Emerging Threats

Mirax Trojan Hijacks Android Devices for Proxy Network
Meet Mirax, a sneaky new Android banking trojan that's not only stealing credentials, but also hijacking devices to create a powerful proxy network - putting European users at risk. This emerging malware is a triple threat, combining a malware-as-a-service model, remote access capabilities, and residential proxies to wreak havoc on infected phones.

Booking.com Exposes Reservation Data Breach Risk
Did you know that a recent data breach at Booking.com may have exposed sensitive trip details, including your name, contact info, and private messages to hotels, to unknown attackers? This incident is a stark reminder that even major travel platforms can be vulnerable to data breaches, putting your personal info at risk.

Hackers Exploit Microsoft 365 Mailbox Rules to Conceal Post-Breach Activity
Hackers are exploiting a sneaky vulnerability in Microsoft 365 mailbox rules to hide their tracks, siphon sensitive data, and maintain a backdoor into compromised accounts. This stealthy tactic allows attackers to fly under the radar, making it even harder to detect and stop them.

Storm Infostealer Exploits Server-Side Decryption for Session Hijacking
Imagine if hackers could hijack your online sessions, bypassing even the strongest passwords and multifactor protections - a new infostealer called Storm makes this a chilling reality by exploiting server-side decryption to steal sensitive browser data. This sneaky malware allows attackers to take over your accounts, all without needing to crack your password.

Zero-Day Exploits Target PDF Files Amid State-Sponsored Infrastructure Meddling
A critical zero-day flaw has been hiding in plain sight within everyday PDF files, and at the same time, state-sponsored actors have been aggressively probing vital infrastructure, creating a perfect storm that demands immediate attention. This dual threat of quietly persistent PDFs and long-simmering meddling has escalated into a situation that requires rapid action.

Zero-Day Exploits Proliferate as Breakout Times Shrink
Imagine a research preview that can teach itself to find and exploit the very flaws security teams scramble to patch - that's now a harsh reality, as an advanced language model has autonomously discovered and exploited zero-day vulnerabilities in every major operating system and browser. This breakthrough should be a wake-up call for security teams to rethink their response times to alerts.

Booking.com Breach Exposes Customer Data
A single-line warning from Booking.com that your personal data may have been exposed can be unsettling, especially when it lacks crucial details on what happened and how to protect yourself. This data breach notification raises more questions than answers, leaving customers and experts alike searching for clarity.

Basic-Fit Discloses Data Breach Exposing Member Information
Basic-Fit, Europe's largest gym chain, has confirmed a data breach that exposed sensitive information, including bank details, for around one million customers, raising urgent concerns about data security and accountability. The breach, which resulted from a cyberattack, compromised names, addresses, dates of birth, and financial information, but thankfully did not involve password theft.

FBI Disrupts W3LL Phishing Operation Linked to $20m in Fraud
The FBI has successfully dismantled a massive phishing operation built around the notorious W3LL phishing kit, which was linked to a staggering $20 million in fraud attempts. By taking down this operation, the bureau has disrupted a key tool used by cybercriminals to carry out their scams.

Rockstar Games Data Breached as ShinyHunters Exploits Third-Party Vulnerability
Rockstar Games has been hit by a data breach, with a notorious hacking group called ShinyHunters claiming it accessed sensitive information through a vulnerability in a third-party tool, rather than a complex hack. The group says it simply walked through an open door, exploiting access to Snowflake metrics to get to the data.

APT37 Exploits Facebook for RokRAT Malware Delivery
North Korean hackers APT37 have cleverly turned Facebook friend requests into a sneaky way to deliver RokRAT malware, exploiting our natural tendency to trust social connections. By accepting a friend request, victims unwittingly open the door to a remote access trojan that can compromise their device.

Kaspersky Uncovers JanelaRAT Malware Targeting Latin American Users
Kaspersky's Global Research and Analysis Team has uncovered a sophisticated malware campaign, dubbed JanelaRAT, that's specifically targeting users in Latin America with financial threats. This evolved malware has been detailed in a recent report, revealing its updated functionality and infection chain.

Authorities Disrupt $12m Crypto Scam Targeting 20,000 Victims
A single click can be costly: over 20,000 crypto users across three countries fell victim to a $12 million approval phishing scam, tricked into handing over full access to their wallets. Thankfully, authorities swooped in, seizing the lost funds in a major cross-border crackdown dubbed Operation Atlantic.

OpenAI Disrupts macOS App Signing Process After Supply Chain Breach
OpenAI recently took swift action to protect its users by revoking a macOS app certificate after discovering a malicious library had been downloaded through a GitHub Actions workflow used to sign its applications. This move highlights the vulnerability of even trusted software signing processes to supply chain breaches, and the importance of staying vigilant in macOS app security.

Marimo Flaw Exploited for Credential Theft in Active Attacks
A critical vulnerability in Marimo is being actively exploited by attackers to steal sensitive credentials, and it requires no prior authentication to run code remotely. This flaw has severe consequences for organizations using Marimo, making it essential to take immediate action.

Adobe Fixes Exploited Flaw in Acrobat Reader
Adobe has issued an emergency update to fix a critical security flaw in Acrobat Reader that's being actively exploited by hackers, allowing them to run malicious code on affected installations. If you're one of millions of users, make sure to update now to keep your data safe.

CPUID Compromised, Trojanized Software Deploys STX RAT
For one day in April, unsuspecting users who visited CPUID.com, a trusted site for hardware-monitoring tools, unknowingly downloaded trojanized software that deployed a malicious remote access trojan called STX RAT. The compromised software, including CPU-Z and HWMonitor, turned a trusted resource into a malware delivery vehicle.

Global Crackdown Uncovers 20,000 Crypto Fraud Victims
A shocking 20,000 people across Canada, the UK, and the US have been identified as victims of cryptocurrency fraud in a major international crackdown led by the UK's National Crime Agency. This staggering number puts a face to the faceless - and highlights the urgent need for action against these scams.

Malware Poisons Open Source Tools in Dual Supply Chain Attacks
Imagine trusting a tool, only to have it secretly turned against you - that's what happened in March when two massive supply chain attacks infected popular open source tools with malware, putting tens of thousands of organizations at risk. The full extent of the damage may not be known for months, but one thing is clear: the threat is real and far-reaching.

Hungarian Government Credentials Exposed in Breach Data
The Hungarian government's digital defenses have been left vulnerable after nearly 800 state logins, including defense and NATO-linked accounts, surfaced in breach data, raising serious concerns about the nation's security posture. One alarming example? A username as simple as "FrankLampard", the name of a Premier League midfielder.

Anubis Ransomware Gang Targets Signature Healthcare in 2TB Data Heist
In a chilling 2TB data heist, the Anubis ransomware gang has struck Signature Healthcare in Massachusetts, stealing sensitive patient information despite claiming they didn't encrypt the hospital's systems. As the healthcare system scrambles to cope, patients are feeling the impact, with ambulance patients being diverted and clinicians forced to go old-school with paper records.

Iranian Hackers Target Thousands of US Industrial Devices
Thousands of US industrial devices, including programmable logic controllers made by Rockwell Automation, have been targeted by Iranian-linked hackers, raising concerns about the vulnerability of critical infrastructure networks. This cyber campaign highlights the alarming risk to the networks we rely on every day.

CPUID Website Compromised, Serves Malware via HWMonitor Downloads
For six hours, unsuspecting visitors to the CPUID website were put at risk of having their passwords stolen when malicious malware was served in place of the HWMonitor tool they were trying to download. This alarming security breach highlights the vulnerability even trusted sites can have, leaving users to wonder if their sensitive information is safe.

CPUID Compromised in Supply Chain Attack
A recent supply chain attack on the CPUID project has raised alarming questions about trust in software downloads, after hackers manipulated the official website to serve malware-infected versions of popular tools like CPU-Z and HWMonitor. Can users, defenders, and policymakers be certain that their software sources are safe?