Emerging Threats

APT28 Targets Ukraine, NATO Allies with PRISMEX Malware
Russian threat actor APT28 has launched a new campaign, deploying a previously unknown malware suite called PRISMEX to target Ukraine and its NATO allies, using clever concealment techniques to evade detection. This sophisticated attack combines steganography, COM hijacking, and legitimate cloud services to stay under the radar.

LAPD Data Breach Exposes Sensitive Officer Records
A data breach has exposed sensitive records of the Los Angeles Police Department, raising urgent concerns about operational security, individual privacy, and institutional trust. The incident's implications extend far beyond a single breach, sparking questions about the vulnerability of law enforcement data.

Ransomware Attack Cripples Dutch Healthcare Software Vendor ChipSoft
A ransomware attack has taken down ChipSoft, a Dutch healthcare software vendor, leaving many questions unanswered - but one thing is certain, the company's website is currently offline and its email system is still functioning. The extent of the damage and the identity of the perpetrators remain unclear.

Scottish Healthcare Domains Hijacked, Redirect to Illicit Content
Imagine visiting a trusted healthcare website, only to be redirected to explicit content or illegal streams - that's the alarming reality for some Scottish healthcare domains that have been hijacked. Patients and staff are left with unanswered questions and growing concern after researchers uncovered the breach affecting NHS Scotland-linked sites.

Anthropic's AI Model Exposes Thousands of Zero-Day Flaws in Major Systems
Anthropic's cutting-edge AI model, Claude Mythos, has made a groundbreaking discovery - uncovering thousands of zero-day flaws in major systems, giving us a glimpse into the hidden vulnerabilities of our digital world. This breakthrough is the result of Anthropic's innovative Project Glasswing initiative, which aims to revolutionize cybersecurity.

FBI Disrupts Russian Hacker Network with DNS Hijacking Takedown
In a major cyber takedown, the FBI has successfully disrupted a Russian hacker network by pulling the plug on compromised US-based routers, effectively cutting off the threat actor's malicious infrastructure. This bold move allowed authorities to neutralize the threat without relying on individual device owners to take action.

North Korean Hackers Expand Malicious Package Reach Across Multiple Coding Ecosystems
Beware of the Trojan horse in your code: North Korean hackers have quietly infiltrated multiple package ecosystems, publishing around 1,700 malicious packages that masquerade as legitimate developer tools but act as malware loaders. This sneaky campaign, linked to the Contagious Interview group, puts developers and organizations relying on shared code on high alert.

Iranian Hackers Infiltrate US Critical Infrastructure via OT Weaknesses
US critical infrastructure providers are reeling from a wake-up call after Iranian-backed hackers exploited weaknesses in internet-exposed operational technology assets, causing disruption and financial loss. The alarming breach, revealed by the Cybersecurity and Infrastructure Security Agency, highlights the high stakes of vulnerable systems.

Iran-Linked Hackers Target Internet-Exposed PLCs in US Infrastructure
Iran-affiliated hackers are launching targeted cyber attacks on internet-exposed devices controlling US critical infrastructure, including power plants, water systems, and manufacturing lines. This urgent threat requires immediate attention to protect vulnerable systems from devastating intrusions that can diminish functionality and manipulate operations.

Ransomware Ecosystem Evolves Amid Profitability Decline
The ransomware ecosystem is evolving, with the threat remaining alarmingly widespread across industries and regions, yet the business model fueling it is showing signs of strain. This paradox has emerged as ransomware-as-a-service and specialization have driven its growth, despite declining profitability.

Kaspersky Uncovers Horabot Campaign Targeting Mexico
Kaspersky's Security Operations Center has uncovered a complex Horabot campaign targeting Mexico, and is now sharing crucial insights on how it works and how to detect it. This critical threat intelligence will help defenders in Mexico and beyond prioritize their resources and stay one step ahead of the threat.

DarkSword Exploit Chain Spreads Across Threat Actors
A single iOS exploit chain, known as DarkSword, has been spreading rapidly among threat actors, allowing multiple groups to fully compromise iPhones across several countries. This compact, multi-vulnerability exploit leverages zero-day vulnerabilities to achieve complete device takeover, and was first detected in the wild in November 2025.

Iran-Backed Hackers Infiltrate US Industrial Controls
US cyber and intelligence agencies have sounded the alarm: pro-Iran hackers have infiltrated and disrupted critical US infrastructure, including water and energy systems, posing a pressing threat to national security. These foreign actors have breached government networks and industrial controls, sparking urgent concerns about the vulnerability of America's essential services.

FBI Report Exposes Soaring Cybercrime Losses
Cybercrime losses have skyrocketed 26% to a staggering $20.9 billion in 2025, but the true extent of the damage is likely much worse, as many victims suffer in silence, never reporting the crimes they endure.

TeamPCP Infiltrates Security Infrastructure with Multi-Stage Supply Chain Attack
When security tools meant to safeguard networks become the entry point for attacks, trust is shattered - and that's exactly what's happening with TeamPCP's multi-stage supply chain attacks on security infrastructure. This sinister tactic lets threat actors turn protectors into launchpads for wider compromise.

Mandiant Report Reveals Evolving Cyber Threat Tactics
Discover the alarming evolution of cyber threats in Mandiant's M-Trends 2026 report, which reveals a stark reality: attackers are now operating under two distinct playbooks, drastically changing the detection, response, and risk landscape. The report uncovers a significant increase in global median dwell time to 14 days, with some attacks lingering for as long as 122 days.

Feds Warn of Iranian Cyberattacks on US Energy, Water Systems
US government agencies have issued an urgent warning that Iranian hackers are launching targeted cyberattacks on America's energy and water infrastructure, posing a serious threat to the communities that rely on them. These attacks have already caused harm to victims in the past month, highlighting the need for immediate vigilance.

Unit 42 Uncovers Axios Supply Chain Attack's Far-Reaching Consequences
When a trusted software pathway is compromised, the consequences can be far-reaching - as Unit 42's recent analysis of the Axios supply chain attack starkly reveals, threatening digital trust and resilience. The team's detailed examination exposes the attack's full chain, from initial dropper to forensic cleanup.

North Korea-linked actor compromises axios NPM package
A shocking discovery by Google Threat Intelligence Group has exposed a vulnerability in the popular axios NPM package, which has over 100 million weekly downloads, and has raised urgent questions about the trustworthiness of software supply chains. A malicious dependency was secretly introduced into axios releases, putting countless applications at risk.

Kaspersky Uncovers Coruna Exploit Kit Linked to Operation Triangulation
Kaspersky's researchers have made a significant discovery: the Coruna exploit kit, now targeting iPhones, uses an updated kernel exploit linked to the notorious Operation Triangulation. This finding highlights the evolving threat landscape, where offensive code is repurposed to target new devices.

Feds Disrupt Russia-Backed Espionage Network Infecting 18,000 Devices
Federal authorities have successfully disrupted a massive Russia-backed espionage operation that had infiltrated nearly 18,000 devices, stealing sensitive account credentials and tokens by hijacking internet traffic. This significant takedown thwarts the efforts of Forest Blizzard, a notorious threat group linked to Russia's GRU.

VMware vSphere Ecosystem Targeted by BRICKSTORM Malware Attacks
Imagine an attacker sneaking past your trusted operating system and into the hidden infrastructure that powers your virtual machines - that's the risk posed by BRICKSTORM malware, which targets the VMware vSphere ecosystem. This stealthy threat allows adversaries to operate undetected, evading traditional endpoint tools by establishing persistence at the virtualization layer.

Malicious AI Gateway Exposes Data Through Supply Chain Breach
A recent analysis of LiteLLM, a popular AI gateway, revealed a supply chain breach that embedded malicious code designed to steal sensitive data, highlighting the vulnerability of even the most trusted components. This breach turned a multifunctional gateway meant to enhance AI agents into a vector for data theft, putting countless users at risk.

Hackers Target Asia Pacific with URL-Based Threats
In Asia Pacific, hackers are ditching traditional tactics and using URL-based threats to gain easy access to your digital life - with just one click, your security can be compromised. This emerging threat landscape is redefining how we think about online identity, access, and trust.