightly-lit school hallway, with a laptop on a desk in the foreground.

ShinyHunters Targets Education Sector with School-by-School Ransom Push

ShinyHunters has launched a targeted ransom attack on the education sector, exploiting a vulnerability in Canvas Learning Management System to steal a staggering 275 million records from nearly 9,000 schools and universities. The timing couldn't be more critical, with exams already underway and academic years wrapping up.

Analyst 207
Zara store interior with sales counter and laptop, under bright daylight.

ShinyHunters Breach Exposes 200,000 Zara Customers

A massive data breach at fashion giant Zara has exposed the sensitive information of over 197,000 customers, including email addresses, order details, and support ticket info, after a hacking group called ShinyHunters gained unauthorized access to the company's systems. The breach was quickly contained, with parent company Inditex alerting authorities and assuring customers that no names, passwords, or payment details were compromised.

Analyst 207
Dimly lit smartphone screen on a cluttered nightstand shows a faint, abstract pattern, with a cityscape at dusk visible…

TrickMo Malware Adopts TON Blockchain for Covert Command-and-Control

Meet Trickmo.C, a sneaky new variant of the TrickMo Android banker that's been hiding in plain sight as a TikTok or streaming app, targeting unsuspecting users in France, Italy, and Austria since January. This cunning malware has evolved to use the TON blockchain for covert command-and-control, making traditional domain takedowns a thing of the past.

Analyst 207
Laptop, smartphone, and notebook arranged on a desk in a tidy workspace.

Malicious Repo Exploits OpenAI Model to Deliver Info Stealer

A malicious repository disguised as OpenAI's legitimate Privacy Filter model racked up 244,000 downloads and became the #1 trending project on Hugging Face, but actually hid a sneaky Rust-based information stealer targeting Windows machines. The fake repository, Open-OSS/privacy-filter, expertly impersonated OpenAI's release, even copying the official model card to gain users' trust.

Analyst 207
Mac laptop on a desk with a Terminal window open, in a blurred office setting.

Hackers Exploit Google Ads, AI Chats to Spread Mac Malware

Malicious hackers are exploiting Google ads and AI chat platforms to trick Mac users into downloading malware, using a sneaky tactic that involves fake installation guides and Terminal commands. Clicking on what seems to be a legitimate ad can lead to a malware-ridden surprise, thanks to a vulnerability in Claude's shared-chat feature.

Analyst 207
Server room with rows of equipment and a single server in the foreground, GGUF file on nearby surface.

Ollama Vulnerability Exposes Servers to Remote Memory Leak

A newly discovered vulnerability in Ollama, dubbed "Bleeding Llama," exposes over 300,000 servers worldwide to a severe remote memory leak, with a CVSS score of 9.1. This critical flaw, tracked as CVE-2026-7482, allows attackers to exploit a weakness in the GGUF model loader.

Analyst 207
Laptop screen displays compromised website in home office setting.

JDownloader Site Compromised to Spread Python RAT Malware

A Reddit user recently raised the alarm after Microsoft Defender flagged a JDownloader download on their new PC, uncovering a sinister plot to spread Python RAT malware through the popular download manager's compromised website. The JDownloader site was hacked between May 6-7, 2026, allowing attackers to swap legitimate downloads with malicious payloads.

Analyst 207
Cluttered home office workstation with laptop displaying coding interface.

Malicious Hugging Face repository targets Windows users with infostealer malware

Malicious actors on Hugging Face tricked Windows users into downloading infostealer malware by creating a fake repository that mimicked OpenAI's popular Privacy Filter release. The rogue repository briefly shot to the top of Hugging Face's trending list, racking up 244,000 downloads before being swiftly removed.

Analyst 207
Brightly-lit school hallway with laptops on desks, hinting at technology integration.

ShinyHunters Breach Exposes 9,000 Schools in Canvas Hack

A massive data breach has hit Canvas, a popular learning management system, with hackers claiming to have stolen several terabytes of sensitive data, including personal info for 275 million users, from 9,000 schools. The notorious ShinyHunters group is now demanding action, threatening to leak everything if their demands aren't met.

Analyst 207
Concerned students in a college computer lab check phones and laptops, with a login page hinting at a ransom message in the…

ShinyHunters Breach Disrupts Canvas Education Platform Nationwide

A massive cyberattack by ShinyHunters has disrupted the Canvas Education Platform nationwide, with hackers defacing login pages and holding sensitive data on 275 million students and faculty hostage. The breach forced Instructure to pull Canvas offline, leaving students and faculty in the dark.

Analyst 207
Government building with podium and state emblem, foreground shows blurred computer screen, suggesting official…

Missouri Probes Conduent's Response to Massive Data Breach

Missouri's Department of Commerce and Insurance is stepping up its investigation into Conduent's massive data breach, which is believed to have affected over 25 million people, after the company failed to provide crucial information on the breach's impact. The state agency is urging insurers to come forward with details on their dealings with Conduent, citing significant consumer risk.

Analyst 207
Municipal water utility control room with industrial equipment and infrastructure.

AI Tools Facilitate but Fail to Deliver in Water System Hack Attempt

In a recent cyber attack on nine Mexican government entities, hackers surprisingly used AI tools like Claude and Chat GPT to help breach the systems, but ultimately failed to cause significant harm. The attack, which included a January intrusion into a municipal water and sewage utility, revealed that while AI can facilitate malicious activity, it can't guarantee success.

Analyst 207
Rows of servers and storage systems in a neutral, institutional data center with a single figure in the foreground.

AI-Driven Attacks Infiltrate Cloud Environments, Exposing Hidden Risks

New AI-driven threats are rapidly exploiting cloud security gaps, making it vital for teams to adopt a proactive, holistic approach to risk reduction to safeguard critical assets and data. Stay ahead of adversaries by understanding how they're weaponizing cloud vulnerabilities at alarming speed.

Analyst 207
Brazilian bank interior with customers and staff, smartphone in foreground.

TCLBANKER Trojan Targets Brazil's Financial Sector via WhatsApp Worms

A new Brazilian banking trojan, dubbed TCLBANKER, is targeting the country's financial sector via WhatsApp worms, marking a significant evolution in the threat landscape. This malware can compromise 59 banking, fintech, and cryptocurrency platforms, making it a major player in the region.

Analyst 207
A clean and minimalist computer workstation with a laptop on a plain desk, surrounded by generic technical equipment.

Linux Flaw Exposes Root Access Risk

A newly discovered Linux kernel flaw, nicknamed Dirty Frag, poses a serious risk of root access to major Linux distributions, allowing attackers to exploit vulnerabilities and gain control. Security researcher Hyunwoo Kim found the flaw, which can be chained with other vulnerabilities to obtain root privileges.

Analyst 207
Blurred laptop screen surrounded by scattered educational materials on a university campus.

Ransomware Group ShinyHunters Targets Canvas E-Learning Platform

A massive ransomware attack has hit Canvas, a popular e-learning platform used by over 30 million users, with hackers claiming to have compromised a staggering 275 million individuals' data. The breach, attributed to the notorious ShinyHunters group, forced the platform's developer, Instructure, to take Canvas offline temporarily.

Analyst 207
Dimly lit network closet with disarrayed cables and equipment.

Malware Worm Eliminates Rival, Seizes Control

Meet the malware worm with a ruthless streak - it not only eliminates rival malware from infected systems, but also seizes control and claims the compromised credentials for itself. This cunning worm is taking over, leaving other malicious operators with nothing.

Analyst 207
Smartphone with blurred Google Play Store page on screen, surrounded by receipts on a neutral surface in a bright, everyday…

Fraudulent Call History Apps Drain Millions via 7.3M Play Store Downloads

Millions of Android users have been duped into downloading 28 fake call history apps from the Google Play Store, with over 7.3 million downloads recorded before they were finally removed. These apps, which promised access to call logs and more, actually delivered nothing but randomly generated data - and a hefty price tag.

Analyst 207
Cluttered computer workstation in a small office with a blurred laptop screen.

NVIDIA Discloses GeForce NOW Breach Affecting Armenian Users

NVIDIA recently discovered a security breach affecting users of GeForce NOW in Armenia, which was caused by a compromised system operated by a third-party partner, not by NVIDIA's own network. The company is working closely with the partner to resolve the issue and notify affected users.

Analyst 207
Dimly lit industrial control system with blank, softly glowing screen in a data center setting.

Linux Flaw Exposes Public Root Exploit With No Patches

A critical Linux vulnerability known as Dirty Frag has been exposed, leaving systems open to a public root exploit with no patches or fix available. This high-urgency flaw allows hackers to gain root access, making it essential for admins to take immediate action.

Analyst 207
Rows of computer servers with flickering screens and dimmed lights suggest a breach or disruption in a technology company's…

RansomHouse Hackers Claim Breach of Trellix Source Code

Trellix has confirmed a breach of its source code repository, with hackers from the notorious RansomHouse group claiming to have accessed and encrypted sensitive data on April 17. The group has even posted leaked screenshots to back up its claims.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center.

Data Breaches Surge, Exposing Sensitive Info at AI Startups, Agencies

Data breaches are surging, with AI startups and agencies exposed, as seen in the alarming theft of 10 petabytes from a Chinese supercomputer and 4 terabytes from AI startup Mercor due to a supply-chain vulnerability. These incidents highlight the hidden risks of connecting data to AI models, creating sensitive blind spots that leave large data sets vulnerable to compromise.

Analyst 207
Rows of equipment racks and patch panels in a brightly-lit server room or network closet.

CISA Mandates Patching of Ivanti Flaw Exploited in Zero-Day Attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) is requiring immediate patching of a high-risk Ivanti flaw, CVE-2026-6973, that allows attackers with admin privileges to remotely execute code on vulnerable systems. This critical vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) version 12.8.0.0 and earlier.

Analyst 207