Skip to main content

Emerging Threats

Medical equipment sits in a quiet clinical room with soft daylight, hinting at a potential disruption.

Medtronic Discloses Cyber Breach by ShinyHunters Gang

Medtronic recently reported a cyber breach by the ShinyHunters gang to federal authorities and the SEC, revealing that hackers had infiltrated its corporate IT system. Fortunately, the company has found no evidence that patient safety or electronic connections to customers were compromised.

Analyst 207
Crypto executive looks concerned at laptop with subtle scheduling software on screen.

North Korean Hackers Exploit Fake Zoom Meetings to Target Crypto Executives

North Korean hackers are using a sneaky tactic to target crypto executives: they pose as legitimate meeting attendees, harvesting video and audio to make future scams more convincing. They start by sending Calendly invites for fake catch-up meetings, then swap the link with a fake Zoom or Teams URL to gain their victim's trust.

Analyst 207
US Department of Justice officials gather in a government building to address a cyberespionage case.

US Charges Chinese Hacker in Cyberespionage Case

The US Department of Justice has extradited Chinese national Xu Zewei from Italy to face charges of conducting cyberespionage operations on behalf of China's intelligence services, targeting victims including COVID-19 researchers. Xu's alleged hacking activities, directed by China's Ministry of State Security, spanned over a year, from February 2020 to June 2021.

Analyst 207
Police team examines equipment near cellular tower in downtown area.

Canada Cracks Down on Rogue Cellular Tower Used for Mass Phishing Texts

Imagine receiving a text from your bank or favorite store, but it's actually a sneaky scam - that's what happened in Toronto when a rogue cellular tower started sending out mass phishing texts to unsuspecting users. Canadian authorities cracked down on the culprit in a sting operation dubbed Project Lighthouse.

Analyst 207
Smart meter on a utility pole with blurred details set against a calm daytime city backdrop.

Medtronic, Itron Disclose Breaches by Digital Intruders

Itron sprang into action after detecting an unauthorized break-in on April 13, swiftly notifying law enforcement, and working with cybersecurity experts to investigate and remediate the breach. The company has since confirmed that it has prevented any further unauthorized activity within its corporate systems.

Analyst 207
Brightly-lit retail setting with a point-of-sale terminal in the foreground, hinting at unease.

BlackFile Targets Retail, Hospitality with Extortion Attacks

Meet BlackFile, a notorious extortion group wreaking havoc on the retail and hospitality sectors with high-stakes attacks, demanding seven-figure ransoms from its victims. With a modus operandi that includes impersonation and voice-phishing, this threat actor is using pressure tactics to get what they want.

Analyst 207
Residential home scene with blurred mailman, stack of letters and ADT logo, conveying personal and neighborhood atmosphere.

ShinyHunters Breach Exposes 5.5M ADT Customers' Data

A massive data breach at ADT has exposed the sensitive information of 5.5 million customers, including names, addresses, phone numbers, and email addresses, which is now being tracked by breach-tracking service Have I Been Pwned. This incident highlights the importance of staying vigilant about your personal data security.

Analyst 207
Developer workstation with code on screen in a clean, minimalist environment.

Checkmarx Breach Exposes GitHub Repository Data on Dark Web

Checkmarx revealed that a security breach, linked to a March 23 supply chain attack, exposed sensitive GitHub repository data, which has now surfaced on the dark web. The incident has been contained, with no customer data compromised, as the affected repository was separate from Checkmarx's customer production environment.

Analyst 207
Hospital corridor with medical staff, laptop and device in foreground.

Medtronic Breach Exposes Risks in Medical Tech Sector

The recent Medtronic data breach highlights a glaring vulnerability in the medical tech sector, with phishing attacks like this one proving that many organizations are still granting employees far more access than they need. Medtronic has confirmed the breach was contained within its corporate IT systems, with no evidence it impacted patient safety or product operations.

Analyst 207
Cluttered developer workstation with laptop and monitor in a home office setting.

PyPI Package elementary-data Compromised to Steal Developer Data

A malicious release of the popular elementary-data package on PyPI, which has over 1.1 million monthly downloads, allowed an attacker to steal developer data through a sneaky backdoor. This widely-used open-source tool for data observability in dbt pipelines became a prime target for the secrets-stealing campaign.

Analyst 207
Stealthy cyber attack scene on a laptop screen in a lab setting.

Fast16 Malware Exposes Pre-Stuxnet Cyber Warfare Roots

Meet fast16, a sneaky malware framework that's been around since 2005 - five years before the infamous Stuxnet - and is designed to quietly sabotage high-precision software by subtly altering numerical results. This stealthy approach can cause systems to fail, wear out faster, or produce false conclusions, making it a chilling precursor to modern cyber warfare.

Analyst 207
Residential building with open door and scattered personal items, hinting at vulnerability.

ADT Breach Exposes 5.5 Million in ShinyHunters Hack

A massive data breach at ADT has put 5.5 million people's personal info at risk, including names, phone numbers, addresses, and sensitive details like dates of birth and Social Security numbers. The breach, linked to the ShinyHunters extortion group, has left millions vulnerable to potential identity theft and scams.

Analyst 207
Secure facility entrance with subtle tech infrastructure in background.

Itron Discloses Cyberbreach, Launches Investigation

Itron has launched a swift investigation into a recent cyber security breach, taking immediate action to assess, mitigate, and contain the incident with the help of external advisors and law enforcement. The company currently believes the breach will not have a significant impact on its operations.

Analyst 207
Rows of computer servers and networking equipment in a clean, well-lit corporate IT systems area.

Medtronic Breach Exposes 9 Million Records to Hackers

Medtronic has confirmed a data breach affecting 9 million records, but thankfully, the hackers didn't compromise critical systems that could impact patient safety or product operations. The company's corporate IT systems were the target, and Medtronic assures that business operations, including manufacturing and distribution, remain unaffected.

Analyst 207
Finance director on video call with multiple faces on screen, looking concerned.

Deepfake Voice Attacks Expose Vulnerabilities in Corporate Defenses

With just three seconds of a CEO's voice online, your company is vulnerable to a deepfake voice attack - and it only takes one convincing call to compromise your defenses, as seen in a string of high-profile heists. Make sure your team knows how to spot and stop these sophisticated scams before it's too late.

Analyst 207
Cluttered software development workspace with VS Code on a central computer screen.

Researchers Expose 73 Fake VS Code Extensions Spreading GlassWorm v2 Malware

Malicious VS Code extensions are putting developers at risk, with 73 fake extensions discovered spreading GlassWorm v2 malware, allowing attackers to stealthily retrieve and execute payloads after activation. These extensions act as loaders, using obfuscated JavaScript to achieve the same malicious outcomes as their binary-based counterparts.

Analyst 207
Empty Russian office network room with rows of computer servers and networking equipment.

PhantomCore Exploits TrueConf Flaws to Breach Russian Networks

Researchers Daniil Grigoryan and Georgy Khandozhko revealed that PhantomCore attackers exploited a chain of three TrueConf Server vulnerabilities, including insufficient access control and file reading flaws, to breach Russian networks. This sophisticated attack highlights the importance of addressing these critical vulnerabilities to protect against potential threats.

Analyst 207
Blurred smart home device on a table amidst a residential setting hints at a security breach.

ADT Breach Exposes Customer Data, ShinyHunters Claim Responsibility

ADT confirmed a data breach on April 20, after discovering unauthorized access to sensitive customer and prospective-customer information, which was swiftly shut down and investigated. The breach exposed key personal details, but thankfully, payment information and customer security systems remained unaffected.

Analyst 207
Person sitting at desk with laptop in a home office or public workspace setting.

Microsoft Probes Outlook.com Outage as Sign-in Failures Mount

Microsoft is investigating an Outlook.com outage that's causing sign-in failures and unexpected sign-outs for some users, citing possible issues with client sign-in scenarios. The company is working to identify the root cause, but hasn't yet shared details on the number of affected users or regions.

Analyst 207
Rows of server racks in a brightly-lit data center with equipment slightly askew, hinting at unauthorized access.

ADT Confirms Cyber Intrusion After ShinyHunters Extortion Attempt

ADT confirmed a cyber intrusion on April 20, swiftly isolating the breach and collaborating with incident responders and law enforcement to contain the damage. The compromised data included sensitive information like names, phone numbers, and addresses, as well as dates of birth and partial Social Security numbers for a smaller subset of individuals.

Analyst 207
Researcher examines smartphone with fake CAPTCHA webpage, surrounded by investigation documents.

Cybersecurity Researchers Expose Global SMS, Crypto Fraud Ring

Beware of fake CAPTCHAs that can drain your wallet! A cunning SMS scam routes victims to bogus web pages, tricking them into sending costly texts to over 50 international destinations.

Analyst 207
Person interacting with a blurred payment terminal in a retail setting.

BlackFile Group Launches Vishing Attacks on Retail, Hospitality Firms

Retail and hospitality firms are under siege from a financially motivated threat group, known as BlackFile Group, that's launching vishing attacks to extort money, with a campaign that has been quietly escalating since February 2026. This persistent threat uses no custom malware, making it a stealthy and formidable foe.

Analyst 207
Rows of computer servers and equipment in a calm, professional data center.

Itron Breach Exposes Internal IT Network Vulnerability

Itron recently disclosed that its internal IT network was breached by an unauthorized third party, prompting swift action to contain and mitigate the incident. The company quickly activated its cybersecurity response plan and notified law enforcement, successfully blocking the unauthorized activity with no reported follow-up attempts.

Analyst 207
Laptop screen displays Microsoft Teams conversation in bright office setting.

Microsoft Teams Used to Deploy Sophisticated Snow Malware

Cyber attackers have cleverly used Microsoft Teams to deploy a sophisticated malware suite, dubbed Snow, by tricking victims into installing a fake anti-spam patch that ultimately led to prolonged access, credential theft, and domain compromise. They started by creating a sense of urgency through email bombing, then followed up with a direct message on Microsoft Teams.

Analyst 207