Skip to main content

Emerging Threats

Dimly lit server room with a laptop screen displaying sensitive API tokens and credentials.

Cross-App Permissions Expose Hidden Risks in AI-Driven SaaS Environments

Imagine a single security slip-up exposing 1.5 million API tokens and 35,000 email addresses, leaving AI agents and their users vulnerable to hijacking and misuse. The recent Moltbook breach reveals the hidden risks of cross-app permissions in AI-driven SaaS environments.

Analyst 207
Damaged computer equipment and cables in a dimly lit server room.

Lotus Wiper Malware Disrupts Venezuelan Energy Sector

Cybersecurity researchers uncovered a highly destructive malware, known as Lotus Wiper, that was used to disrupt Venezuela's energy sector in a targeted attack. This powerful data wiper was deployed in a series of devastating attacks at the end of 2025 and beginning of 2026.

Analyst 207
Former ransomware negotiator sits contemplative in dimly lit room with laptop and papers.

Former Ransomware Negotiator Pleads Guilty to Aiding BlackCat Cyber Gang

A former ransomware negotiator turned rogue, Angelo Martino has pleaded guilty to aiding the notorious BlackCat cyber gang, betraying his employer and the industry he was meant to serve. By secretly collaborating with BlackCat, Martino launched devastating ransomware attacks, causing harm to innocent victims and lining his own pockets.

Analyst 207
Cluttered server room with laptops, smartphones, and tangled cables, hint of a global map in the background.

Researchers Expose ProxySmart Software Behind Global SIM Farms

Meet ProxySmart, a sneaky software powering "SIM Farm as a Service" operations worldwide, with a massive footprint of 94 phone farms across 17 countries and 19 US states. Its creators, a Belarus-based vendor, have made it easy for operators to run mobile proxy infrastructure at commercial scale.

Analyst 207
Cluttered workspace with Linux terminal and laptop, cityscape outside, surrounded by notes and coffee cups.

Harvester Malware Exploits Microsoft Graph API for Stealthy Linux Attacks

Meet Harvester, a stealthy espionage group believed to be state-backed, that's been secretly targeting telecommunications, government, and IT organizations in South Asia since 2021. Their latest trick? A Linux-capable GoGra backdoor that uses Microsoft Graph API for covert communications.

Analyst 207
Laptop screen displays code with cityscape visible through window in background.

Mustang Panda Expands LOTUSLITE Malware to Target India, Korea

Meet the evolved LOTUSLITE backdoor, now wielding dynamic DNS-based command-and-control over HTTPS, enabling its operators to remotely access and manipulate targeted systems for espionage purposes. This sophisticated malware supports remote shell access, file operations, and session management, a potent toolkit for data collection and access persistence.

Analyst 207
Dimly lit server room with a highlighted server and a shadowy figure working on a laptop amidst cables and equipment.

Unpatched SharePoint Servers Exposed to Ongoing Spoofing Attacks

Over 1,300 Microsoft SharePoint servers are still vulnerable to a spoofing attack, despite a security update being available since last week, leaving them exposed to ongoing exploitation by hackers. This comes after Microsoft warned that the CVE-2026-32201 vulnerability was exploited as a zero-day, and attackers are continuing to abuse it in widespread campaigns.

Analyst 207
Young British man in his mid-twenties sits somberly in a formal setting surrounded by law enforcement officials.

Scotland Hacker Pleads Guilty in Scattered Spider Cybercrime Case

Meet Tyler Robert Buchanan, the 24-year-old mastermind behind the notorious Scattered Spider cybercrime gang, who has pleaded guilty to federal charges of conspiracy and identity theft. With a potential 22-year prison sentence looming, Buchanan's guilty plea marks a major win for law enforcement in the fight against cybercrime.

Analyst 207
Former ransomware negotiator sits in federal courtroom, looking down with hands clasped, surrounded by financial documents…

Former Ransomware Negotiator Pleads Guilty to Extortion Scheme

A former ransomware negotiator has pleaded guilty to masterminding a brazen extortion scheme that raked in a staggering $75.3 million, exploiting his position to secretly collude with ransomware gangs and betray the very companies he was supposed to protect. Angelo John Martino III faces up to 20 years in prison for his role in the conspiracy.

Analyst 207
Dark French landscape with shattered computer screen, scattered papers, and ghostly figures, featuring a misty Eiffel Tower…

France's ANTS Agency Exposes Data Breach After Hacker Offers Stolen Records for Sale

France's ANTS Agency has suffered a data breach, with hackers offering stolen records for sale, putting individual and professional accounts at risk. The agency is investigating and notifying affected users, urging them to stay vigilant for suspicious activity.

Analyst 207
Locked hospital room with faint light, bed, medical equipment, and laptop displaying ransomware message.

Ex-FBI Chief Urges Homicide Charges for Ransomware Actors Tied to Patient Deaths

It's time to hold ransomware attackers accountable for their deadly actions - Cynthia Kaiser, ex-FBI chief, urges prosecutors to consider felony homicide charges when attacks on hospitals result in patient deaths. Closing the gap between crime severity and consequences is crucial, she stresses.

Analyst 207
Abandoned study with laptop displaying ransomware warning, eerie blue glow, and ghostly suit-clad figure in background.

Gentlemen Ransomware Operation Exposes 1,570 Victims Through SystemBC Malware

A shocking 1,570 networks worldwide have been compromised by the sneaky SystemBC malware, which has been quietly building a massive botnet of victims across the globe. This stealthy threat can even download and execute additional malware, putting your security at risk.

Analyst 207
Dark digital landscape with grid pattern, red warning light, and broken blue-glowing link.

AI Monitor Flags Axios Supply-Chain Attack in Real Time

In a remarkable experiment, Elastic Security Labs' James Spiteri swiftly built a lightweight pipeline that leveraged a live AI agent to monitor package repositories, rapidly evolving into a practical detection capability. This innovative test enabled the AI agent to effectively flag potential threats, such as the Axios supply-chain attack, in real-time.

Analyst 207
Destroyed electrical substation at dusk with rubble, shattered phone, and scattered papers amidst ominous cityscape.

Lotus Malware Targets Venezuelan Energy Firms with Data-Wiping Attacks

A new, highly destructive malware called Lotus has been targeting Venezuela's energy sector, leaving systems completely unrecoverable after wiping data and disabling recovery mechanisms. This devastating attack systematically deletes files and overwrites physical drives, causing irreversible damage.

Analyst 207
Dimly lit network operations center with glowing laptop and large screen displaying city map highlighting vulnerabilities.

CISA Warns of Active Cisco SD-WAN Exploits

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority warning to federal agencies, ordering them to patch three critical Cisco SD-WAN vulnerabilities within four days after discovering they're being actively exploited by hackers. This urgent directive comes after Cisco patched the flaws in its Catalyst SD-WAN Manager platform.

Analyst 207
Person sitting in dark room with laptop showing fake login prompt and nearby smartphone and torn paper with credentials.

macOS ClickFix Attacks Harvest Credentials via AppleScript Stealers

macOS users beware: a sneaky ClickFix campaign is using AppleScript stealers to harvest credentials from 14 browsers, 16 cryptocurrency wallets, and over 200 extensions. This targeted attack has already made off with a staggering amount of sensitive info - and it's still on the loose.

Analyst 207
Shattered padlock on cracked digital screen with binary code and exposed wires.

Vercel Breach Sparks Security Community Debate

The Vercel breach has sparked a heated discussion among security leaders, leaving many to wonder what was compromised and how far-reaching the impact will be. The incident has clearly got the security community talking, but details about the breach and the conversations surrounding it remain scarce.

Analyst 207
Cracked smartphone screen next to discarded smart card with eerie interface and cursor on sensitive file in background.

Malware Exploits Android App to Harvest NFC Card Data

A new malware called NGate is putting NFC payment card users in Brazil at risk, exploiting the popular HandyPay app to steal sensitive card data and PINs. This sneaky attack leaves cardholders vulnerable to financial loss and compromised personal info.

Analyst 207
Person in hoodie sits before laptop with ransom demand, cityscape behind, cash and phone discarded beside.

Ransomware Negotiator Pleads Guilty to Aiding BlackCat Extortions

Meet Angelo Martino, a 41-year-old from Florida who just pleaded guilty to helping the notorious BlackCat ransomware gang extort even bigger payouts from US companies. Martino teamed up with the BlackCat operators in April 2023, marking the start of his involvement in their malicious activities.

Analyst 207
Person in hoodie with obscured face pleading, surrounded by code and scattered items on a desk.

Scattered Spider Member Pleads Guilty to $8 Million Crypto Heist

A 24-year-old British hacker, Tyler Robert Buchanan, has pleaded guilty to masterminding an $8 million crypto heist as part of the notorious Scattered Spider cybercrime group. His downfall began with a trail of seemingly harmless text messages that ultimately led to his guilty plea.

Analyst 207
Suited figure in shadows surrounded by devices with encrypted screens.

Gentlemen Ransomware Spreads Rapidly Through Affiliate Network

Gentlemen Ransomware is spreading rapidly through its affiliate network, fueling a surge in multi-platform attacks and infections linked to the malicious tool SystemBC. This ransomware-as-a-service operation is making it alarmingly easy for cybercriminals to join the fray and wreak havoc.

Analyst 207
Person in handcuffs stands before dark cityscape with faint glow of screens.

Former Ransomware Negotiator Pleads Guilty in High-Profile Gang Case

In a shocking twist, a former ransomware negotiator has pleaded guilty to aiding the notorious ALPHV/BlackCat gang in extorting millions from US businesses, raising disturbing questions about the blurred lines between victim and perpetrator. This comes on the heels of a nonprofit organization paying a staggering $26.8 million ransom.

Analyst 207
Padlocked gate with ominous glow, surrounded by twisted metal and digital weeds, with a shattered smartphone in the…

Vercel Breach Exposes OAuth, AI-Driven Threats

A recent breach at Vercel exposed sensitive data after attackers exploited OAuth and hijacked an employee's account, showcasing a disturbingly swift and sophisticated assault that may have been fueled by artificial intelligence. The stolen data is now being sold to the highest bidder for a whopping $2 million.

Analyst 207
Cracked virtual tunnel with cityscape glow, symbolizing breached secure network.

CISA Warns of Active Exploitation of SD-WAN Flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a newly discovered SD-WAN flaw that's already being exploited by attackers, giving US government agencies just four days to secure vulnerable systems. Time is of the essence in this urgent directive, which CISA has framed as an operational emergency.

Analyst 207