Emerging Threats

Ransomware Breach Exposes Sensitive Data at Sandhills Medical Foundation
Sandhills Medical Foundation suffered a devastating ransomware attack on May 8, 2025, putting sensitive data at risk. It took nearly 11 months for affected individuals to be notified in April 2026, sparking an investigation into the breach.

Trellix Source Code Repository Breached
Trellix revealed a breach of its source-code repository over the weekend, but fortunately found no signs of exploitation or compromise to its code release process. The company is still investigating and has promised to share more details once it's completed.

Phishing Campaign Exploits Legitimate RMM Tools to Hit 80+ Orgs
A sneaky phishing campaign has infiltrated over 80 organizations, mostly in the US, by exploiting legitimate remote monitoring and management (RMM) tools like SimpleHelp and ScreenConnect. The attackers cleverly used customized versions of these tools, already installed by the victims, to bypass defenses and gain unauthorized access.

Malicious PyTorch Lightning Package Exploits Supply Chain to Steal Credentials
A malicious version of the popular PyTorch Lightning package, downloaded over 11 million times, was found to contain a stealthy backdoor that steals credentials by silently executing a heavily obfuscated JavaScript payload. The compromised package, version 2.6.3, triggers the malicious routine automatically when imported, putting users at risk.

Data Centers Emerge as Prime Targets in Cyber Warfare
In today's digital age, data centers have become a high-stakes battleground in cyber warfare, with modern economies, militaries, and corporations relying heavily on digital infrastructure to stay competitive and operational. A recent attack in the Middle East that took out cloud data centers served as a wake-up call, highlighting a critical vulnerability that could have far-reaching consequences.

Attackers Exploit Amazon SES to Bypass Email Security in Phishing Campaigns
Phishing campaigns are now using Amazon's Simple Email Service to make malicious messages look legit, bypassing standard email security checks and putting victims at risk of revealing sensitive data. By exploiting Amazon SES's trusted reputation and authentication features, attackers are making it harder to spot phishing emails.

Trellix Breach Exposes Source Code Repository
Trellix has confirmed a security incident involving unauthorized access to part of its source code repository, and is working closely with forensic experts and law enforcement to investigate. The company is reviewing the breach and will share updates as more information becomes available.

Cybercrime Groups Exploit AI for Rapid, High-Impact Attacks
Cybercrime groups are leveraging AI to launch lightning-fast, high-impact attacks, outpacing security patches and leaving devastating consequences in their wake. This week, a critical vulnerability in cPanel and WHM was exploited, leading to website wipes, botnet deployments, and ransomware attacks.

Cybersecurity Experts Imprisoned for Ransomware Extortion Scheme
Two American cybersecurity experts, Ryan Goldberg and Kevin Martin, have been sentenced to prison for their roles in a brazen 2023 ransomware campaign that targeted companies across the United States. Their crimes have brought to light the severe consequences of cyberattacks and the importance of protecting businesses from such threats.

Fraudsters Target Credit Unions with Structured Loan Scams
Fraudsters are now targeting credit unions with sophisticated loan scams, using stolen identities and social engineering to exploit lending workflows. In fact, auto lending fraud exposure is expected to hit $9.2 billion by 2025, making it a lucrative target for these scammers.

Silver Fox Targets India, Russia with ABCDoor Malware via Tax Phishing
Meet Silver Fox, a China-based cybercrime group that's using tax phishing scams to deliver a sneaky new malware called ABCDoor, targeting India and Russia with cleverly crafted emails that masquerade as official tax notices. The group's tactics involve PDFs with links to infected archives, tricking victims into downloading the malware.

AI-Assisted Attacks Surge as Barrier to Entry Drops
A 17-year-old with no coding experience was recently arrested for hacking into Kaikatsu Club and stealing 7 million users' personal data - his motive? To fund his Pokémon card habit. This shocking case highlights a disturbing trend: nontechnical individuals are now using AI-powered tools to launch devastating cyberattacks.

CISA Warns of Active Linux Exploit
A newly discovered Linux kernel bug, dubbed "Copy Fail," allows unprivileged users to gain root privileges on unpatched systems, prompting urgent warnings from CISA and researchers. If your Linux system was built between 2017 and the recent patch, you're at risk - and need to act fast to protect yourself.

cPanel Vulnerability Exploited to Target Gov't, MSP Networks
A critical cPanel vulnerability, CVE-2026-41940, is being actively exploited by attackers to bypass authentication and gain control of government, military, MSP, and hosting provider networks. This alarming threat uses hard-coded credentials and cleverly defeats CAPTCHA protections to wreak havoc on vulnerable systems.

Voter Data Exposes Personal Info to Potential Abuse
Your voter data is at risk of being exposed and used against you, with publicly available registration files potentially revealing sensitive information about you and your family. Even redacted files can be easily linked to other public datasets, making it simple for employers, fraud rings, or others to access your personal info.

Global Crackdown Targets Crypto Scam Centers, Arrests 276
In a major global crackdown, authorities have arrested 276 suspects and shut down nine cryptocurrency scam centers, dealing a significant blow to fraudsters targeting Americans from abroad. This coordinated effort, led by Dubai Police and involving the FBI and China's Ministry of Public Security, sends a clear message: scammers can't hide from the law, no matter where they are in the world.

Instructure Breach Exposes Data of 275 Million Users
A recent data breach at Instructure, the company behind Canvas, has compromised the sensitive information of 275 million users, including names, email addresses, student ID numbers, and private messages. The company is actively investigating the incident with cybersecurity experts and law enforcement.

Telegram Abused for Crypto Scams and Android Malware Delivery
Researchers uncovered a massive scam operation, dubbed FEMITBOT, that uses Telegram's Mini Apps to spread fake crypto platforms, brand impersonations, and Android malware, with a single API string tying it all together. Victims are lured in with a convincing, app-like interface that tricks them into divulging sensitive info.

CISA Warns of Actively Exploited Linux Root Access Bug
A nine-year-old Linux kernel bug, known as Copy Fail, is being actively exploited in the wild, allowing unprivileged users to gain root access with a simple 732-byte Python-based exploit. The Cybersecurity and Infrastructure Security Agency has added this vulnerability to its Known Exploited Vulnerabilities catalog, warning of potential security risks.

cPanel flaw fuels mass Sorry ransomware attacks
A critical flaw in cPanel, tracked as CVE-2026-41940, has been exploited in a massive ransomware campaign, compromising at least 44,000 IP addresses. This alarming attack has already been used in the wild as a zero-day, with threat actors accessing control panels and wreaking havoc on web hosting systems.

Trellix Source Code Breach Exposes Repository Vulnerability
Trellix recently identified a security breach that compromised a portion of its source code repository, prompting an immediate investigation with leading forensic experts and notification of law enforcement. The company has assured that there's no evidence its source code release process was affected or exploited - yet.

Threat Actors Exploit Blind Spots Beyond Endpoint Defenses
Attackers are now moving at an alarming pace, taking data four times faster than in 2025, and exploiting the blind spots that an over-reliance on endpoint defenses creates. They're striking across multiple surfaces, from cloud services to remote users, to evade detection and get in and out quickly.

North Korea Exploits Fake Meetings to Fuel Crypto Heists
North Korea is using fake video meetings to trick people into crypto scams, fueling a growing concern in the world of cryptocurrency. This clever tactic is just one of the many evolving methods threat actors are using to steal money.

Ransomware Defenses Hold, But New AI Threats Emerge
While ransomware defenses have shown significant improvement, experts warn that complacency is a luxury we can't afford, especially with hospital systems remaining prime targets. New AI threats are emerging, demanding our attention and action.