Emerging Threats

Voter Data Exposes Sensitive Information to Potential Misuse
A simple experiment by Noah M. Kenney revealed alarming privacy risks when he linked publicly available voter data from two counties with other public records, highlighting the sensitive information at risk of misuse. By analyzing voter files from Texas and North Carolina, Kenney showed just how easily voter data can be exploited.

Romance Scammers Pocket £102M via Cyber Deception Tactics
Romance scammers made off with a staggering £102 million in the UK last year, using their silver tongues to swindle victims out of their hard-earned cash. Their tactics, cloaked in sweet talk and false affection, ultimately led to a £102 million payday.

ShinyHunters Leak Exposes 119K Vimeo Emails
A massive data leak, allegedly perpetrated by the threat actor group ShinyHunters, has put 119,000 Vimeo email addresses at risk, according to a recent report. This alarming breach raises serious concerns about online data security and user privacy.

Real Estate Giant Hit by Vishing Incident from ShinyHunters, Qilin Gang
Cushman & Wakefield, a real estate giant, has confirmed a vishing incident at the hands of notorious threat actors ShinyHunters and Qilin Gang, highlighting the growing threat of social engineering attacks. This recent breach serves as a stark reminder of the importance of robust security measures.

Attackers Exploit Fresh 'CopyFail' Linux Flaw for Financial Gain
Attackers are already exploiting a newly discovered Linux flaw called CopyFail to line their pockets, and it's essential to stay informed about this developing threat. The vulnerability has been identified, and malicious actors are capitalizing on it - but details on affected systems and patches are still emerging.

CloudZ RAT Exploits Windows Phone Link for Credential Theft
Cyber attackers have cleverly exploited the Microsoft Phone Link feature to steal sensitive credentials and one-time passwords, all without needing to infect mobile devices with malware. By targeting this built-in Windows application, hackers can access synced phone data and extract valuable information.

India Issues Infosec Alert as Mythos Threat Looms
India's securities regulator is sounding the alarm on a looming cybersecurity threat, warning market players to bolster their defenses and get ahead of AI-powered attacks. With the Mythos threat on the horizon, it's crucial to develop new strategies and solidify cyber-basics to stay safe.

Palo Alto Networks Firewalls Targeted in Zero-Day Exploits
Palo Alto Networks firewalls are under attack by zero-day exploits targeting a vulnerability in the User-ID Authentication Portal, allowing hackers to execute malicious code with root privileges. This buffer overflow flaw, tracked as CVE-2026-0300, poses a significant risk to organizations with Internet-exposed firewalls.

UK Workers Sell Corporate Logins, Exposing Firms to Cybercrime
One in eight UK employees at large firms have sold or know someone who has sold corporate logins in the past year, a shocking trend that puts companies at risk of cybercrime. Alarming still, many justify this risky behaviour, with senior executives being more likely to think selling credentials is acceptable.

Palo Alto Networks Flaw Exploited for Remote Code Execution
A critical vulnerability in Palo Alto Networks' PAN-OS software has been exploited, allowing hackers to execute malicious code with root privileges on firewalls - and all it takes is a few specially crafted packets. This buffer overflow flaw, tracked as CVE-2026-0300, puts PA-Series and VM-Series firewalls at risk of remote code execution attacks.

DarkSword Malware Targets iOS with Sophisticated Exploit Chain
Meet DarkSword, a sneaky malware that's been targeting iOS devices with a sophisticated exploit chain, leveraging six different vulnerabilities to deploy its final-stage payloads across iOS versions 18.4 through 18.7. Google Threat Intelligence Group has tracked its use back to November 2025, with multiple actors - from commercial vendors to suspected state-sponsored operators - employing it to compromise devices.

Quasar Linux Malware Targets Developers with Stealthy Implant
Meet Quasar Linux, a sneaky new malware targeting developers with a potent blend of stealth, persistence, and credential theft capabilities that can compromise software supply chains. This Linux implant is quietly infiltrating dev and DevOps environments, putting cloud toolchains at risk.

Instructure Breach Exposes 280 Million Records from 8,800 Educational Institutions
A massive data breach at Instructure has put the sensitive information of 280 million students, teachers, and staff from 8,800 educational institutions at risk, with the ShinyHunters extortion gang claiming responsibility for the attack. The stolen records include data from colleges, school districts, and online education platforms that use Canvas.

Kaspersky Uncovers Trojanized DAEMON Tools in Targeted Supply-Chain Attack
If you installed DAEMON Tools between April 8 and now, your system may be compromised - Kaspersky researchers warn that a highly sophisticated supply-chain attack has been delivering a backdoor to thousands of systems via trojanized installers. Check your machines for unusual activity and take action ASAP to protect your organization.

Phishing Campaign Targets 35,000 Users in 2 Days
In just 48 hours, a massive phishing campaign hit over 35,000 users across 13,000 organizations in 26 countries, with nearly 1 in 5 targets in the healthcare and life sciences sector. The alarming attack highlights the speed and scale of modern phishing operations.

European Lawmakers Urge Swift Action on AI-Driven Cybersecurity Threats
European lawmakers are sounding the alarm, warning that Europe is unprepared for the growing threat of AI-driven cybersecurity attacks and urging swift action to defend against them. They've pressed the European Commission for rapid action, citing the alarming capabilities of advanced AI models like Anthropic's Mythos.

Taiwan Railway Hack Exposes Vulnerabilities in TETRA System
A clever 23-year-old hacker brought Taiwan's high-speed rail to a standstill for 48 minutes by exploiting a shocking weakness in the TETRA system, used to coordinate critical communications. Using just a few pieces of easily-bought equipment, the attacker sent a fake "General Alarm" signal that was treated as the real deal.

Kaspersky Uncovers DAEMON Tools Supply Chain Attack
Kaspersky researchers have uncovered a sneaky supply chain attack that used compromised DAEMON Tools installers, downloaded directly from the official website, to deliver a malicious payload - and what's even scarier is that these installers were digitally signed by the very developers of DAEMON Tools themselves.

Latvian Hacker Sentenced for Role in Former Conti Leaders' Ransomware Extortion Scheme
A Latvian hacker has been sentenced to 8.5 years in federal prison for his role in a massive ransomware extortion scheme that targeted over 54 companies, causing hundreds of millions of dollars in losses. Deniss Zolotarjovs, 35, helped former Conti leaders extort payments from victims over a two-year period.

Microsoft Uncovers Large-Scale Phishing Campaign Using Fake Compliance Emails
In just 48 hours, a massive phishing campaign targeted over 35,000 users across 13,000 organizations in 26 countries, using convincing fake compliance emails to steal login credentials. The sophisticated attack, detected by Microsoft's Defender Research team, hit US firms hard, but its global reach was widespread.

China-Linked UAT-8302 Exploits Shared Malware to Target Global Governments
Meet UAT-8302, a sophisticated China-linked threat group that's been secretly targeting governments worldwide, deploying custom malware to infiltrate and gather intel. Its recent attacks have hit government entities in South America and southeastern Europe, raising global cybersecurity concerns.

Stalkerware Breach Exposes Risks for Executives
A shocking stalkerware breach has exposed a treasure trove of sensitive information, including 86,859 images - seemingly screenshots from a single victim's device - used to secretly stalk a high-profile European entrepreneur and media personality. The alarming leak highlights the very real risks executives face in the digital age.

ScarCruft APT Exploits Yanbian Gaming Platform for Intelligence Gathering
Meet ScarCruft, a notorious North Korea-aligned espionage group that's been caught exploiting a popular gaming platform in China to gather intel on its users. The group trojanized a site serving traditional Yanbian-themed games, compromising both Windows and Android software.

CISA Warns of Active Exploits of Linux 'CopyFail' Flaw
A newly disclosed Linux kernel vulnerability, dubbed "CopyFail," is being actively exploited, allowing low-privilege users to gain full root control on unpatched systems with a single, unmodified exploit binary. This alarming flaw, tracked as CVE-2026-31431, has sparked emergency patching efforts to prevent widespread attacks.