Skip to main content

Emerging Threats

Industrial control system interface on a computer screen with blurred machinery in the background.

Researchers Uncover 'fast16' Malware Targeting Engineering Software Years Before Stuxnet

Researchers have uncovered a long-forgotten malware, fast16, that was designed to sabotage engineering software, beating even the infamous Stuxnet by at least five years. This ancient cyber threat, dating back to 2005, was engineered to spread rapidly and produce inaccurate calculations across entire facilities.

Analyst 207
Person at desk looks at laptop with Microsoft Teams on screen, background webpage blurred.

Google Exposes Microsoft Teams Phishing Campaign Using Custom Snow Malware

Beware of scammers posing as helpdesk heroes! They'll flood your inbox with spam, then reach out on Microsoft Teams with a fake fix that actually steals your password using custom Snow malware.

Analyst 207
Modern tech facility with large glass window overlooking blurred cityscape.

US Warns of China’s Industrial-Scale AI Model Theft Campaigns

The White House has sounded the alarm on China's large-scale AI model theft campaigns, warning that stolen models, although imperfect, can still pose a significant threat. Unauthorized AI model distillation can enable foreign entities to develop knockoff versions with potentially damaging consequences.

Analyst 207
Busy airport terminal in Central or South America with laptop on luggage cart.

TGR-STA-1030 Intensifies Espionage Push in Central, South America

The threat group TGR-STA-1030 is ramping up its espionage efforts in Central and South America, with sustained and widespread activity observed across multiple countries since February. This persistent campaign has recently intensified, with a heavy focus on regions within Central and South America.

Analyst 207
Cluttered developer workstation with laptop, notes, and coffee cups, blurred cityscape in background.

npm Ecosystem Faces Rising Threat from Sophisticated Malware Campaigns

The npm ecosystem's security has reached a critical turning point, with sophisticated malware campaigns on the rise and a new baseline of threats emerging since September 2025. Malicious actors are now exploiting developer trust, transforming nuisance attacks into high-consequence supply-chain threats.

Analyst 207
Blurred customer information sheet on a cluttered office desk with scattered papers and a pen.

ADT Confirms Data Breach After ShinyHunters Extortion Threat

ADT confirmed a data breach after a threat from hackers known as ShinyHunters, who demanded an extortion payment. The breach exposed sensitive customer info, including names, phone numbers, addresses, and in some cases, dates of birth and Social Security numbers.

Analyst 207
Rows of networking gear on racks in a federal network operations center with a hint of concern.

CISA Warns of Persistent Cisco Backdoor on Federal Networks

The Cybersecurity and Infrastructure Security Agency (CISA) has detected a sneaky backdoor, dubbed Firestarter, lurking on federal networks, which may not have been fully eliminated by Cisco's recent patches. Federal agencies are now on high alert, urged to hunt for this stealthy malware that could compromise their networks.

Analyst 207
Cisco firewall device on a network equipment rack in a dimly lit data center.

Firestarter Malware Evades Cisco Firewall Updates, Persists Across Reboots

A custom backdoor called Firestarter has been discovered evading Cisco firewall updates and persisting across reboots, posing a significant threat to cybersecurity. This sophisticated malware is attributed to a threat actor linked to cyberespionage campaigns, including the notorious ArcaneDoor operation.

Analyst 207
Laptop screen displays lines of code on a modern office desk with blurred equipment in the background.

Supply-Chain Attacks Target Software Libraries

Supply-chain attacks are now using automation tools to spread malware at alarming speed, with recent incidents showing malicious code can go live in mere hours and be merged into projects in just minutes. This sinister trend highlights the dark side of modern software development's emphasis on speed and automation.

Analyst 207
Retail customer service desk with blurred computer screen nearby in daytime setting.

BlackFile Targets Retail with Vishing Extortion Tactics

Meet BlackFile, a financially motivated group that's been wreaking havoc on retail and hospitality organizations with a clever vishing extortion tactic, posing as IT support staff to steal data since February 2026. They're using spoofed VoIP numbers and fake Caller ID names to pull off their scams.

Analyst 207
Network equipment and security appliances in a brightly lit industrial control room.

CISA Exposes Persistent FIRESTARTER Backdoor in Cisco Devices

CISA and NCSC have uncovered a sneaky FIRESTARTER backdoor lurking in Cisco devices, allowing hackers to regain control even after patches are applied. This persistent threat can leave devices vulnerable to re-entry, putting your entire network at risk.

Analyst 207
Modern lab setting with computer workstation and subtle industrial background.

US Warns of Coordinated AI Model Extraction Campaigns by Foreign Adversaries

The US government has sounded the alarm on a critical threat: foreign adversaries are launching coordinated, large-scale campaigns to steal American AI capabilities, specifically targeting the distillation of advanced US AI models into smaller, lighter-weight versions. To combat this, the White House is directing federal agencies to collaborate with the private sector to develop best practices for protection.

Analyst 207
Network operations center with computer workstations and equipment showing subtle signs of a security breach.

CISA Uncovers Firestarter Backdoor in Federal Network

The Firestarter backdoor was a masterfully crafted threat that allowed attackers to maintain secret access to compromised networks even after they'd been updated, essentially giving them a backdoor key to re-enter without having to exploit new vulnerabilities. This sneaky tactic left victims vulnerable to repeat attacks, highlighting the need for robust cybersecurity measures.

Analyst 207
NASA employees work at desks with laptops and computers in a well-lit office setting.

NASA Targeted in Chinese Phishing Scheme for U.S. Defense Software

For years, unsuspecting NASA employees and collaborators were duped into sharing sensitive US defense software with a Chinese national masquerading as a colleague, in a brazen phishing scheme that went undetected for years. The scam funneled top-secret aerospace and defense tech to the imposter, violating US export control laws in the process.

Analyst 207
Cruise ship customer service area with desks, chairs, and a large window overlooking a calm sea.

Carnival Breach Exposes 7.5M Emails in Alleged ShinyHunters Hack

A massive data breach at Carnival Corporation has exposed a whopping 7.5 million emails, allegedly at the hands of the notorious ShinyHunters hack group, after failed negotiations between the two parties left customers' sensitive information vulnerable. The breach is said to have yielded terabytes of internal corporate data, sparking concerns for customers and the company behind Holland America Line.

Analyst 207
Laptop screen shows an open email message in a brightly-lit office setting.

Zimbra Servers Targeted in Ongoing XSS Attacks

Beware of sneaky phishing emails that can hijack your Zimbra server with just a glance - no clicks or downloads required. A single malicious email can trigger a cross-site scripting attack, thanks to a recently patched vulnerability, CVE-2025-48700.

Analyst 207
Person holding smartphone with scattered papers in foreground, standing in blurred city or coffee shop background.

Malicious Apps Expose Crypto Investors to Seed Phrase Theft on App Store

Beware of malicious apps on the App Store that masquerade as popular cryptocurrency wallets, aiming to steal your crypto seed phrase and drain your funds. These fake apps, uncovered by Kaspersky researchers, can trick you into revealing sensitive information with just a few taps.

Analyst 207
Laptop screen shows blurred PDF as trojanized document is opened in quiet workspace.

Tropic Trooper Exploits SumatraPDF to Deploy AdaptixC2

Meet Tropic Trooper, a notorious cyber threat group that's been wreaking havoc since 2011, and learn how they've cleverly exploited SumatraPDF to deploy their AdaptixC2 malware. Their latest tactic involves using GitHub as a command-and-control platform to target Chinese-speaking individuals in Taiwan, as well as users in South Korea and Japan.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room.

LMDeploy Vulnerability Exploited Within 13 Hours of Disclosure

A critical vulnerability in LMDeploy's vision-language module was exploited in the wild just 13 hours after its disclosure, allowing attackers to access sensitive resources and internal networks. This server-side request forgery flaw, tracked as CVE-2026-33626, affects all versions of the toolkit prior to 0.12.0.

Analyst 207
Developer workstation with laptop and terminal, surrounded by notes and coffee cups, with a blurred cityscape in the…

Malware Targets Developers with Worm-Like Npm Supply Chain Attack

Malware is targeting developers through a sneaky npm supply chain attack, executing malicious code the moment a package is installed, and harvesting sensitive data to spread across ecosystems. Over 6,700 weekly downloads of one affected package show just how widespread the threat could be.

Analyst 207
A researcher examines computer equipment in a dimly lit, cluttered forensics lab.

Researchers Uncover Pre-Stuxnet Cyber-Sabotage Malware

Meet fast16, a stealthy cyber-sabotage malware that went undetected until now, marking a new era in covert statecraft. Discovered by SentinelOne researchers, this silent threat has been hiding in plain sight since 2016.

Analyst 207
Cluttered server room with stacked routers, cables, and wires in dim light.

China Builds Covert Hacker Networks with Compromised Routers

China-nexus cyber actors have dramatically changed their game, ditching solo operations for massive networks of hacked devices - and it's a threat you need to know about. A joint advisory from top cyber agencies worldwide warns of this new tactic, urging vigilance in the face of large-scale cyber attacks.

Analyst 207
Dimly lit telecom hub at night with blurred architecture and infrastructure.

Surveillance campaigns exploit telecom vulnerabilities with commercial tools

Researchers have uncovered a shocking truth: telecom vulnerabilities are being exploited by covert surveillance campaigns using commercial tools, putting global telecommunications security at risk. This alarming trend allows unknown parties to track targets undetected, highlighting a pressing need for tighter regulations.

Analyst 207
Control room of a water treatment plant with a computer workstation in the foreground and blurred equipment in the…

New Malware ZionSiphon Targets Water Plants, Falls Flat

A new piece of malware called ZionSiphon, reportedly targeting Israeli water facilities, has been found to be surprisingly inept, with experts describing it as broken and showing little understanding of its supposed targets. The malware's code includes strings referencing the Israeli water sector and politically charged messaging, but its overall incompetence has downplayed initial alarm.

Analyst 207