Emerging Threats

Cross-App Permissions Expose Hidden Risks in AI-Driven SaaS Environments
Imagine a single security slip-up exposing 1.5 million API tokens and 35,000 email addresses, leaving AI agents and their users vulnerable to hijacking and misuse. The recent Moltbook breach reveals the hidden risks of cross-app permissions in AI-driven SaaS environments.

Lotus Wiper Malware Disrupts Venezuelan Energy Sector
Cybersecurity researchers uncovered a highly destructive malware, known as Lotus Wiper, that was used to disrupt Venezuela's energy sector in a targeted attack. This powerful data wiper was deployed in a series of devastating attacks at the end of 2025 and beginning of 2026.

Former Ransomware Negotiator Pleads Guilty to Aiding BlackCat Cyber Gang
A former ransomware negotiator turned rogue, Angelo Martino has pleaded guilty to aiding the notorious BlackCat cyber gang, betraying his employer and the industry he was meant to serve. By secretly collaborating with BlackCat, Martino launched devastating ransomware attacks, causing harm to innocent victims and lining his own pockets.

Researchers Expose ProxySmart Software Behind Global SIM Farms
Meet ProxySmart, a sneaky software powering "SIM Farm as a Service" operations worldwide, with a massive footprint of 94 phone farms across 17 countries and 19 US states. Its creators, a Belarus-based vendor, have made it easy for operators to run mobile proxy infrastructure at commercial scale.

Harvester Malware Exploits Microsoft Graph API for Stealthy Linux Attacks
Meet Harvester, a stealthy espionage group believed to be state-backed, that's been secretly targeting telecommunications, government, and IT organizations in South Asia since 2021. Their latest trick? A Linux-capable GoGra backdoor that uses Microsoft Graph API for covert communications.

Mustang Panda Expands LOTUSLITE Malware to Target India, Korea
Meet the evolved LOTUSLITE backdoor, now wielding dynamic DNS-based command-and-control over HTTPS, enabling its operators to remotely access and manipulate targeted systems for espionage purposes. This sophisticated malware supports remote shell access, file operations, and session management, a potent toolkit for data collection and access persistence.

Unpatched SharePoint Servers Exposed to Ongoing Spoofing Attacks
Over 1,300 Microsoft SharePoint servers are still vulnerable to a spoofing attack, despite a security update being available since last week, leaving them exposed to ongoing exploitation by hackers. This comes after Microsoft warned that the CVE-2026-32201 vulnerability was exploited as a zero-day, and attackers are continuing to abuse it in widespread campaigns.

Scotland Hacker Pleads Guilty in Scattered Spider Cybercrime Case
Meet Tyler Robert Buchanan, the 24-year-old mastermind behind the notorious Scattered Spider cybercrime gang, who has pleaded guilty to federal charges of conspiracy and identity theft. With a potential 22-year prison sentence looming, Buchanan's guilty plea marks a major win for law enforcement in the fight against cybercrime.

Former Ransomware Negotiator Pleads Guilty to Extortion Scheme
A former ransomware negotiator has pleaded guilty to masterminding a brazen extortion scheme that raked in a staggering $75.3 million, exploiting his position to secretly collude with ransomware gangs and betray the very companies he was supposed to protect. Angelo John Martino III faces up to 20 years in prison for his role in the conspiracy.

France's ANTS Agency Exposes Data Breach After Hacker Offers Stolen Records for Sale
France's ANTS Agency has suffered a data breach, with hackers offering stolen records for sale, putting individual and professional accounts at risk. The agency is investigating and notifying affected users, urging them to stay vigilant for suspicious activity.

Ex-FBI Chief Urges Homicide Charges for Ransomware Actors Tied to Patient Deaths
It's time to hold ransomware attackers accountable for their deadly actions - Cynthia Kaiser, ex-FBI chief, urges prosecutors to consider felony homicide charges when attacks on hospitals result in patient deaths. Closing the gap between crime severity and consequences is crucial, she stresses.

Gentlemen Ransomware Operation Exposes 1,570 Victims Through SystemBC Malware
A shocking 1,570 networks worldwide have been compromised by the sneaky SystemBC malware, which has been quietly building a massive botnet of victims across the globe. This stealthy threat can even download and execute additional malware, putting your security at risk.

AI Monitor Flags Axios Supply-Chain Attack in Real Time
In a remarkable experiment, Elastic Security Labs' James Spiteri swiftly built a lightweight pipeline that leveraged a live AI agent to monitor package repositories, rapidly evolving into a practical detection capability. This innovative test enabled the AI agent to effectively flag potential threats, such as the Axios supply-chain attack, in real-time.

Lotus Malware Targets Venezuelan Energy Firms with Data-Wiping Attacks
A new, highly destructive malware called Lotus has been targeting Venezuela's energy sector, leaving systems completely unrecoverable after wiping data and disabling recovery mechanisms. This devastating attack systematically deletes files and overwrites physical drives, causing irreversible damage.

CISA Warns of Active Cisco SD-WAN Exploits
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority warning to federal agencies, ordering them to patch three critical Cisco SD-WAN vulnerabilities within four days after discovering they're being actively exploited by hackers. This urgent directive comes after Cisco patched the flaws in its Catalyst SD-WAN Manager platform.

macOS ClickFix Attacks Harvest Credentials via AppleScript Stealers
macOS users beware: a sneaky ClickFix campaign is using AppleScript stealers to harvest credentials from 14 browsers, 16 cryptocurrency wallets, and over 200 extensions. This targeted attack has already made off with a staggering amount of sensitive info - and it's still on the loose.

Vercel Breach Sparks Security Community Debate
The Vercel breach has sparked a heated discussion among security leaders, leaving many to wonder what was compromised and how far-reaching the impact will be. The incident has clearly got the security community talking, but details about the breach and the conversations surrounding it remain scarce.

Malware Exploits Android App to Harvest NFC Card Data
A new malware called NGate is putting NFC payment card users in Brazil at risk, exploiting the popular HandyPay app to steal sensitive card data and PINs. This sneaky attack leaves cardholders vulnerable to financial loss and compromised personal info.

Ransomware Negotiator Pleads Guilty to Aiding BlackCat Extortions
Meet Angelo Martino, a 41-year-old from Florida who just pleaded guilty to helping the notorious BlackCat ransomware gang extort even bigger payouts from US companies. Martino teamed up with the BlackCat operators in April 2023, marking the start of his involvement in their malicious activities.

Scattered Spider Member Pleads Guilty to $8 Million Crypto Heist
A 24-year-old British hacker, Tyler Robert Buchanan, has pleaded guilty to masterminding an $8 million crypto heist as part of the notorious Scattered Spider cybercrime group. His downfall began with a trail of seemingly harmless text messages that ultimately led to his guilty plea.

Gentlemen Ransomware Spreads Rapidly Through Affiliate Network
Gentlemen Ransomware is spreading rapidly through its affiliate network, fueling a surge in multi-platform attacks and infections linked to the malicious tool SystemBC. This ransomware-as-a-service operation is making it alarmingly easy for cybercriminals to join the fray and wreak havoc.

Former Ransomware Negotiator Pleads Guilty in High-Profile Gang Case
In a shocking twist, a former ransomware negotiator has pleaded guilty to aiding the notorious ALPHV/BlackCat gang in extorting millions from US businesses, raising disturbing questions about the blurred lines between victim and perpetrator. This comes on the heels of a nonprofit organization paying a staggering $26.8 million ransom.

Vercel Breach Exposes OAuth, AI-Driven Threats
A recent breach at Vercel exposed sensitive data after attackers exploited OAuth and hijacked an employee's account, showcasing a disturbingly swift and sophisticated assault that may have been fueled by artificial intelligence. The stolen data is now being sold to the highest bidder for a whopping $2 million.

CISA Warns of Active Exploitation of SD-WAN Flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a newly discovered SD-WAN flaw that's already being exploited by attackers, giving US government agencies just four days to secure vulnerable systems. Time is of the essence in this urgent directive, which CISA has framed as an operational emergency.