Emerging Threats

KrebsOnSecurity.com Exclusive: Best Security Insights at 16
For its 16th year, KrebsOnSecurity pulls back the curtain on how organized extortion rings, DDoS‑for‑hire botnets and scaled social‑engineering tradecraft turned lone hackers into multimillion‑dollar criminal businesses.

Aisuru and Kimwolf Botnets Exclusive: Damaging Findings
Get the inside scoop on the Aisuru and Kimwolf botnets—exclusive findings reveal how they spread, the damage theyre causing, and smart steps to protect your systems.

Most Parked Domains Now a Stunningly Dangerous Threat
Think typing a URL is safe? New research shows most parked domains—expired, dormant, or misspelled names—now funnel visitors into scams, fake installers and malware, so a simple typo or old bookmark can turn into a costly trap.

Drones to Diplomas: Exclusive Damning Link to Essay Mill
Think essay mills are just a campus nuisance? A new investigation reveals a $25M ad‑driven cheating network that used Google search ads to funnel students to essay services — and whose money trail ties to a Kremlin‑connected oligarch and a Russian university involved in attack drone development, turning academic dishonesty into a national security worry.

Drones to Diplomas: Exclusive Damning $25M Essay Mill Link
Get the inside scoop on a $25M essay mill tying drones to diplomas—our exclusive exposé reveals how the scheme works and why it matters for students and educators alike.

Rey Exclusive: Inside the Best Scattered Lapsus$ Admin
When a reporter called his father and unmasked Rey, the public face of Scattered LAPSUS$ Hunters, it upended a group built on anonymity and exposed how social‑engineering, account takeovers and micropaid crowds power a new, scalable extortion playbook. The fallout forces a rare reckoning about motive, accountability—and the practical fixes defenders and regulators can’t ignore.

Putinswap Exclusive: Controversial Ransomware Swap
When diplomacy, law enforcement and cybercrime collide, messy deals get made. France’s controversial exchange — freeing a man accused of acting as a ransomware payment negotiator in return for a Swiss NGO consultant detained in Russia — raises urgent questions about justice, precedent and who we choose to protect.

Ransomware Exclusive: Stunning Worst Surge of 2025
Think ransomware was fading? The 2025 ransomware surge proves otherwise—smarter, faster attacks (retail incidents jumped 58% in Q2) are crippling stores, exposing data and stretching insurers and regulators to the breaking point.

Ransomware Exclusive: Alarming Rise in 2025 Attacks
Think 2025 would be the year ransomware cooled off? Think again—publicly disclosed ransomware incidents spiked dramatically as attackers pivoted to fast, high-volume strikes that hit retailers, healthcare, local governments and small businesses with encryption, data theft and public shaming, costing victims downtime, fines and shattered trust.

Ransomware attacks Exclusive 2025 surge: Devastating rise
Thought ransomware attacks were fading? In 2025 they surged back—publicly disclosed retail incidents spiked 58% in Q2, turning our everyday stores into high-stakes targets for encryption, data theft and extortion.

UK regulators Exclusive: Damaging X probe over Grok nudes
What happens when an AI meant for chat starts generating intimate images of real people? UK regulators, lawyers and users are probing Grok nudes — and X could face serious enforcement under the Online Safety Act.

AI Exclusive: Dangerous Vibe-Code Malware Surge
Playful vibe coding—quick, AI-assisted tinkering—has slid into the criminal underground, letting amateurs spin up adaptive ransomware, cryptominers and hyper-personalized phishing at speed. The result is a weird mix of sloppy charm and real danger as generative tools turn into a malware force‑multiplier.

Transparent Tribe Targets India: Exclusive Severe RAT Alert
Heads up: Transparent Tribe is slipping weaponized .LNK shortcut files disguised as PDFs into spear-phishing emails, silently installing a remote-access trojan that can steal data and maintain persistent access to Indian government, academic, and strategic networks.

AI-Generated Images: Stunning Guide to Effortless Refunds
When generative AI can fake a broken toaster, refunds become a trust lottery. This guide breaks down how cheap, scalable image fraud works and who ends up paying the price.

INTERPOL Stunning Crackdown: 574 Arrested in Africa, Guilty
INTERPOLs month‑long Operation Sentinel arrested 574 suspects across 19 African countries and recovered roughly $3 million — a major strike against business email compromise and digital extortion, but a reminder that arrests must be paired with legal, financial and technical reforms to truly stop these agile cyber gangs.

Security Leaders Exclusive: Damaging Marquis Breach
The Marquis data breach exposed hundreds of thousands of tax‑credit records — and it asks a blunt question: when trust is the currency, who pays? Security leaders say this wasn’t a freak accident but a familiar mix of human error, misconfiguration and governance gaps that proves convenience still too often outpaces caution.

Security Leaders Exclusive: Critical Take on Marquis Breach
Nearly 250,000 Americans had their tax‑credit records exposed in the Marquis breach — a wake‑up call that this wasnt just a technical slip but a systemic security failure companies, regulators, and consumers must fix together. Experts break down what went wrong, who’s accountable, and the urgent steps to protect victims and prevent the next catastrophe.

Security Leaders Exclusive: Alarming Marquis Breach Insight
The Marquis data breach forces a simple but urgent question: when a trusted provider is compromised, who pays — the vendor, its customers, or the wider ecosystem? With attackers evolving faster than defenders, security leaders say it’s time to rethink third‑party and supply‑chain risk.

After Email Hacking, Campus Faces Stunning Costly Breach
The University of Pennsylvania breach began with an Oct. 31 email hack that quickly escalated into a far costlier intrusion, leaving students and staff scrambling and officials grappling with steep financial and operational fallout. Its a stark reminder that a single compromised inbox can cascade into widespread harm for campuses everywhere.

Coupang Breach: Stunning Damage Hits 34M, Leaders React
Coupang breach jolted roughly 34 million customers after attackers used vishing and compromised vendor channels to steal—and then extort—sensitive data; here’s what went wrong and what customers and companies need to do next.

Coupang Breach Exclusive: Critical Response to 34M
The Coupang data breach affecting 34 million customers shows that stolen contact and profile details—even without payment or authentication theft—can fuel highly convincing phishing, impersonation and downstream fraud. Security leaders warn the real damage is erosion of trust, not just downtime.

HMRC Exclusive: Alarming 135K Scam Reports
HMRC logged 135,500 suspected scam reports in ten months — nearly 4,800 tied to self‑assessment — showing fraudsters are getting craftier with texts, calls and AI‑generated lures. Here’s what to watch for and how to protect yourself.

FBI Warns: Exclusive Alert on Dangerous Fake Video Scams
If a stranger texts you a video of a loved one and demands ransom, don’t panic — the FBI warns these terrifying scams are increasingly powered by generative AI. Learn how synthetic photos, fleeting messages, and emotional pressure are used to extort victims and what signs can expose the fraud.

AI vs. Human Drivers: Stunning Proof of Dangerous Flaws
We’re sold on driverless cars as a lifesaving leap, but mounting research and exposés reveal troubling failure modes—from hidden “sleeper” backdoors that trigger only in rare conditions to social and regulatory blind spots that could multiply harm at scale.