Emerging Threats

Hackers Exploit React2Shell in Widespread Credential Theft Drive
Hackers are on the prowl, exploiting the React2Shell flaw (CVE-2025-55182) to steal sensitive credentials from vulnerable Next.js applications on a massive scale. With a single vulnerability, they can wreak havoc - the question is, how many credentials will be compromised before a patch is applied?

Fortinet Fixes Exploited Flaw in FortiClient EMS Software
Fortinet has urgently patched a critical vulnerability in its FortiClient EMS software, which had already been exploited in the wild, to prevent further security breaches. The flaw, tracked as CVE-2026-35616, allows for pre-authentication API access bypass and privilege escalation, posing a significant threat to endpoint security.

LinkedIn Harvests Browser Data with Secret Chrome Extension Scans
A recent report, dubbed BrowserGate, uncovers LinkedIn's hidden practice of scanning visitors' browsers for installed extensions and harvesting device data, raising serious questions about user privacy. The professional social network reportedly checks for over 6,000 Chrome extensions, leaving users to wonder: what should LinkedIn know about your browser?

Device Code Phishing Attacks Proliferate as OAuth Abuse Kits Spread
This year, device code phishing attacks have skyrocketed, surging over 37 times as new OAuth abuse kits make it easier for hackers to hijack accounts. The alarming rise puts account security at risk, leaving many users wondering if the accounts they think are safe really belong to them.

LiteLLM Supply-Chain Compromise Exposes Mercor Data
A single faulty AI dependency can become a backdoor for attackers - as seen in the recent LiteLLM supply-chain compromise that exposed sensitive data, source code, and internal credentials at Mercor. This alarming incident highlights the risks of relying on third-party dependencies and the importance of securing your supply chain.

Stryker Restores Manufacturing Systems After Iranian Hacktivist Attack
Stryker has successfully restored its manufacturing systems after a devastating cyberattack by an Iranian hacktivist group caused a global outage, and is now operating at full capacity across its global network. The company is still investigating the incident, but is reassuring customers that all is back to normal.

TA416 Targets Europe with OAuth Phishing and PlugX Malware
A China-aligned cyber threat, known as TA416, has resurfaced in Europe, targeting government and diplomatic networks with OAuth phishing and PlugX malware, raising concerns about intent and defensive readiness. This renewed focus comes after a two-year lull, with the threat actor employing new tactics to infiltrate European organizations.

Hims & Hers Discloses Data Breach After Zendesk Ticket Compromise
Hims & Hers Health has alerted customers to a data breach after sensitive support tickets were stolen from a third-party platform operated by Zendesk, raising concerns about consumer safety when sharing personal info online. The breach exposed data from support tickets, highlighting the vulnerability of sensitive transactions on external systems.

Microsoft Uncovers Cookie-Based Web Shells Persisting on Linux Servers
Microsoft's latest discovery reveals a sneaky new tactic: hackers are hiding malicious commands in browser cookies to secretly control compromised Linux servers. This clever trick forces us to rethink what we consider normal web traffic and take a closer look at the potential threats lurking in plain sight.

Qilin Ransomware Targets German Political Party Die Linke
Die Linke, a German political party, has fallen victim to a crippling Qilin ransomware attack, forcing a shutdown of its IT systems and compromising sensitive data. The Qilin group has claimed responsibility, threatening to leak stolen information unless demands are met.

Nation-State Hackers Exploit Cloud Services for Global Espionage
In the shadows of the digital world, nation-state hackers are quietly exploiting cloud services to orchestrate global cyber espionage - but how can organizations, governments, and individuals defend against threats they can't see? The hidden world of cyber espionage poses a daunting question: what's at stake when the invisible forces of cyber threats manipulate the systems we rely on?

Ransomware Attacks Evolve to Exploit Stolen Data for Double Extortion
Ransomware attacks have taken a sinister turn, now using stolen data to blackmail victims into paying up - not just by encrypting their files, but by threatening to expose sensitive information to the world. This double extortion tactic adds a whole new level of pressure, forcing victims to weigh the cost of a data breach against the cost of a ransom.

Venom Phishing Platform Targets C-Suite Execs in Credential Theft Campaigns
Meet Venom, a sneaky new phishing platform that's putting top executives in its crosshairs, threatening to drain their credentials and wreak havoc on corporate boardrooms. This automated threat is scaling up credential theft like never before, making it a high-risk concern for senior leaders and their organizations.

Mercor AI Startup Discloses Data Breach Involving Open AI, Anthropic Partnerships
Mercor, an AI startup partnered with industry giants OpenAI and Anthropic, has confirmed a data breach - raising concerns about the potential impact on users and the company's ability to regain trust. The incident has left many questions unanswered, including what data was compromised and who might be affected.

North Korean Hackers Target Axios Maintainer in Supply Chain Breach
A shocking supply chain breach has been uncovered, where North Korean hackers launched a highly targeted social engineering campaign against the maintainer of the Axios npm package, successfully altering code relied upon by others. The attackers' tailored approach raises urgent questions about trust and vulnerability in open-source ecosystems.

Zoom Meetings Exposed by Rogue Web Service
Meetings meant to be private, ended up being public. A rogue web service called WebinarTV has been exploiting Zoom meeting security by searching for publicly available invites, joining and secretly recording sessions, and publishing them online.

Microsoft Grapples with Weeks-Long Exchange Online Mailbox Access Disruptions
Weeks of frustrating disruptions have left Outlook mobile and macOS users struggling to access their Exchange Online mailboxes, sparking a flurry of questions about reliability and resolution. Microsoft is actively investigating the issue, but for affected users, the wait for a fix continues.

Drift Protocol Exploited for $285 Million in Novel Social Engineering Attack
In a shocking turn of events, the Drift Protocol, a Solana-based decentralized exchange, was exploited for a staggering $285 million in a highly sophisticated social engineering attack involving durable nonces. This novel attack allowed malicious actors to swiftly gain control of the platform's administrative powers, resulting in a massive loss of funds.

Engineer Pleads Guilty to Ransomware Extortion Plot Targeting Industrial Firm
A former infrastructure engineer has pleaded guilty to a ransomware extortion plot that targeted his own employer, an industrial firm in New Jersey, by locking administrators out of 254 servers. This shocking breach of trust highlights the devastating consequences of insider threats in the digital age.

Malware Resurfaces in Mobile Apps, Targets Crypto Wallets
Beware of a sneaky new malware hiding in plain sight on both app stores, designed to steal sensitive crypto wallet recovery phrases from unsuspecting users. This deceptive SparkCat variant masquerades as harmless apps, putting your digital assets at risk.

European Commission Cloud Hack Compromises 30 EU Entities
A massive cloud hack has struck the European Commission, compromising the data of at least 30 EU entities, including the Commission itself, at the hands of the notorious threat group TeamPCP. This alarming breach raises critical questions about who holds the keys to the EU's cloud and what happens when they fall into the wrong hands.

Drift Protocol Exploited for $280 Million by North Korean Hackers
In a shocking and sophisticated attack, North Korean hackers seized control of the Drift Protocol's Security Council, resulting in a staggering loss of at least $280 million. This brazen exploit raises serious questions about the security of even the most trusted blockchain platforms.

FBI System Breach Exposes Sensitive Data
A major breach of an FBI system has sent shockwaves through the cybersecurity landscape, leaving organizations and individuals wondering if they're prepared for the worst. This alarming incident is just the latest in a string of high-profile hacks, including a data leak affecting 450,000 Lloyds records and a breach at the Dutch treasury.

US Charges Filed in High-Profile Crypto Hacks and Fentanyl Cases
This week's string of high-profile crypto hacks, indictments, and regulatory moves exposes a growing dilemma: as decentralized finance and crypto markets expand, the lines between crime, commerce, and policy are becoming increasingly blurred. From charged crypto hacks to fentanyl cases, the seams where these worlds meet are fraying in plain sight.