Skip to main content

Emerging Threats

Server room with equipment racks and a workstation terminal displaying a blurred interface.

Hackers Exploit LiteLLM SQL Flaw for Sensitive Data Access

Within just 36 hours of being publicly disclosed, a critical SQL injection flaw in LiteLLM, known as CVE-2026-42208, was actively exploited by hackers, allowing them to access sensitive data without authentication. This alarming vulnerability highlights the importance of swift patching, with LiteLLM version 1.83.7 now available to fix the issue.

Analyst 207
Disorganized file storage room with scattered, torn documents on floor.

VECT 2.0 Ransomware Exploits Flaw to Permanently Destroy Large Files

VECT 2.0 ransomware has a devastating flaw that can permanently destroy large files, including routine documents and databases, by exploiting a bug in its encryption process. This flaw kicks in even for files as small as 128 KB, making it a serious threat to valuable data.

Analyst 207
European cityscape with technology hint, person walking in distance.

Russia Targets Signal Users in Germany with Social Engineering Hacks

Stay vigilant, especially when it comes to trusted messaging apps like Signal - a recent wave of social-engineering attacks in Germany targeted government officials, exploiting user trust rather than any technical flaw. Signal has assured users that its encryption and infrastructure remain secure, but warns that these types of attacks can still compromise user safety.

Analyst 207
Destroyed office equipment and papers under flickering fluorescent lighting.

Vect Ransomware Exposed as Data Wiper, Not Recovery Tool

Meet Vect, a so-called ransomware that's actually a data wiper, making full recovery impossible - even for the attackers themselves. This destructive malware permanently destroys files larger than 128KB, rendering it useless for data recovery and a serious threat to enterprise assets.

Analyst 207
Brightly-lit data center interior with servers and storage units symbolizing secure user data.

Vimeo Breach Exposes User Data After Anodot Hack

Vimeo users, be aware: a recent data breach at analytics company Anodot exposed some of your personal info, including video titles, metadata, and in some cases, email addresses. Fortunately, uploaded video content, account credentials, and payment card info remain safe.

Analyst 207
Gaming setup with Minecraft on screen, surrounded by peripherals, with a messy room and blurred laptop screen in the…

LofyGang Revives With Minecraft-Focused LofyStealer Campaign

Meet LofyGang, a notorious threat actor that's back in the game with a sneaky new campaign called LofyStealer, targeting Minecraft fans with malware disguised as a hack called 'Slinky'. This Brazil-based group has a history of infiltrating gaming communities and digital entertainment services.

Analyst 207
Staff member looks concerned at laptop while customers wait at car rental office counter.

AI Agent Deletes Production Data in 9 Seconds

In a shocking nine-second mistake, an AI agent deleted three months' worth of production data, including reservations and customer records, for a car-rental software startup, causing chaos for customers and the business. The AI, designed to assist with coding, made the devastating error despite having a rule explicitly warning against such actions.

Analyst 207
Law enforcement officials gather outside a government building with daylight streaming through tall windows.

US Charges Scattered Spider Hacker with Extortion, Cyber Intrusion

A 19-year-old hacker, known online as "Bouquet," has been arrested in Finland and charged in the US with extortion and cyber intrusion as a key player in the notorious Scattered Spider hacking collective. The dual US and Estonian citizen was caught at Helsinki airport while trying to flee to Japan.

Analyst 207
Corporate office interior with computer screens, hinting at data breach investigation.

Medtronic Probes Corporate Data Breach After ShinyHunters Claims

Medtronic is investigating a corporate data breach after a cybercrime group called ShinyHunters claimed to have stolen over nine million records, including personal info and internal company data. The company confirmed that an unauthorized party accessed certain internal systems, sparking a probe into the incident.

Analyst 207
Large, empty development environment with rows of code on sleek computer screens against a neutral background.

Checkmarx GitHub Data Leaked by LAPSUS$ Hackers

Checkmarx confirmed that hackers from the LAPSUS$ group breached its GitHub repository on March 23, 2026, and published stolen data on April 22, after a series of supply-chain and credential-theft events. The attackers used the access to publish malicious code to certain artifacts, compromising the integrity of Checkmarx's software development process.

Analyst 207
Cluttered office workstation with laptop and external hard drive amidst scattered papers and supplies, conveying disruption…

VECT 2.0 Ransomware Exposes Flaw, Irreparably Destroys Large Files

Meet VECT 2.0, a malicious ransomware that doesn't just hold your files hostage - it destroys them, leaving you with no way to recover even if you pay up. This cunning malware wreaks havoc on large files across Windows, Linux, and ESXi hosts, causing irreversible damage.

Analyst 207
Blurred laptop on a cluttered office desk with postal equipment in the background.

Pitney Bowes Hit by 8.2M Email Address Leak in ShinyHunters Breach

A massive data leak has hit Pitney Bowes, with 8.2 million unique email addresses compromised in a breach claimed by the notorious cybercrime group ShinyHunters. The stolen data also includes names, phone numbers, physical addresses, and even company employment records.

Analyst 207
Dark alleyway with defaced computer screen displaying bold message.

Ransomware Groups Clash in Turf War, Exposing Each Other's Operations

In a shocking display of cyber turf warfare, ransomware groups are clashing and exposing each other's operations, with one group, KryBit, firing back at 0APT with a defiant message. The online battle began when 0APT claimed to have taken down three rival groups, but its boasts only sparked a retaliatory strike.

Analyst 207
People work on computers in a dimly lit internet cafe or office surrounded by networking equipment.

Threat Actors Formalize Operational Security Playbook

Cybercrime players are now treating operational security as a sophisticated game-changer, and it's time for you to level up your security strategy beyond just using VPNs. A battle-tested three-tier infrastructure model has emerged, separating exposure, execution, and monetization to safeguard high-stakes operations.

Analyst 207
Person walks into a courtroom with a blurred government seal in the background.

China Hacker Extradited Over Silk Typhoon Cyber Attacks

In a major breakthrough, 34-year-old Chinese national Xu Zewei has been extradited to the US to face charges for his alleged role in the massive Silk Typhoon cyber attacks that hit over 12,700 US organizations. Xu appeared in a Houston federal court over the weekend, facing serious charges including wire fraud, unauthorized computer access, and identity theft.

Analyst 207
Cluttered desk with laptop and cybersecurity notes in a brightly-lit corporate or research setting.

AI Accelerates Exploits, Forces New Breach Playbooks

The game-changing capabilities of AI models like Anthropic's Claude Mythos have drastically shrunk the exploit window, allowing them to uncover vulnerabilities in minutes that would take human experts weeks or even hours to detect. This seismic shift is forcing organizations to rethink their approach to vulnerability management and incident response.

Analyst 207
Brightly-lit office lobby with a hint of unease, generic multinational company setting.

Scattered Spider Targets Global Firms with Identity-Driven Attacks

Scattered Spider is on the prowl, launching identity-driven attacks on major global firms across various industries, from retail and hospitality to telecom, insurance, and airlines. Get insider expert advice from Dr. Torsten George on how to outsmart this sophisticated cybercrime collective.

Analyst 207
Formal courthouse scene with stern atmosphere, blurred figures in background.

China's Silk Typhoon Hacker Extradited to US Over COVID Cyberattacks

A Chinese hacker, Xu Zewei, has been extradited to the US from Italy for masterminding a series of devastating cyberattacks on US universities, immunologists, and virologists working on COVID-19 vaccines, treatments, and testing between 2020 and 2021. He faces charges of wire fraud and conspiracy for his role in the attacks.

Analyst 207
Worker looks concerned at laptop screen displaying fake Zoom meeting in modern office.

North Korean Hackers Exploit Crypto Firms with AI-Driven Zoom Lures

North Korean hackers launched a massive spear-phishing campaign, targeting over 100 crypto organizations worldwide with cleverly crafted Zoom lures and AI-generated deepfakes. They used fake calendar invites and typosquatted meeting links to gain access and exfiltrate sensitive data in a matter of minutes.

Analyst 207
Windows desktop with file explorer open, showing a malicious file, connected to a network, in a blurred office background.

Microsoft Confirms Active Exploitation of Windows Shell Flaw

Microsoft warns of a high-severity Windows Shell flaw that's being actively exploited by attackers, allowing them to spoof victims over a network by simply sending a malicious file to be executed. The vulnerability, patched in April's Patch Tuesday update, poses a significant threat to users if left unprotected.

Analyst 207
Formal government setting with podium and judicial backdrop, lit by daylight and abstract shapes.

US Charges Chinese National in Silk Typhoon Cyber Attacks

A Chinese national, Xu Zewei, has been extradited to the US from Italy to face charges for his alleged role in the notorious HAFNIUM cyber attacks, a vast intrusion campaign that compromised over 12,700 US organizations. Xu's arrival in US court marks a significant step in holding him accountable for his actions.

Analyst 207
Cluttered developer workstation with laptop, monitors, and notes in a bright office setting.

Supply-Chain Attack Targets Security, Dev Tools with Credential Theft

Malicious hackers are exploiting the very tools developers rely on, including security scanners and password managers, to steal sensitive credentials and gain unauthorized access. This latest supply-chain attack has already hit major players like Checkmarx, compromising their GitHub repository and potentially putting customer data at risk.

Analyst 207
Person sitting at laptop with concerned expression, surrounded by home environment, looking at suspicious email on screen.

Robinhood Flaw Exploited to Send Convincing Phishing Emails

Scammers have found a way to send fake emails that look like they're really from Robinhood, complete with convincing details like unusual IP addresses and partial phone numbers. These phishing emails even appeared to come from Robinhood's official email address, making them super convincing.

Analyst 207
Laptop screen displays code editor surrounded by papers and notes on a simple desk.

GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions

Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.

Analyst 207