Skip to main content

Emerging Threats

Office desk with phone in foreground and blurred person in background.

Cushman & Wakefield Discloses Vishing Incident Amid Dual Ransomware Threats

Cushman & Wakefield recently fell victim to a vishing incident, but swift action was taken to contain the breach and protect its systems. The company has confirmed that its operations remain normal and it's working closely with experts to investigate and respond to the incident.

Analyst 207
Person in background looks concerned at a piece of paper near a computer workstation.

Phishing Campaign Exploits Signed RMM Software to Plant Persistent Backdoors

A long-running phishing campaign has compromised over 80 US organizations by using legitimately signed remote monitoring software to install silent, persistent backdoors, according to Securonix research. The attack begins with a clever email impersonating the US Social Security Administration, tricking victims into downloading malicious payloads.

Analyst 207
Laptop screen displays a content management system dashboard in a brightly-lit office setting.

MetInfo CMS Flaw Exploited for Remote Code Execution Attacks

A critical flaw in the MetInfo content management system, CVE-2026-29014, allows remote attackers to execute arbitrary code with a CVSS score of 9.8, putting your site at risk of full takeover. This unauthenticated PHP code-injection vulnerability affects versions 7.9, 8.0, and 8.1, and can be exploited with crafted requests containing malicious PHP code.

Analyst 207
Server room with laptop screen blurred, hinting at a security breach.

Vimeo Breach Exposes 119,000 in Data Heist by ShinyHunters Gang

A recent data breach at Vimeo exposed the email addresses and names of over 119,000 users, thanks to a hack by the notorious ShinyHunters extortion gang, which gained access through a vulnerability at data anomaly detection company Anodot. The breach highlights the importance of securing third-party integrations to protect sensitive user data.

Analyst 207
Person sits at cluttered desk with laptop in dimly lit home office.

Vimeo Breach Exposes 119,000 Email Addresses

A data breach at Vimeo has compromised the email addresses of over 119,000 users, with hackers also accessing some metadata and technical data from a third-party analytics vendor. Fortunately, no video content, login credentials, or payment card information was stolen.

Analyst 207
Computer screen displays OAuth integration interface in a CRM workspace.

OAuth Grants Expose Hidden Attack Vector in Enterprise Workspaces

Unmanaged OAuth grants are a ticking time bomb in enterprise workspaces, with 80% of security leaders recognizing them as a critical or significant risk. A recent attack by threat actor UNC6395 exploited valid OAuth refresh tokens to breach Salesforce environments of over 700 organizations, highlighting the devastating consequences of neglecting OAuth security.

Analyst 207
Person sits alone in dimly lit room, surrounded by blurred dating profiles on laptop screen, conveying sadness and isolation.

Romance Scammers Rake in £102M Through Emotional Manipulation

Romance scammers exploited the trust of unsuspecting victims to pocket a staggering £102 million in 2025, with the average person losing around £9,500 in these emotionally manipulative scams. This heart-wrenching trend saw a 29% surge in reported cases, with £280,000 lost daily.

Analyst 207
Windows laptop with Phone Link app open, connected to smartphone via USB, on a cluttered home office desk.

CloudZ Malware Exploits Microsoft Phone Link to Harvest SMS and OTPs

Beware: CloudZ malware is exploiting Microsoft's Phone Link feature to intercept SMS and OTPs, putting your sensitive info at risk. This sneaky attack uses a plugin called Pheno to tap into your Phone Link activity and steal your private messages.

Analyst 207
A blurred figure in a suit sits or stands with their back to the camera in a government building interior with a judge's…

Karakurt Ransomware Operative Sentenced for Extortion Role

Meet Deniss Zolotarjovs, a Latvian national who helped his ransomware gang extort dozens of companies - and even a government entity with a crippled 911 system - by leveraging stolen sensitive data, including children's health information. He's now facing 8.5 years in prison for his role in the Karakurt extortion operation.

Analyst 207
Brightly lit computer workstation with generic gaming peripherals and cables against a neutral background.

ScarCruft Expands Malware Arsenal with Multi-Platform BirdCall Backdoor

ScarCruft hackers have launched a sneaky attack on a popular video game platform, infecting both Windows and Android users with a new backdoor called BirdCall. The multi-platform threat has been targeting ethnic Koreans in China since late 2024, allowing hackers to gain unauthorized access.

Analyst 207
Smartphone on a cluttered gaming desk with blurred Android game interface.

North Korean Hackers Infiltrate Android Games to Spy on Defectors

Security researchers at Eset stumbled upon a sneaky plot by North Korean hackers, who infiltrated popular Android games to spy on defectors by hiding a backdoor called BirdCall in the apps. The malicious code was cleverly disguised in game files available for download on a regional gaming platform's official website.

Analyst 207
People play games at computers in a crowded internet cafe with a potentially infected system in the background.

ScarCruft hackers deploy BirdCall malware via gaming platform.

North Korean hackers APT37, also known as ScarCruft, have cleverly expanded their BirdCall malware to target Android devices, adapting their Windows backdoor to spy on mobile users. They even used a popular gaming platform to sneak the malware onto unsuspecting devices.

Analyst 207
Rows of computer servers in a dimly-lit data center represent a vulnerable cybersecurity setting.

Trellix Breach Exposes Source Code to Threat Actors

Trellix has confirmed a breach of its internal development assets, revealing that threat actors gained unauthorized access to a portion of its source code repository. The company is working with experts to investigate and has found no evidence that its source code has been exploited so far.

Analyst 207
Laptop workstation in a brightly-lit hospital corridor with medical equipment and computers in the background.

Microsoft Exposes Large-Scale Phishing Campaign Targeting 35,000 Users Worldwide

A massive phishing campaign targeting over 35,000 users worldwide has been uncovered, using sophisticated email templates that convincingly masquerade as legitimate internal communications. The highly convincing lures successfully hit organizations across 26 countries, with a staggering 92% of targets based in the US.

Analyst 207
Industrial control system in a factory setting with a nearby computer screen.

Weaver E-cology Flaw Exploited Through Debug API Endpoint

A critical bug in Weaver E-cology, known as CVE-2026-22679, is being actively exploited - allowing hackers to take full control of your system with a CVSS score of 9.8. This severe vulnerability lets attackers execute commands without needing login credentials, putting your entire system at risk.

Analyst 207
University campus workstation with laptop screen blurred, surrounded by ordinary indoor lighting.

Instructure Data Breach Exposes Sensitive Information

A massive data breach at Instructure has potentially exposed the sensitive information of 275 million individuals, making it one of the largest breaches in recent weeks. The incident, which was disclosed on May 1, is still under investigation, with the company working closely with experts to contain the damage and keep users informed.

Analyst 207
Rows of computer servers and equipment in a Linux server room with a single workstation in the foreground.

Linux Vulnerability 'Copy Fail' Exposes High-Severity Risk

A newly discovered Linux vulnerability, dubbed "Copy Fail," poses a high-severity risk, allowing authenticated local users to gain root access and take total control of a system. This alarming flaw, tracked as CVE-2026-31431, has already moved from discovery to exploitation in the wild.

Analyst 207
Small defense firm office with networking equipment and abstract cyber threat representation.

Nation-State Hackers Target Small Defense Firms' Network Gaps

Small defense firms are leaving themselves exposed to nation-state hackers, who exploited over 14 zero-day vulnerabilities in edge devices like routers and firewalls in 2025 to gain a foothold in the US defense industrial base. These stealthy cyber espionage groups are investing heavily in reconnaissance and pre-positioning operations to infiltrate and linger in their targets' networks.

Analyst 207
Dimly lit, abandoned cryptocurrency trading room with scattered papers and broken equipment.

Grinex Shutdown Won't Curb Russian Sanctions Evasion

The shutdown of Grinex, a Kyrgyzstan-registered cryptocurrency exchange, highlights the cat-and-mouse game of sanctions evasion, where experts warn that the ecosystem's fragmentation will only make it harder to track illicit activity. As Kaitlin Martin, a senior intelligence analyst at Chainalysis, notes, a fractured ecosystem makes it increasingly difficult to target evasive maneuvers.

Analyst 207
Data storage room with rows of file cabinets and servers, and an open laptop in the foreground.

Ransomware Gang Exposes Alleged Liberty Mutual Data Trove

A massive 108-gigabyte data trove allegedly stolen from Liberty Mutual has been exposed by ransomware gang Everest Group, containing sensitive policyholder information including names, addresses, and financial details. The group claims to have published the data after the insurance company failed to respond to its demands.

Analyst 207
Brightly-lit industrial server room with a generic controller on the wall.

Hackers Exploit Weaver E-cology Bug in Targeted Attacks

Hackers are taking advantage of a critical bug in Weaver E-cology, using an exposed debug API endpoint to execute system commands on vulnerable servers without needing login credentials. This security flaw, tracked as CVE-2026-22679, affects Weaver E-cology 10.0 builds prior to March 12.

Analyst 207
Rows of servers and network equipment in a data center appear vulnerable with some areas blurred or out of focus.

AI-Driven Attacks Infiltrate Cloud Environments

Stay ahead of the threats: as AI-driven attacks infiltrate cloud environments, it's crucial to adopt a proactive, holistic approach to risk reduction and protect your critical assets and data. Google Cloud and XM Cyber warn that understanding how attackers move laterally throughout your network is key to safeguarding against emerging AI-driven threats.

Analyst 207
Cloud-based email service dashboard on laptop screen with blurred interface, surrounded by a brightly-lit institutional…

Phishing Attacks Exploit Amazon SES to Evade Detection

Kaspersky researchers have uncovered a surge in phishing attacks that cleverly exploit Amazon's trusted email service to evade detection. By using valid Amazon SES credentials, attackers can send convincing phishing messages that slip past standard security checks.

Analyst 207
Dental office with scattered files and subtle server room hint.

New York Fines Delta Dental $2.25M for MOVEit Hack Violations

Delta Dental of New York has been fined $2.25 million by the New York Department of Financial Services for its handling of a massive data breach involving hackers stealing around 60,000 files from its MOVEit servers in 2023. The hefty penalty highlights the importance of robust cybersecurity measures to protect sensitive information.

Analyst 207