Skip to main content

Emerging Threats

US Charges Filed in High-Profile Crypto Hacks and Fentanyl Cases

US Charges Filed in High-Profile Crypto Hacks and Fentanyl Cases

This week's string of high-profile crypto hacks, indictments, and regulatory moves exposes a growing dilemma: as decentralized finance and crypto markets expand, the lines between crime, commerce, and policy are becoming increasingly blurred. From charged crypto hacks to fentanyl cases, the seams where these worlds meet are fraying in plain sight.

Analyst 207
Hackers Exploit React2Shell Flaw to Breach 766 Next.js Hosts

Hackers Exploit React2Shell Flaw to Breach 766 Next.js Hosts

In a massive credential harvesting operation, hackers exploited the React2Shell vulnerability to breach 766 Next.js hosts, scooping up sensitive database credentials, SSH private keys, and other valuable secrets. This single software flaw was turned into an automated threat, compromising hundreds of sites and putting their digital kingdoms at risk.

Analyst 207
Iowa AG Targets Change Healthcare Over Ransomware Lapses

Iowa AG Targets Change Healthcare Over Ransomware Lapses

Iowa's attorney general is taking a stand against UnitedHealth Group, seeking financial damages and major security overhauls after a devastating 2024 ransomware attack on its Change Healthcare unit. The bold move aims to hold the healthcare giant accountable and prevent similar cyberattacks in the future.

Analyst 207
GitHub Exposed to Infostealer Malware via Claude Code Leak

GitHub Exposed to Infostealer Malware via Claude Code Leak

A recent leak of Claude's source code has taken a dark turn, with hackers exploiting the situation to spread Vidar, a notorious infostealer malware, by creating fake GitHub repositories that masquerade as legitimate projects. This cleverly crafted bait is luring unsuspecting users into a trap that can have serious cybercrime consequences.

Analyst 207
Drift Protocol Compromised in $280 Million Heist

Drift Protocol Compromised in $280 Million Heist

In a shocking, high-stakes heist, a sophisticated threat actor exploited a vulnerability in Drift Protocol's governance, seizing control of its Security Council and making off with at least $280 million in a single, precision strike. This brazen breach serves as a stark reminder of the devastating consequences of compromised governance controls.

Analyst 207
Malware Infiltrates Leaked Claude Code Downloads

Malware Infiltrates Leaked Claude Code Downloads

Tens of thousands of people who downloaded the leaked Claude Code over the last week unknowingly installed credential-stealing malware, including Vidar stealer and GhostSocks, alongside the purported source code. This digital trap turned what seemed like open-source gold into a digital pickpocket, putting sensitive information at risk.

Analyst 207
Hasbro Hit by Data Breach, Disrupting IT Operations

Hasbro Hit by Data Breach, Disrupting IT Operations

Hasbro, the iconic toymaker behind beloved brands like Transformers, Peppa Pig, and Monopoly, has suffered a significant data breach that's disrupted its IT operations and may cause weeks-long delays in getting toys to eager kids and retailers. Despite the setback, Hasbro assures that it can still receive orders and ship products, but warns of potential delays.

Analyst 207
UK Warns of Targeted Attacks on WhatsApp and Signal Accounts

UK Warns of Targeted Attacks on WhatsApp and Signal Accounts

The UK's cybersecurity agency has issued a warning about hackers targeting WhatsApp and Signal accounts, specifically using social engineering tactics to gain access to private conversations. To stay safe, "high-risk" individuals can take steps to protect themselves from these types of cyber-attacks.

Analyst 207
Storm Infostealer Decrypts Credentials to Evade Detection

Storm Infostealer Decrypts Credentials to Evade Detection

Meet Storm, a sneaky new infostealer that's taking password theft to the next level by remotely decrypting stolen credentials, allowing hackers to slip past security defenses undetected. This game-changing tactic lets stolen passwords be used immediately, bypassing local security controls that would normally sound the alarm.

Analyst 207
GitHub Exploited in Sophisticated Malware Campaign

GitHub Exploited in Sophisticated Malware Campaign

Malicious actors have launched a sophisticated malware campaign that exploits GitHub as a covert command-and-control channel, using trusted platforms to evade detection and wreak havoc on unsuspecting organizations. This multi-stage threat employs LNK files, embedded decoders, and PowerShell to establish persistence and exfiltrate sensitive data.

Analyst 207
Akira Ransomware Executes Attacks in Under 60 Minutes

Akira Ransomware Executes Attacks in Under 60 Minutes

Akira ransomware has become alarmingly efficient, capable of executing a full-scale attack in under 60 minutes - leaving organizations with an incredibly tight window to detect and respond to threats. This lightning-fast strike highlights the urgent need for robust security measures to counter the rapidly evolving ransomware landscape.

Analyst 207
Bugs Chain Into Massive Backdoors, Threats Multiply

Bugs Chain Into Massive Backdoors, Threats Multiply

When small flaws are linked together, they can create massive backdoors - and the latest ThreatsDay Bulletin is sounding the alarm on this rapidly escalating threat landscape. The result? A multiplying list of active problems demanding attention now.

Analyst 207
Threat Actors Exploit Vacant Homes to Intercept Mail for Fraud

Threat Actors Exploit Vacant Homes to Intercept Mail for Fraud

Threat actors are exploiting vacant homes as postal drop points to intercept and manipulate mail, converting a traditional weakness into a powerful tool for fraud. This emerging hybrid scam combines physical-world tactics with digital deception, allowing criminals to fabricate identities and wreak havoc on unsuspecting victims.

Analyst 207
Stryker Recovers from Data-Wiping Cyberattack Claimed by Handala Hackers

Stryker Recovers from Data-Wiping Cyberattack Claimed by Handala Hackers

In a remarkable comeback, Stryker Corporation has bounced back to full operation just three weeks after a devastating data-wiping cyberattack erased many of its systems, claimed by the Iranian-linked Handala hacktivist group. The global medical-technology giant has successfully restored its operations, showcasing resilience in the face of cyber threats.

Analyst 207
Progress ShareFile Flaws Enable Pre-Auth RCE Attacks

Progress ShareFile Flaws Enable Pre-Auth RCE Attacks

When the tool designed to safeguard confidential documents becomes a vulnerability, data theft can occur without a single login credential. Progress ShareFile's two chained flaws allow for pre-authentication remote code execution attacks, putting sensitive files at risk of unauthorized exfiltration.

Analyst 207
Fake ISO Installers Spread RATs, Crypto Miners in Global Campaign

Fake ISO Installers Spread RATs, Crypto Miners in Global Campaign

Beware of fake ISO installers that masquerade as legitimate software, but secretly unleash a malicious payload of RATs, crypto miners, and CPA fraud on unsuspecting victims. For over two years, a financially motivated operation, codenamed REF1695, has been quietly spreading malware through these Trojan horses.

Analyst 207
Google Exposes Sophisticated iPhone Hacking Tool Likely Tied to US Government

Google Exposes Sophisticated iPhone Hacking Tool Likely Tied to US Government

Imagine a single website visit being all it takes to secretly install malware on your iPhone, bypassing every defense along the way - that's the alarming reality uncovered by Google's security researchers. They've discovered a sophisticated hacking tool, dubbed Coruna, that exploits 23 iOS vulnerabilities to silently compromise devices.

Analyst 207
WhatsApp Exposes Italian Users to Spyware via Fake iOS App

WhatsApp Exposes Italian Users to Spyware via Fake iOS App

WhatsApp has alerted around 200 users, mostly in Italy, about a sneaky spyware attack that hit them after they downloaded a fake version of the app for iOS. This alarming incident raises a crucial question: how can you trust that the app on your phone is genuine?

Analyst 207
Microsoft Probes Outlook Disruption Tied to Email Delivery Issues

Microsoft Probes Outlook Disruption Tied to Email Delivery Issues

Microsoft is investigating a frustrating issue affecting Classic Outlook users, preventing them from sending emails via Outlook.com due to a bug linked to broader email delivery problems. The disruption is causing inconvenience for users relying on seamless communication.

Analyst 207
F5 BIG-IP Instances Vulnerable to Ongoing RCE Attacks

F5 BIG-IP Instances Vulnerable to Ongoing RCE Attacks

With over 14,000 F5 BIG-IP Access Policy Manager instances exposed online, a critical vulnerability is putting countless systems at risk of remote code execution attacks. Attackers are actively exploiting this flaw, making it crucial for organizations to take immediate action to protect themselves.

Analyst 207
OT Attacks Threaten £5m Downtime Hit on CNI Firms

OT Attacks Threaten £5m Downtime Hit on CNI Firms

A single cyberattack on operational technology systems could cripple critical infrastructure providers, causing up to £5m in downtime losses and days of operational paralysis. For organisations that underpin essential services, the stakes have never been higher.

Analyst 207
Mercor Hit in Widespread LiteLLM Supply-Chain Attack

Mercor Hit in Widespread LiteLLM Supply-Chain Attack

Thousands of companies, including AI hiring startup Mercor, have been hit by a widespread LiteLLM supply-chain attack, marking the first publicly disclosed downstream casualty of a software supply-chain intrusion. This incident raises a critical question: how can organizations trust their tech toolchains when the chain itself can be compromised?

Analyst 207
CrystalRAT Malware Emerges with Advanced RAT and Data Theft Capabilities

CrystalRAT Malware Emerges with Advanced RAT and Data Theft Capabilities

Meet CrystalRAT, a powerful malware-as-a-service that's being sold on Telegram, capable of giving outsiders remote control of your computer, stealing sensitive files, recording every keystroke, and even hijacking your clipboard. This malicious tool is a nightmare come true, and its emergence poses a serious threat to online security.

Analyst 207
Hackers Exploit TrueConf Flaw to Deploy Malicious Updates

Hackers Exploit TrueConf Flaw to Deploy Malicious Updates

Imagine the video conferencing platform you rely on to connect with your team being turned against you, allowing hackers to spread malicious software to everyone in the room. A recently discovered zero-day flaw in TrueConf's update mechanism has been exploited by threat actors to deliver and execute malicious files on connected devices.

Analyst 207