Skip to main content

Emerging Threats

Shadowy figure looms over dimly lit cityscape, laptop screen displays Eastern Europe map, nearby smartphone lies broken.

APT28 Targets Ukraine, NATO Allies with PRISMEX Malware

Russian threat actor APT28 has launched a new campaign, deploying a previously unknown malware suite called PRISMEX to target Ukraine and its NATO allies, using clever concealment techniques to evade detection. This sophisticated attack combines steganography, COM hijacking, and legitimate cloud services to stay under the radar.

Analyst 207
Broken police badge on dark surface with cracked laptop and scattered papers, cityscape visible through rain-soaked window.

LAPD Data Breach Exposes Sensitive Officer Records

A data breach has exposed sensitive records of the Los Angeles Police Department, raising urgent concerns about operational security, individual privacy, and institutional trust. The incident's implications extend far beyond a single breach, sparking questions about the vulnerability of law enforcement data.

Analyst 207
Darkened hospital corridor with a cracked laptop screen displaying a red lock symbol.

Ransomware Attack Cripples Dutch Healthcare Software Vendor ChipSoft

A ransomware attack has taken down ChipSoft, a Dutch healthcare software vendor, leaving many questions unanswered - but one thing is certain, the company's website is currently offline and its email system is still functioning. The extent of the damage and the identity of the perpetrators remain unclear.

Analyst 207
Cracked NHS ID badge lies on hospital trolley amidst tangled cables and a smartphone displaying illicit content in a dimly…

Scottish Healthcare Domains Hijacked, Redirect to Illicit Content

Imagine visiting a trusted healthcare website, only to be redirected to explicit content or illegal streams - that's the alarming reality for some Scottish healthcare domains that have been hijacked. Patients and staff are left with unanswered questions and growing concern after researchers uncovered the breach affecting NHS Scotland-linked sites.

Analyst 207
Ominous padlock with crack set against blurred cityscape with glowing device screens.

Anthropic's AI Model Exposes Thousands of Zero-Day Flaws in Major Systems

Anthropic's cutting-edge AI model, Claude Mythos, has made a groundbreaking discovery - uncovering thousands of zero-day flaws in major systems, giving us a glimpse into the hidden vulnerabilities of our digital world. This breakthrough is the result of Anthropic's innovative Project Glasswing initiative, which aims to revolutionize cybersecurity.

Analyst 207
Globe centered on Russia with shattered network, silhouettes of law enforcement disrupting tangled web.

FBI Disrupts Russian Hacker Network with DNS Hijacking Takedown

In a major cyber takedown, the FBI has successfully disrupted a Russian hacker network by pulling the plug on compromised US-based routers, effectively cutting off the threat actor's malicious infrastructure. This bold move allowed authorities to neutralize the threat without relying on individual device owners to take action.

Analyst 207
Shadowy figure in hoodie surrounded by screens and cables, coding on laptop with multiple terminals open.

North Korean Hackers Expand Malicious Package Reach Across Multiple Coding Ecosystems

Beware of the Trojan horse in your code: North Korean hackers have quietly infiltrated multiple package ecosystems, publishing around 1,700 malicious packages that masquerade as legitimate developer tools but act as malware loaders. This sneaky campaign, linked to the Contagious Interview group, puts developers and organizations relying on shared code on high alert.

Analyst 207
Dimly lit industrial control room with analog panels and code on screens, with a ghostly US map projection.

Iranian Hackers Infiltrate US Critical Infrastructure via OT Weaknesses

US critical infrastructure providers are reeling from a wake-up call after Iranian-backed hackers exploited weaknesses in internet-exposed operational technology assets, causing disruption and financial loss. The alarming breach, revealed by the Cybersecurity and Infrastructure Security Agency, highlights the high stakes of vulnerable systems.

Analyst 207
Dark industrial control room with spotlight on US map showing targeted areas and exposed industrial equipment.

Iran-Linked Hackers Target Internet-Exposed PLCs in US Infrastructure

Iran-affiliated hackers are launching targeted cyber attacks on internet-exposed devices controlling US critical infrastructure, including power plants, water systems, and manufacturing lines. This urgent threat requires immediate attention to protect vulnerable systems from devastating intrusions that can diminish functionality and manipulate operations.

Analyst 207
Darkened underground lair with modern computer equipment and a lone figure hunched over a laptop.

Ransomware Ecosystem Evolves Amid Profitability Decline

The ransomware ecosystem is evolving, with the threat remaining alarmingly widespread across industries and regions, yet the business model fueling it is showing signs of strain. This paradox has emerged as ransomware-as-a-service and specialization have driven its growth, despite declining profitability.

Analyst 207
Person intensely focused in dimly lit room surrounded by screens displaying code and Mexico maps.

Kaspersky Uncovers Horabot Campaign Targeting Mexico

Kaspersky's Security Operations Center has uncovered a complex Horabot campaign targeting Mexico, and is now sharing crucial insights on how it works and how to detect it. This critical threat intelligence will help defenders in Mexico and beyond prioritize their resources and stay one step ahead of the threat.

Analyst 207
Shadowy figure in hoodie sits before laptop with eerie glow, surrounded by clutter, with cityscape and damaged skyscrapers…

DarkSword Exploit Chain Spreads Across Threat Actors

A single iOS exploit chain, known as DarkSword, has been spreading rapidly among threat actors, allowing multiple groups to fully compromise iPhones across several countries. This compact, multi-vulnerability exploit leverages zero-day vulnerabilities to achieve complete device takeover, and was first detected in the wild in November 2025.

Analyst 207
Dimly lit industrial control room with a lone figure in shadows, surrounded by flickering computer screens and a cracked…

Iran-Backed Hackers Infiltrate US Industrial Controls

US cyber and intelligence agencies have sounded the alarm: pro-Iran hackers have infiltrated and disrupted critical US infrastructure, including water and energy systems, posing a pressing threat to national security. These foreign actors have breached government networks and industrial controls, sparking urgent concerns about the vulnerability of America's essential services.

Analyst 207
Dimly lit home office with shattered laptop and smartphone, surrounded by scattered papers and broken glass.

FBI Report Exposes Soaring Cybercrime Losses

Cybercrime losses have skyrocketed 26% to a staggering $20.9 billion in 2025, but the true extent of the damage is likely much worse, as many victims suffer in silence, never reporting the crimes they endure.

Analyst 207
Shadowy figure in a hoodie amidst industrial complex with glowing laptop screens and cables.

TeamPCP Infiltrates Security Infrastructure with Multi-Stage Supply Chain Attack

When security tools meant to safeguard networks become the entry point for attacks, trust is shattered - and that's exactly what's happening with TeamPCP's multi-stage supply chain attacks on security infrastructure. This sinister tactic lets threat actors turn protectors into launchpads for wider compromise.

Analyst 207
Person in a hoodie with obscured face sits in front of laptop displaying cityscape, surrounded by network-like lines and…

Mandiant Report Reveals Evolving Cyber Threat Tactics

Discover the alarming evolution of cyber threats in Mandiant's M-Trends 2026 report, which reveals a stark reality: attackers are now operating under two distinct playbooks, drastically changing the detection, response, and risk landscape. The report uncovers a significant increase in global median dwell time to 14 days, with some attacks lingering for as long as 122 days.

Analyst 207
Dimly lit control room with computer screens and machinery, a lone chair pushed back from a console in the foreground.

Feds Warn of Iranian Cyberattacks on US Energy, Water Systems

US government agencies have issued an urgent warning that Iranian hackers are launching targeted cyberattacks on America's energy and water infrastructure, posing a serious threat to the communities that rely on them. These attacks have already caused harm to victims in the past month, highlighting the need for immediate vigilance.

Analyst 207
Tangled web of interconnected chains and gears with a broken link highlighted, set against a cityscape at dusk.

Unit 42 Uncovers Axios Supply Chain Attack's Far-Reaching Consequences

When a trusted software pathway is compromised, the consequences can be far-reaching - as Unit 42's recent analysis of the Axios supply chain attack starkly reveals, threatening digital trust and resilience. The team's detailed examination exposes the attack's full chain, from initial dropper to forensic cleanup.

Analyst 207
Shadowy figure lurks near laptop with tangled wires and broken padlock, amidst eerie city glow.

North Korea-linked actor compromises axios NPM package

A shocking discovery by Google Threat Intelligence Group has exposed a vulnerability in the popular axios NPM package, which has over 100 million weekly downloads, and has raised urgent questions about the trustworthiness of software supply chains. A malicious dependency was secretly introduced into axios releases, putting countless applications at risk.

Analyst 207
Person in shadows holds smartphone and laptop, surrounded by ghostly triangles and geometric shapes, evoking cyber threat…

Kaspersky Uncovers Coruna Exploit Kit Linked to Operation Triangulation

Kaspersky's researchers have made a significant discovery: the Coruna exploit kit, now targeting iPhones, uses an updated kernel exploit linked to the notorious Operation Triangulation. This finding highlights the evolving threat landscape, where offensive code is repurposed to target new devices.

Analyst 207
Shadowy figure holds damaged laptop amidst glowing code, set against a dark cityscape and Russian map backdrop.

Feds Disrupt Russia-Backed Espionage Network Infecting 18,000 Devices

Federal authorities have successfully disrupted a massive Russia-backed espionage operation that had infiltrated nearly 18,000 devices, stealing sensitive account credentials and tokens by hijacking internet traffic. This significant takedown thwarts the efforts of Forest Blizzard, a notorious threat group linked to Russia's GRU.

Analyst 207
Dark digital landscape with stormy cloud over virtualized infrastructure and shattered virtual machine in foreground.

VMware vSphere Ecosystem Targeted by BRICKSTORM Malware Attacks

Imagine an attacker sneaking past your trusted operating system and into the hidden infrastructure that powers your virtual machines - that's the risk posed by BRICKSTORM malware, which targets the VMware vSphere ecosystem. This stealthy threat allows adversaries to operate undetected, evading traditional endpoint tools by establishing persistence at the virtualization layer.

Analyst 207
Broken chain link reveals glowing circuit board amidst puzzle pieces and cityscape at dusk, with ominous laptop screen…

Malicious AI Gateway Exposes Data Through Supply Chain Breach

A recent analysis of LiteLLM, a popular AI gateway, revealed a supply chain breach that embedded malicious code designed to steal sensitive data, highlighting the vulnerability of even the most trusted components. This breach turned a multifunctional gateway meant to enhance AI agents into a vector for data theft, putting countless users at risk.

Analyst 207
Person in shadows hunched over laptop with eerie glow, cityscape blurred in background, ghostly URL pathway trails from…

Hackers Target Asia Pacific with URL-Based Threats

In Asia Pacific, hackers are ditching traditional tactics and using URL-based threats to gain easy access to your digital life - with just one click, your security can be compromised. This emerging threat landscape is redefining how we think about online identity, access, and trust.

Analyst 207