Emerging Threats

Checkmarx Disrupts TeamPCP Intrusion via Sabotaged Jenkins Plugin
Checkmarx sprang into action to stop a TeamPCP intrusion after a Jenkins plugin was sabotaged, ruining engineers' weekend plans with a Saturday attack. The swift response thwarted another attempted breach by the same cyber actor.

ShinyHunters Targets Education Sector with School-by-School Ransom Push
ShinyHunters has launched a targeted ransom attack on the education sector, exploiting a vulnerability in Canvas Learning Management System to steal a staggering 275 million records from nearly 9,000 schools and universities. The timing couldn't be more critical, with exams already underway and academic years wrapping up.

ShinyHunters Breach Exposes 200,000 Zara Customers
A massive data breach at fashion giant Zara has exposed the sensitive information of over 197,000 customers, including email addresses, order details, and support ticket info, after a hacking group called ShinyHunters gained unauthorized access to the company's systems. The breach was quickly contained, with parent company Inditex alerting authorities and assuring customers that no names, passwords, or payment details were compromised.

TrickMo Malware Adopts TON Blockchain for Covert Command-and-Control
Meet Trickmo.C, a sneaky new variant of the TrickMo Android banker that's been hiding in plain sight as a TikTok or streaming app, targeting unsuspecting users in France, Italy, and Austria since January. This cunning malware has evolved to use the TON blockchain for covert command-and-control, making traditional domain takedowns a thing of the past.

Malicious Repo Exploits OpenAI Model to Deliver Info Stealer
A malicious repository disguised as OpenAI's legitimate Privacy Filter model racked up 244,000 downloads and became the #1 trending project on Hugging Face, but actually hid a sneaky Rust-based information stealer targeting Windows machines. The fake repository, Open-OSS/privacy-filter, expertly impersonated OpenAI's release, even copying the official model card to gain users' trust.

Hackers Exploit Google Ads, AI Chats to Spread Mac Malware
Malicious hackers are exploiting Google ads and AI chat platforms to trick Mac users into downloading malware, using a sneaky tactic that involves fake installation guides and Terminal commands. Clicking on what seems to be a legitimate ad can lead to a malware-ridden surprise, thanks to a vulnerability in Claude's shared-chat feature.

Ollama Vulnerability Exposes Servers to Remote Memory Leak
A newly discovered vulnerability in Ollama, dubbed "Bleeding Llama," exposes over 300,000 servers worldwide to a severe remote memory leak, with a CVSS score of 9.1. This critical flaw, tracked as CVE-2026-7482, allows attackers to exploit a weakness in the GGUF model loader.

JDownloader Site Compromised to Spread Python RAT Malware
A Reddit user recently raised the alarm after Microsoft Defender flagged a JDownloader download on their new PC, uncovering a sinister plot to spread Python RAT malware through the popular download manager's compromised website. The JDownloader site was hacked between May 6-7, 2026, allowing attackers to swap legitimate downloads with malicious payloads.

Malicious Hugging Face repository targets Windows users with infostealer malware
Malicious actors on Hugging Face tricked Windows users into downloading infostealer malware by creating a fake repository that mimicked OpenAI's popular Privacy Filter release. The rogue repository briefly shot to the top of Hugging Face's trending list, racking up 244,000 downloads before being swiftly removed.

ShinyHunters Breach Exposes 9,000 Schools in Canvas Hack
A massive data breach has hit Canvas, a popular learning management system, with hackers claiming to have stolen several terabytes of sensitive data, including personal info for 275 million users, from 9,000 schools. The notorious ShinyHunters group is now demanding action, threatening to leak everything if their demands aren't met.

ShinyHunters Breach Disrupts Canvas Education Platform Nationwide
A massive cyberattack by ShinyHunters has disrupted the Canvas Education Platform nationwide, with hackers defacing login pages and holding sensitive data on 275 million students and faculty hostage. The breach forced Instructure to pull Canvas offline, leaving students and faculty in the dark.

Missouri Probes Conduent's Response to Massive Data Breach
Missouri's Department of Commerce and Insurance is stepping up its investigation into Conduent's massive data breach, which is believed to have affected over 25 million people, after the company failed to provide crucial information on the breach's impact. The state agency is urging insurers to come forward with details on their dealings with Conduent, citing significant consumer risk.

AI Tools Facilitate but Fail to Deliver in Water System Hack Attempt
In a recent cyber attack on nine Mexican government entities, hackers surprisingly used AI tools like Claude and Chat GPT to help breach the systems, but ultimately failed to cause significant harm. The attack, which included a January intrusion into a municipal water and sewage utility, revealed that while AI can facilitate malicious activity, it can't guarantee success.

AI-Driven Attacks Infiltrate Cloud Environments, Exposing Hidden Risks
New AI-driven threats are rapidly exploiting cloud security gaps, making it vital for teams to adopt a proactive, holistic approach to risk reduction to safeguard critical assets and data. Stay ahead of adversaries by understanding how they're weaponizing cloud vulnerabilities at alarming speed.

TCLBANKER Trojan Targets Brazil's Financial Sector via WhatsApp Worms
A new Brazilian banking trojan, dubbed TCLBANKER, is targeting the country's financial sector via WhatsApp worms, marking a significant evolution in the threat landscape. This malware can compromise 59 banking, fintech, and cryptocurrency platforms, making it a major player in the region.

Linux Flaw Exposes Root Access Risk
A newly discovered Linux kernel flaw, nicknamed Dirty Frag, poses a serious risk of root access to major Linux distributions, allowing attackers to exploit vulnerabilities and gain control. Security researcher Hyunwoo Kim found the flaw, which can be chained with other vulnerabilities to obtain root privileges.

Ransomware Group ShinyHunters Targets Canvas E-Learning Platform
A massive ransomware attack has hit Canvas, a popular e-learning platform used by over 30 million users, with hackers claiming to have compromised a staggering 275 million individuals' data. The breach, attributed to the notorious ShinyHunters group, forced the platform's developer, Instructure, to take Canvas offline temporarily.

Malware Worm Eliminates Rival, Seizes Control
Meet the malware worm with a ruthless streak - it not only eliminates rival malware from infected systems, but also seizes control and claims the compromised credentials for itself. This cunning worm is taking over, leaving other malicious operators with nothing.

Fraudulent Call History Apps Drain Millions via 7.3M Play Store Downloads
Millions of Android users have been duped into downloading 28 fake call history apps from the Google Play Store, with over 7.3 million downloads recorded before they were finally removed. These apps, which promised access to call logs and more, actually delivered nothing but randomly generated data - and a hefty price tag.

NVIDIA Discloses GeForce NOW Breach Affecting Armenian Users
NVIDIA recently discovered a security breach affecting users of GeForce NOW in Armenia, which was caused by a compromised system operated by a third-party partner, not by NVIDIA's own network. The company is working closely with the partner to resolve the issue and notify affected users.

Linux Flaw Exposes Public Root Exploit With No Patches
A critical Linux vulnerability known as Dirty Frag has been exposed, leaving systems open to a public root exploit with no patches or fix available. This high-urgency flaw allows hackers to gain root access, making it essential for admins to take immediate action.

RansomHouse Hackers Claim Breach of Trellix Source Code
Trellix has confirmed a breach of its source code repository, with hackers from the notorious RansomHouse group claiming to have accessed and encrypted sensitive data on April 17. The group has even posted leaked screenshots to back up its claims.

Data Breaches Surge, Exposing Sensitive Info at AI Startups, Agencies
Data breaches are surging, with AI startups and agencies exposed, as seen in the alarming theft of 10 petabytes from a Chinese supercomputer and 4 terabytes from AI startup Mercor due to a supply-chain vulnerability. These incidents highlight the hidden risks of connecting data to AI models, creating sensitive blind spots that leave large data sets vulnerable to compromise.

CISA Mandates Patching of Ivanti Flaw Exploited in Zero-Day Attacks
The US Cybersecurity and Infrastructure Security Agency (CISA) is requiring immediate patching of a high-risk Ivanti flaw, CVE-2026-6973, that allows attackers with admin privileges to remotely execute code on vulnerable systems. This critical vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) version 12.8.0.0 and earlier.