Emerging Threats

SAP npm Packages Compromised in Supply-Chain Attack
Security researchers have uncovered a supply-chain attack that compromised four official SAP npm packages, allowing attackers to extract sensitive secrets from CI runner memory. The affected packages, which support SAP's Cloud Applications, have been deprecated on NPM and users are urged to update to secure versions.

FBI Disrupts Global Crypto Scam Network
In a massive global crackdown, US and international authorities have dismantled a notorious network of cryptocurrency scam centers, arresting at least 276 individuals across the Middle East and Southeast Asia. This historic operation marks one of the largest US-assisted enforcement efforts against transnational cybercrime networks to date.

WordPress Plugin Exposes 70,000 Sites to Backdoor Vulnerability
A shocking security vulnerability has been uncovered in a popular WordPress plugin, leaving over 70,000 sites open to backdoor attacks that can inject malicious code on demand. The issue was discovered in the Quick Page/Post Redirect plugin, which was infected with a hidden backdoor five years ago.

Hackers exploit Qinglong flaws for cryptomining deployments
Hackers are taking advantage of two major flaws in the Qinglong open-source task scheduler, CVE-2026-3965 and CVE-2026-4047, which can be combined to gain remote control of vulnerable systems. These authentication-bypass vulnerabilities affect Qinglong versions 2.20.1 and older, and have been exploited for cryptomining deployments.

UK Biobank Data Surfaces for Sale on Alibaba Amid Security Probe
UK Biobank data was mysteriously listed for sale on Alibaba, but thankfully, the listings were swiftly removed with the help of the UK and Chinese governments, and no sales were made. The sensitive data, which includes genomic information, health records, and medical imaging, had been shared with researchers but was de-identified to protect participants' identities.

Microsoft Patch Fails to Quell Russian Spy Exploitation of Windows Flaw
Microsoft's latest patch isn't enough to stop Russian spies from exploiting a Windows flaw, leaving sensitive information vulnerable to exposure. The incomplete fix is linked to a previously patched vulnerability from February, highlighting the urgent need for a more robust solution.

Ukrainian Police Disrupt Roblox Account Hacking Ring
Ukrainian police have cracked down on a massive Roblox account hacking ring, arresting three suspects who hijacked over 610,000 accounts and resold them for a staggering $225,000 profit. The bust in Lviv also yielded a haul of $35,000 in cash and dozens of digital devices.

Malware Targets SAP npm Packages in Supply Chain Attack
A new supply-chain attack campaign, dubbed mini Shai-Hulud, is targeting SAP-related npm packages, delivering credential-stealing malware that threatens JavaScript and cloud applications. This sneaky attack puts sensitive data at risk, and experts are warning of a potentially massive impact.

North Korea Targets Developers with AI-Generated npm Malware
Security researchers have uncovered a sneaky malware campaign targeting developers, involving a malicious npm package called @validate-sdk/v2 that's designed to steal sensitive secrets, including crypto-wallet credentials. This tainted package, linked to a North Korean threat actor, was cleverly disguised as a utility SDK for legitimate tasks like hashing and validation.

Ransomware Drives 90% of Manufacturing Cyber Losses
Ransomware is wreaking havoc on the manufacturing sector, responsible for a staggering 90% of total cyber losses - despite accounting for just a small fraction of claims. When ransomware strikes, the financial blow is severe, highlighting the urgent need for robust security measures.

Police Disrupt €50 Million Crypto Investment Fraud Ring
A massive €50 million crypto investment fraud ring has been dismantled thanks to a joint investigation by Austrian and Albanian authorities, supported by Europol and Eurojust, resulting in the arrest of 10 suspects and the seizure of cash and electronic devices. The alleged scammers, operating from call centres in Albania, left a trail of financial devastation across Italy, Germany, Greece, Spain, Canada, and the UK.

AI-Assisted Code Targets Crypto Wallets via Malicious npm Dependency
Researchers have uncovered a sneaky malicious npm campaign, dubbed PromptMink, linked to North Korean hackers Famous Chollima, which targets crypto developers with fake utility packages that secretly steal sensitive info and funds. The campaign's clever tactics even involve an AI-assisted code commit to fly under the radar.

OAuth Breach Risks Expose AI-Driven Enterprise Vulnerability
A single misstep with a trial AI tool led to a major breach: a Vercel employee's casual OAuth grant to Context.ai created a lasting vulnerability that attackers exploited when Context.ai was compromised. This incident highlights the alarming ease with which AI-driven tools can become enterprise security weak spots.

Cybercriminals Exploit 2.9 Billion Compromised Credentials
Imagine 2.9 billion personal login details floating around in the dark corners of the internet, vulnerable to exploitation by cybercriminals - that's the staggering reality revealed by a recent threat intelligence analysis. This massive cache of compromised credentials, tracked globally in 2025, is a goldmine for hackers leveraging stolen logins, malware, and AI to wreak havoc.

Vect Ransomware Exposes Flaw, Turns into Data-Destroying Wiper
Researchers uncovered a critical flaw in Vect Ransomware that unexpectedly turns it into a data-destroying wiper, permanently destroying files over 128KB instead of encrypting them. This shocking misfire stems from a faulty ChaCha20‑IETF implementation that strips away crucial security protections.

GoDaddy Domain Transfer Exposes Non-Profit to Security Risks
A shocking security breach occurred when a 27-year-old domain was transferred from a GoDaddy account to another customer without any authentication checks, putting a non-profit at risk. The alarming transfer was completed in just four minutes, raising serious concerns about GoDaddy's domain transfer process.

CISA Flags Actively Exploited ConnectWise, Windows Flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged two major vulnerabilities, including a critical flaw in ConnectWise ScreenConnect and a Microsoft Windows Shell bug, as actively exploited by hackers. These flaws could allow attackers to execute remote code, access confidential data, and compromise critical systems.

ClawHub Skills Co-opt AI Agents in Secret Crypto Mining Operation
Meet ClawSwarm, a mysterious crypto mining operation that masquerades as a collection of harmless OpenClaw skills, with 9,800 downloads and counting. Researchers uncovered thirty suspicious skills published by a single user, "imaflytok", on ClawHub, a registry and marketplace for OpenClaw skills.

LiteLLM SQL Flaw Exploited 36 Hours After Disclosure
A critical SQL injection flaw, CVE-2026-42208, was exploited just 36 hours after its disclosure, putting vulnerable LiteLLM versions at risk of unauthorized database access. The bug, with a CVSS score of 9.3, allows unauthenticated callers to reach a vulnerable database query through the proxy's error-handling path.

Hackers Exploit LiteLLM SQL Flaw for Sensitive Data Access
Within just 36 hours of being publicly disclosed, a critical SQL injection flaw in LiteLLM, known as CVE-2026-42208, was actively exploited by hackers, allowing them to access sensitive data without authentication. This alarming vulnerability highlights the importance of swift patching, with LiteLLM version 1.83.7 now available to fix the issue.

VECT 2.0 Ransomware Exploits Flaw to Permanently Destroy Large Files
VECT 2.0 ransomware has a devastating flaw that can permanently destroy large files, including routine documents and databases, by exploiting a bug in its encryption process. This flaw kicks in even for files as small as 128 KB, making it a serious threat to valuable data.

Russia Targets Signal Users in Germany with Social Engineering Hacks
Stay vigilant, especially when it comes to trusted messaging apps like Signal - a recent wave of social-engineering attacks in Germany targeted government officials, exploiting user trust rather than any technical flaw. Signal has assured users that its encryption and infrastructure remain secure, but warns that these types of attacks can still compromise user safety.

Vect Ransomware Exposed as Data Wiper, Not Recovery Tool
Meet Vect, a so-called ransomware that's actually a data wiper, making full recovery impossible - even for the attackers themselves. This destructive malware permanently destroys files larger than 128KB, rendering it useless for data recovery and a serious threat to enterprise assets.

Vimeo Breach Exposes User Data After Anodot Hack
Vimeo users, be aware: a recent data breach at analytics company Anodot exposed some of your personal info, including video titles, metadata, and in some cases, email addresses. Fortunately, uploaded video content, account credentials, and payment card info remain safe.