Skip to main content

Emerging Threats

Rows of computer servers with flickering screens and dimmed lights suggest a breach or disruption in a technology company's…

RansomHouse Hackers Claim Breach of Trellix Source Code

Trellix has confirmed a breach of its source code repository, with hackers from the notorious RansomHouse group claiming to have accessed and encrypted sensitive data on April 17. The group has even posted leaked screenshots to back up its claims.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center.

Data Breaches Surge, Exposing Sensitive Info at AI Startups, Agencies

Data breaches are surging, with AI startups and agencies exposed, as seen in the alarming theft of 10 petabytes from a Chinese supercomputer and 4 terabytes from AI startup Mercor due to a supply-chain vulnerability. These incidents highlight the hidden risks of connecting data to AI models, creating sensitive blind spots that leave large data sets vulnerable to compromise.

Analyst 207
Rows of equipment racks and patch panels in a brightly-lit server room or network closet.

CISA Mandates Patching of Ivanti Flaw Exploited in Zero-Day Attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) is requiring immediate patching of a high-risk Ivanti flaw, CVE-2026-6973, that allows attackers with admin privileges to remotely execute code on vulnerable systems. This critical vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) version 12.8.0.0 and earlier.

Analyst 207
Cluttered developer workstation with laptop and devices, screens blank.

Linux RAT Quasar Exploits Developer Credentials for Supply Chain Compromise

Meet QLNX, a sneaky Linux malware that's targeting developers and DevOps teams to gain control of the software supply chain by stealing sensitive credentials. This stealthy threat operates from memory, masquerading as a harmless system process while secretly exfiltrating data and awaiting commands from its controllers.

Analyst 207
University campus setting with laptop, papers, and books, hinting at disruption.

ShinyHunters Breach Exposes Educational SaaS Canvas

ShinyHunters hackers have claimed responsibility for taking down educational software platform Canvas in a cyberattack that left users offline. The group didn't hold back, giving the developer a scathing "F for security" in their criticism of the breach.

Analyst 207
Dusty server room with Linux server at center, surrounded by cables and equipment under flickering fluorescent light.

Linux Backdoor Exploits PAM Modules to Harvest SSH Credentials

Meet PamDOORa, a sneaky Linux backdoor that's being sold on the dark web for $1,600, allowing hackers to harvest SSH credentials using a clever combination of a magic password and TCP port. This stealthy threat leverages PAM modules to gain persistent access to your system.

Analyst 207
Blurred computer screen looms behind brightly-lit customer service desk in retail store.

Zara Breach Exposes Data of 197,000 Customers Worldwide

A recent data breach at a former technology provider exposed the sensitive information of 197,400 Zara customers worldwide, including email addresses, product details, and order IDs. The breach, revealed by data-breach notification service Have I Been Pwned, highlights the importance of securing customer data.

Analyst 207
Laptop on a cluttered student desk with a blurred screen.

ShinyHunters Breach Educational SaaS Canvas

A recent cyberattack has left Canvas, a popular educational software-as-a-service platform, offline, with hackers group ShinyHunters taking credit for the breach and raising serious concerns about the platform's security. The incident has disrupted learning and left many wondering about the safety of sensitive data.

Analyst 207
Server racks and cloud storage units in a data center with a hint of disruption.

PCPJack Disrupts TeamPCP's Cloud Footprint with Credential Theft

Meet PCPJack, a sneaky new credential theft framework that's wreaking havoc on TeamPCP's cloud operations by stealing sensitive credentials and clearing out the competition. This malicious tool is quietly moving through cloud environments, leaving a trail of compromised systems in its wake.

Analyst 207
Linux terminal on a laptop in a research setting with code on the screen.

Linux 'Dirty Frag' Zero-Day Exposes Root Flaw in Major Distros

A newly discovered Linux zero-day, dubbed "Dirty Frag," allows hackers to instantly gain root access on major distributions by chaining two separate kernel vulnerabilities. This flaw enables attackers to alter protected system files in memory without authorization, putting countless systems at risk.

Analyst 207
A Linux workstation sits on a plain surface in a clean office setting, surrounded by blurred equipment and code.

Linux Flaw Enables Root Access Across Major Distributions

A newly discovered Linux flaw, dubbed Dirty Frag, allows hackers to gain root access across major distributions by exploiting a chain of vulnerabilities in the kernel codebase. This unpatched local privilege escalation is a deterministic logic bug, making it a particularly potent threat.

Analyst 207
Rows of equipment and racks in a brightly-lit server room with a single unoccupied laptop in the foreground.

Ivanti Discloses Actively Exploited Zero-Day in Endpoint Manager

Ivanti has confirmed that hackers are actively exploiting a zero-day vulnerability, CVE-2026-6973, in its Endpoint Manager Mobile (EPMM) software, allowing them to run code remotely with administrative privileges. The company has issued patches for this and four other EPMM flaws to protect its customers.

Analyst 207
Blurred laptop screen shows Canvas login page in bright college library setting.

ShinyHunters Breach Exposes 330 Colleges in Canvas Hack

The notorious ShinyHunters gang has breached Instructure's Canvas, exposing a staggering 330 colleges to a devastating hack, and issued a chilling ultimatum with a May 2026 deadline to negotiate. The attackers replaced login pages with an extortion message, demanding schools seek cyber advisory help and secretly reach out to settle.

Analyst 207
Busy office scene with people in background, laptop in foreground displaying signs of malware breach.

TCLBanker Malware Spreads Rapidly via WhatsApp, Outlook

Beware of a rapidly spreading malware, TCLBanker, that's infecting 59 major banking, fintech, and cryptocurrency platforms through sneaky WhatsApp and Outlook attacks. This sneaky trojan uses a fake Logitech AI Prompt Builder installer to wreak havoc on your digital security.

Analyst 207
Rows of computer servers and storage equipment in a neutral-colored data center with industrial flooring and cable…

PCPJack Credential Stealer Exploits CVEs to Spread Across Cloud Systems

Meet PCPJack, a sneaky credential stealer that's exploiting vulnerabilities to spread rapidly across cloud systems, swiping sensitive info from services like cloud, finance, and productivity tools. Its operators are after one thing: illicit financial gain.

Analyst 207
Rows of computer servers with a focused server displaying a blank screen in a brightly-lit network operations center.

Ivanti EPMM Flaw Exploited, Grants Admin-Level Access

A critical flaw in Ivanti's Endpoint Manager Mobile (EPMM) has been exploited, allowing attackers to gain admin-level access - and the government is taking swift action to mitigate the threat. Federal agencies are now required to remediate the vulnerability, known as CVE-2026-6973, by May 10, 2026.

Analyst 207
Rows of computer servers and storage equipment in a data center with a single unoccupied Linux terminal in the foreground.

PCPJack Worm Targets Cloud Infrastructure, Steals Credentials

A fresh malware campaign, dubbed PCPJack, is targeting cloud infrastructure, stealing credentials and wreaking havoc on Linux-based systems with a sophisticated framework that installs hidden working directories and establishes persistence. This alarming attack bears striking similarities to earlier TeamPCP/PCPCat campaigns, raising concerns about its potential impact.

Analyst 207
Person sitting at laptop in office setting with blurred screen.

Australia Warns of ClickFix Malware Attacks Spreading Vidar Stealer

Beware of ClickFix malware attacks that trick you into executing commands, allowing hackers to bypass security and steal your info. The Australian Cyber Security Center has warned of a new campaign using WordPress-hosted sites to spread the Vidar Stealer malware.

Analyst 207
IT staff members work at a computer terminal in a brightly-lit server room with a blurred monitoring screen in the…

Ivanti Discloses High-Severity EPMM Flaw Exploited in Zero-Day Attacks

Ivanti has disclosed a high-severity flaw in its Endpoint Manager Mobile (EPMM) product, which has been exploited in limited zero-day attacks requiring admin authentication. To protect against this vulnerability, customers are advised to patch to Ivanti EPMM versions 12.6.1.1, 12.7.0.1, or 12.8.0.1.

Analyst 207
Cluttered office desk with laptop and smartphone, screens blurred.

Malicious Site Exploits AI Interest to Deploy Beagle Backdoor

Beware of a fake website masquerading as Anthropic's Claude interface, tricking users into downloading a 505 MB ZIP archive that unleashes a new, previously undocumented Windows backdoor called Beagle. This malicious campaign uses a convincing imitation of the legitimate site to spread the infection.

Analyst 207
Network device in a brightly-lit tech environment with blurred background infrastructure.

Palo Alto Networks Discloses Active Exploitation of PAN-OS Flaw Enabling Espionage

Palo Alto Networks has uncovered active exploitation of a high-severity flaw in PAN-OS software, allowing attackers to execute arbitrary code with root privileges and inject shellcode into vulnerable systems. This critical vulnerability, tracked as CVE-2026-0300, enables unauthenticated remote code execution, putting affected appliances at risk of espionage.

Analyst 207
Industrial control systems and pipes at a municipal water utility under ordinary lighting, with subtle hints of a potential…

Dragos Warns of AI-Powered Cyber-Attack on Mexican Water Utility

A recent cyber attack on a Mexican water utility highlights the growing threat of AI-powered attacks, with commercial AI tools used to identify and breach operational technology infrastructure. The attack, detected by Dragos, shows how easily an adversary can target critical infrastructure with the help of advanced AI tools.

Analyst 207
Person typing on laptop keyboard in modern office setting with blurred screen.

AI Exploits Emerge as New Security Threat

As AI use grows, a hidden risk is emerging: malicious inputs can alter model behavior, bypassing safeguards and putting enterprises at risk. This "prompt injection" tactic is like phishing, targeting the link between user and system to wreak havoc.

Analyst 207
Dimly lit, ransacked suburban home interior with laptop and digital wallet setup.

Crypto Heist Ringleader Gets 6.5 Years for $230 Million Loot

Marlon Ferro, the mastermind behind a brazen crypto heist, has been sentenced to 6.5 years for stealing $230 million in cryptocurrency using a cunning mix of online scams and targeted home invasions. He served as the group's instrument of last resort, carrying out daring residential burglaries to get his hands on valuable digital assets.

Analyst 207