Emerging Threats

Education Sector Grapples with 63% Surge in Cyber-Attacks
The education sector is facing a daunting reality: a 63% surge in cyber-attacks is putting institutions at risk, threatening the very openness and collaboration that define higher education. Can schools and universities keep pace with the growing threat?

Vercel Breach Exposes Additional Customer Accounts
A recent Vercel breach exposed additional customer accounts after a malicious chain of events began with a compromised employee account at Context.ai, which was likely triggered by a simple online search for Roblox scripts. The breach highlights the risks of malware distribution and token theft, with threat intel pointing to a sophisticated attack targeting valuable keys and account credentials.

Eset Exposes Chinese Hackers' Careless Backdoor Tactics
Chinese hackers have been caught off guard by their own carelessness, leaving behind a digital trail that exposed their previously undetected backdoor tactics. Researchers uncovered over 9,000 messages revealing the attackers' testing systems and habits, leading to the identification of a Chinese nation-state actor dubbed GopherWhisper.

China-Linked GopherWhisper Targets Mongolian Government Systems with Go Backdoors
A China-linked cyber group, dubbed GopherWhisper, has been targeting Mongolian government systems with a suite of Go-based backdoors, infecting at least 12 systems and potentially dozens more. The attackers used clever tactics, routing command-and-control traffic through compromised Discord and Slack servers.

Researchers Expose AI Agents to Malicious Prompt Injection Payloads
Imagine a browser AI that can summarize web pages, but with a hidden vulnerability that allows malicious instructions to be embedded and executed - a newly discovered threat that security researchers are warning deserves our attention. Forcepoint researchers have uncovered 10 real-world examples of indirect prompt injection payloads designed to subvert AI agents and wreak havoc.

npm Worm Targets Dev Environments, Exploits Supply Chain
A newly discovered npm malware attack has infected multiple packages, using sneaky tactics like install-time execution and credential theft to compromise developer environments and spread through the supply chain. This self-propagating malware strain appears to be targeting specialized developer workflows, putting a spotlight on vulnerabilities in the software development process.

Anthropic's Mythos Model Exposes Limited Capabilities
Anthropic's highly anticipated Mythos model, designed to proactively identify vulnerabilities, has been compromised - with a small group of individuals reportedly gaining unauthorized access to the preview through a third-party vendor environment. The incident has raised concerns about the model's limited capabilities to protect itself from exploitation.

AI-Driven Cyberthreats Expose Need for Advanced Threat Intelligence
In today's hyper-fast cyber threat landscape, operating at machine speed is no longer a choice - it's a necessity, as expert Tom Kellermann warns, highlighting the urgent need for advanced threat intelligence to combat AI-driven attacks.

Mirai Campaign Exploits RCE Flaw in Obsolete D-Link Routers
In early March 2026, Akamai's Security Incident Response Team detected a Mirai botnet campaign exploiting a critical vulnerability, CVE-2025-29635, in outdated D-Link routers, enlisting vulnerable devices into a botnet through automated attacks. This flaw in D-Link DIR-823X series routers puts countless devices at risk of being hijacked.

Discord Group Exploits Claude's Secret AI Model
A fresh controversy is brewing over Anthropic's highly touted AI model, Mythos, after a Discord group exploited a secret pathway to access the powerful technology. The AI Security Institute had praised Mythos as a significant leap forward, but its limited release to select partners like Nvidia and Apple has raised new questions about access control.

Kyber Ransomware Targets Windows, VMware with Post-Quantum Encryption
Meet the Kyber Ransomware, a potent threat that targets both Windows and VMware environments with cutting-edge, post-quantum encryption. This sophisticated malware has been found to strike multiple systems at once, as seen in a March 2026 incident where two variants were deployed on the same network.

Malicious Docker Images Compromise Checkmarx Supply Chain
Malicious Docker images compromised the Checkmarx supply chain by embedding a tampered KICS binary that secretly collected and sent sensitive data to an external endpoint. This sneaky data-exfiltration risk put users at risk, thanks to an altered scan report generated by the poisoned image.

Malware Worm Exploits npm Packages to Hijack Developer Tokens
Meet CanisterSprawl, a sneaky self-propagating worm that's compromising npm packages and using stolen developer tokens to spread its reach. This malware goes beyond just stealing credentials, turning one infected environment into a web of additional package compromises.

Breach Exposes Anthropic's AI Model Vulnerability
A shocking security breach has exposed a vulnerability in Anthropic's advanced AI model, Mythos, allowing unauthorized users to gain access by simply changing a model name. This incident raises serious concerns about the safety and reliability of cutting-edge AI technology.

MacOS Attacks Evolve, Exploiting Native Tools for Stealth
As macOS use surges in enterprise environments, accounting for over 45% of organizations, attackers are getting creative - exploiting native tools like Remote Application Scripting, Terminal, and AppleScript to stealthily run code, move undetected, and evade security measures. Cisco Talos warns that these tactics allow hackers to issue malicious instructions across processes and systems without triggering conventional monitoring.

Harvester Expands Linux Arsenal with GoGra Backdoor in South Asia
Harvester's Linux arsenal just got a boost with the deployment of the GoGra backdoor in South Asia, enabling the threat actor to sneak past traditional network defenses by hijacking legitimate Microsoft Graph API and Outlook mailboxes. This latest move is linked to Harvester's earlier espionage campaigns targeting key sectors in the region.

Hackers Expose 19M Records in French Government Agency Breach
A recent data breach at France's Agence nationale des titres sécurisés (ANTS) may have compromised 19 million records, but thankfully, no action is required from users - for now. The agency is notifying affected individuals and advising them to stay vigilant for suspicious contacts.

Spanish Police Disrupts $4.7M Manga Piracy Platform, Arrests Four
In a major crackdown on piracy, Spanish police have shut down a massive manga piracy platform that had been illegally providing access to millions of copyrighted works since 2014, and arrested four individuals in connection with the operation. The platform's systematic infringement had amassed a huge following, but ultimately led to the authorities taking action.

Cybercrime Shifts to Caller-as-a-Service Model
US elderly citizens alone lost a staggering $3.4B in 2023 to phone-based scams, highlighting the alarming rise of a highly organized and profitable fraud economy. This Caller-as-a-Service model has made it easier for scammers to specialize and scale their operations, putting even more people at risk.

CISOs Face New Era of AI-Driven Threats
The old security measures are no longer enough - a 'passed' audit only tells you where you've been, not where you are now, in a threat landscape rapidly changed by AI-driven attacks. Advanced AI tools can now discover and exploit weaknesses at unprecedented speeds and scales, outpacing traditional security methods.

Phishing Attacks Exploit Email Blind Spots with Silent Subject Lines
Phishing attacks are on the rise, with a 13.9% surge in January and February, followed by a 7% increase in March, and cybercriminals are getting sneaky by using empty subject lines to bypass email defenses and pique human curiosity. By ditching the subject line, attackers are exploiting a blind spot that can trick both automated filters and human instincts.

npm Ecosystem Targets New Supply-Chain Attack to Steal Auth Tokens
Researchers have uncovered a sneaky supply-chain worm that can hijack auth tokens and spread malware through the npm ecosystem, putting countless packages at risk. This stealthy threat can inject itself into every package it can publish, creating a ripple effect of compromised code.

France's ID Agency Probes Breach Claiming 19M Records Stolen
A massive data breach at France's ID agency may have exposed a staggering 19 million records, putting the personal info of nearly a third of the country's population at risk. The breach, detected on April 15, involves the theft of sensitive data, including login IDs, names, email addresses, and dates of birth.

Cross-App Permissions Expose Hidden Risks in AI-Driven SaaS Environments
Imagine a single security slip-up exposing 1.5 million API tokens and 35,000 email addresses, leaving AI agents and their users vulnerable to hijacking and misuse. The recent Moltbook breach reveals the hidden risks of cross-app permissions in AI-driven SaaS environments.