Skip to main content

Emerging Threats

Hospital corridor with people walking, laptop on administrator's desk near large windows.

Ransomware Defenses Hold, But New AI Threats Emerge

While ransomware defenses have shown significant improvement, experts warn that complacency is a luxury we can't afford, especially with hospital systems remaining prime targets. New AI threats are emerging, demanding our attention and action.

Analyst 207
Medical device in a clinical setting shows subtle signs of concern.

Medtronic Faces Federal Lawsuits Over Recent Hack

Medtronic is facing a wave of federal lawsuits after a massive data breach exposed over 9 million records containing sensitive personal information, sparking concerns about the company's handling of customer data. The breach, attributed to the ransomware gang ShinyHunters, has left many questioning the vulnerability of medical device manufacturers to cyber threats.

Analyst 207
Concerned person checks laptop in small workspace, conveying vulnerability.

Vietnamese Hackers Exploit Google AppSheet in 30,000-Account Facebook Phishing Spree

A massive phishing operation, dubbed AccountDumpling, has compromised around 30,000 Facebook accounts using a clever tactic: sending malicious emails from a legitimate Google AppSheet address to bypass spam filters. This sophisticated scam was more than just a simple phishing kit - it was a constantly evolving operation with real-time control panels and a lucrative criminal enterprise.

Analyst 207
Natural light pours into a French government agency's interior, highlighting institutional elements amidst a scene of…

French Teen Detained for Breach of Gov't Agency Data

A massive data breach at a French government agency has led to the detention of a 15-year-old suspect, with 11.7 million accounts impacted, prompting a swift investigation and criminal probe. The breach was detected on April 13, and authorities were notified just a few days later.

Analyst 207
A cluttered journalist's workspace with scattered notes and a laptop displaying a blank screen.

Researchers Warn of Emerging Exploit Threats After AI-Enabled Zero-Day Discovery

BleepingComputer issued a swift correction, retracting a report of a new data breach at Instructure due to reliance on outdated information from a prior incident, and expressed regret for the error. The incorrect story was pulled shortly after publication.

Analyst 207
Brightly-lit server room with subtle signs of security breach.

China-Linked Hackers Expose Wide-Ranging Espionage Campaign

Meet SHADOW-EARTH-053, a China-aligned espionage group that's been secretly lurking in the shadows since December 2024, using clever tactics like exploiting vulnerabilities and deploying web shells to gain persistent access to sensitive targets. Their sophisticated attacks have been linked to other notorious intrusion sets, revealing a vast and complex espionage campaign.

Analyst 207
A brightly-lit office workspace with a laptop on a desk, surrounded by ordinary decor and a subtle hint of a phone nearby.

Cybercrime Groups Exploit Vishing, SSO Abuse in SaaS Extortion Spree

Cybercrime groups are launching lightning-fast extortion attacks within trusted SaaS environments, exploiting vishing and SSO abuse to evade detection and strike with precision. By hiding in plain sight, they're creating significant challenges for defenders trying to keep up.

Analyst 207
Rack-mounted servers and network equipment in a brightly-lit data center interior.

cPanel Vulnerability Exploited, Ransomware Attacks Reported

A critical cPanel vulnerability, CVE-2026-41940, has been exploited, putting servers at risk of full takeover and ransomware attacks - with a near-worst-case severity score of 9.8. This flaw affects cPanel, WebHost Manager, and WP Squared, and has already been flagged by the US government's cybersecurity agency as being exploited in the wild.

Analyst 207
Government building with tall windows, abstract seal, and blurred laptop in foreground.

US Sentences Two Cybersecurity Pros for BlackCat Ransomware Role

Two cybersecurity experts turned to a life of crime, using their specialized knowledge to extort victims through BlackCat ransomware attacks, and have been sentenced to four years in prison for their roles. Ryan Goldberg and Kevin Martin deployed the ransomware against multiple US victims between April and December 2023.

Analyst 207
Close-up of Linux server circuit board with a faintly glowing area indicating a vulnerability.

AI Uncovers Nine-Year-Old Linux Kernel Zero-Day Flaw

A shocking nine-year-old flaw in the Linux kernel, dubbed "Copy Fail," allows unprivileged users to secretly alter readable files and potentially gain root access to affected systems. This vulnerability, tracked as CVE-2026-31431, has been lurking in Linux kernels since 2017, putting countless machines at risk.

Analyst 207
Rows of computer equipment and cables in a brightly-lit server room or network operations center.

Pro-Iran Hackers Extort Canonical with Sustained DDoS Attacks

Canonical, the company behind Ubuntu, is battling a relentless cyber assault, with its website crippled by a sustained Distributed Denial of Service (DDoS) attack that has left its main site inaccessible. The Islamic Cyber Resistance in Iraq, also known as 313 Team, has claimed responsibility for the attack.

Analyst 207
Two men in formal attire sit in a courtroom with a judge's bench in the background under natural light.

US Cybersecurity Workers Jailed for Aiding BlackCat Ransomware Gang

Meet Ryan Goldberg and Kevin Martin, two cybersecurity experts who abused their skills to line their pockets by aiding the notorious BlackCat ransomware gang. They've been sentenced to four years in prison for their roles in facilitating devastating ransomware attacks.

Analyst 207
Cluttered software development workspace with laptop and monitor displaying GitHub page.

Malicious Ruby Gems, Go Modules Exploit CI Pipelines for Credential Theft

Malicious actors are targeting developers and CI pipelines with fake Ruby Gems and Go Modules, masquerading as familiar libraries to steal credentials. The campaign, linked to the GitHub account BufferZoneCorp, poses a significant threat to software supply chains.

Analyst 207
Formal courthouse interior with podium and judge's bench under tall windows.

Ransomware Negotiators Sentenced for BlackCat Attacks

Two former cybersecurity experts, who once worked to protect companies, were sentenced to four years in prison for using their skills to extort US businesses as affiliates of the notorious BlackCat ransomware gang. They exploited their specialized knowledge to orchestrate attacks on US companies, leaving a trail of devastation in their wake.

Analyst 207
Server control panel in a data center with a focus on a single targeted system.

cPanel vulnerability exploited in wild, CISA warns

A critical cPanel vulnerability, CVE-2026-41940, with a near-perfect 9.8 CVSS score, is being exploited in the wild, putting roughly 1.5 million exposed instances at risk of being opened without a password. This flaw allows attackers to bypass authentication by cleverly manipulating the password field with hidden line breaks.

Analyst 207
Person working at desk with laptop in a well-lit office setting.

Malicious AI Browser Extensions Exfiltrate User Data

Beware of AI browser extensions that promise to boost productivity but secretly steal your data. Researchers uncovered 18 malicious extensions that masquerade as helpful tools but deliver spyware, Trojans, and other threats that can hijack your online activity.

Analyst 207
Formal courthouse interior with podium and blurred emblem in background.

Ex-Incident Responders Sentenced for Ransomware Extortion Scheme

Two former cybersecurity pros, Ryan Clifford Goldberg and Kevin Tyler Martin, have been sentenced to four years in prison for using their specialized knowledge to orchestrate a string of devastating ransomware attacks, extorting victims instead of protecting them. The pair, who once worked in incident response, now face the consequences of their crimes.

Analyst 207
Modern workspace with a computer on a clutter-free desk, surrounded by minimal office decor.

Malware Worms Into SAP, Intercom and Lightning Developer Tools

Malicious actors struck SAP's JavaScript and cloud application development ecosystem on April 29, releasing poisoned versions of four widely-used npm packages that receive a staggering 572,000 weekly downloads. The compromised packages, which included mbt, @cap-js/db-service, @cap-js/postgres, and @cap-js/sqlite, were published in a brief window of just two hours.

Analyst 207
Formal hearing room with officials seated at a table, daylight through tall windows, and a podium in the scene.

US Cyber Command Warns of Election Interference Threats

Get ready for a déjà vu: US Cyber Command warns that foreign interference is likely to disrupt the midterm elections, just like we've seen in the past. Army Gen. Joshua Rudd's warning to the Senate Armed Services Committee is a stark reminder that countries like Russia, China, and Iran are actively trying to undermine our democracy.

Analyst 207
Hospital staff member in scrubs looks concerned while reviewing patient chart on laptop in busy emergency department with…

Ransomware Attacks on Hospitals Target Patient Care, Spark Calls for Tougher Stance

Hospitals are under attack - literally. Last year, a staggering 460 ransomware attacks hit American hospitals and healthcare systems, causing 47 patient deaths, diverted ambulances, and canceled surgeries.

Analyst 207
Office worker sits at desk with laptop and papers, surrounded by ordinary office atmosphere.

Phishing campaigns increasingly harness AI to evade detection

Phishing campaigns are getting smarter by the minute, with a whopping 86% of recent attempts leveraging AI to sneak past detection. This marks a significant jump from just two years ago, when AI was used in 80% of phishing ops.

Analyst 207
Modern office setting with laptop and notepad in foreground, blurred workstations in background.

Phishing Kit Bluekit Incorporates AI to Streamline Attacks

Meet Bluekit, a cutting-edge phishing kit that's revolutionizing the game with an AI Assistant panel, pairing traditional templates with advanced AI models to help cybercriminals quickly draft campaign materials. This innovative tool is streamlining attacks, making it easier for malicious actors to launch sophisticated phishing campaigns.

Analyst 207
French government officials gather around a table with documents in a dimly lit office.

French Teen Suspected in Mega-Breach at Secure Document Agency

A massive cyber security breach at France's secure document agency, ANTS, has led to the theft of 12-18 million lines of sensitive data, which was then offered for sale online. A 15-year-old French teen has been detained in connection with the leak, prompting the Paris Public Prosecutor's Office to launch a judicial investigation.

Analyst 207
A cluttered office workspace with laptop and papers on a desk in a brightly-lit room.

Silver Fox APT Targets Russia, India with ABCDoor Backdoor

Over 1,600 malicious emails, disguised as tax-audit notices, were sent to targets in India and Russia between January and February 2026, aiming to trick recipients into downloading a backdoor or clicking on a malicious link. The cleverly crafted phishing campaign unfolded in two waves, using PDFs and archives to spread the ABCDoor backdoor.

Analyst 207