Emerging Threats

FBI Warns: Exclusive Alert on Dangerous Fake Video Scams
If a stranger texts you a video of a loved one and demands ransom, don’t panic — the FBI warns these terrifying scams are increasingly powered by generative AI. Learn how synthetic photos, fleeting messages, and emotional pressure are used to extort victims and what signs can expose the fraud.

AI vs. Human Drivers: Stunning Proof of Dangerous Flaws
We’re sold on driverless cars as a lifesaving leap, but mounting research and exposés reveal troubling failure modes—from hidden “sleeper” backdoors that trigger only in rare conditions to social and regulatory blind spots that could multiply harm at scale.

Marquis Software Breach Devastating: Exclusive Analysis
A misconfigured firewall at Marquis Software exposed sensitive records for more than 780,000 Americans — a wake-up call that one small lapse can cascade into national risk and demands urgent fixes, transparency, and stronger security.

New Android Albiriox Malware Exclusive: Dangerous Surge
Albiriox malware is being sold like a subscription, turning smartphones into turnkey crime tools that give even novice operators remote takeover, credential harvesting, and live‑fraud capabilities. That MaaS model lowers the bar for attackers and creates an industrialized path from infection to immediate theft that security teams and users now must reckon with.

Coupang Confirms Stunning, Damaging Leak of 34M Customers
If youve shopped on Coupang, keep an eye on your accounts: the company confirmed a suspected cyber-attack exposed personal data for about 34 million customers, prompting a police probe and warnings about fraud. The breach lays bare how one‑click convenience concentrates risk and is fueling renewed calls for tougher data safeguards.

Malware Stunningly Evades AI in Critical npm Breach
Think your npm packages are safe? Researchers found a malicious npm package that talks to a remote AI-like controller, adapting at runtime to dodge scanners and quietly steal valuable data.

Royal Borough of Kensington and Chelsea Exclusive: Major Leak
A suspected ransomware attack on the Royal Borough of Kensington and Chelsea is a stark wake-up call about how much of our lives we trust to local councils. Beyond locked systems, exposed personal records and disrupted services can leave residents — especially the vulnerable — at risk of fraud, identity theft and real harm.

French Football Federation Exclusive: Damaging Data Breach
Imagine names, birthdates and contact details for more than two million amateur players suddenly exposed — that’s the frightening possibility tied to a suspected breach at the French Football Federation. Players and parents should be on alert for phishing and scams while the federation works to lock down access and notify those affected.

FCC Warns: Exclusive Threat of False Radio Alerts
The FCC is sounding the alarm on false radio alerts—here’s how to spot bogus broadcasts and protect yourself from dangerous misinformation on the airwaves.

Bloody Wolf Expands in Central Asia Exclusive Danger
As Bloody Wolf expands across Central Asia, attackers are repurposing trusted remote‑administration tools to slip quietly into government networks and exfiltrate sensitive data. That shift from noisy attacks to stealthy intelligence gathering leaves smaller states scrambling to detect and respond.

Fraud Fears: Exclusive Reassuring Outlook for Holidays
Worried about holiday fraud? ICO data shows no Q4 2024 spike in reported data breaches — a reassuring sign, but one that forces us to ask whether criminals have gone stealthier or our reporting systems are missing the real threat.

Shai-Hulud v2 Exclusive: Dangerous Spread Exposes Secrets
Shai‑Hulud’s second wave has jumped from npm into Maven, turning trusted packages into a secret‑stealing worm that probes CI and environment tokens and self‑replicates through dependencies. If you build or secure software, now’s the moment to rotate credentials, harden pipelines, and vet every dependency.

Cyber-Attack Exclusive: Severe OnSolve CodeRED Outage
Imagine the sirens going silent: when INC Ransom hit OnSolve’s CodeRED, communities missed vital alerts and scrambled to improvise slow, unreliable backups. The outage — and exposed user data — lays bare how dangerously dependent public safety has become on just a few commercial providers.

Huawei Exclusive: Dangerous Chinese Surveillance Risks
Leaked reporting lays bare how Chinese surveillance has flowed from labs into startups, turning facial recognition, NLP and phone‑forensics into commercial tools sold to local governments. What looks like efficient security is increasingly opaque — and alarmingly easy to repurpose for control.

RomCom: Exclusive Warning on Dangerous SocGholish Malware
Exclusive warning: attackers are now pairing the SocGholish social-engineering loader with the RomCom malware family to deliver Mythic Agent via convincing fake update prompts, turning routine installs into persistent backdoors. Read on to see how this clever combo exploits trusted software and everyday habits—and what you can do to stop it.

Smishing Triad Impersonation Campaigns: Exclusive Threat
Think that bank-looking text is really from your provider? Smishing Triad attackers now pair believable sender IDs with lookalike Egyptian domains, SIM farms and hijacked devices to harvest credentials and bypass 2FA—one click can mean compromise.

Iberia Airlines Exclusive: Critical Supply Chain Breach
When Iberia alerts customers that a supplier was compromised, it’s a reminder that a single supply‑chain breach can ripple into delays, data exposure and broader operational headaches across modern travel. If you got the email, here’s what it means for your trip and what to look out for next.

Rewiring Democracy Exclusive: Best Paths for Reform
Rewiring Democracy asks: as AI rewrites our political infrastructure, who will teach the machines to learn — and safeguard — our democratic values? This urgent, clear-eyed book maps the reforms we need before algorithms reshape civic life.

UNC2891 Money Mule Network Exclusive: Devastating ATM Fraud
Meet UNC2891: a slick, multi-year fraud machine that cloned bank cards and used fake job postings to recruit a vast money-mule network. By coordinating synchronized ATM cash-outs across borders, they turned digital theft into physical cash — a chilling playbook and a wake-up call for banks and consumers.

Gartner Warns: Stunning Shadow AI Risk to 40% of Firms
Turns out the handy AI tools employees love could be your companys hidden threat: Gartner warns that by 2030, 40% of firms will face security or compliance incidents from shadow AI—unsanctioned consumer or third‑party models that can leak PII, payment data and trade secrets. Convenience is great until it becomes a costly regulatory and financial headache.

UK, US and Australia Sanction Media Land – Stunning Blow
When protected at all costs becomes a shield for criminals, the UK, US and Australia moved in — jointly sanctioning a bulletproof hosting provider and four executives to choke off the infrastructure behind ransomware, scams and other cybercrime.

Europol Operation: Stunning, Devastating $55M Crypto Bust
Europes Cyber‑Patrol Week used blockchain forensics and cross‑border raids to disrupt crypto services moving roughly $55 million, delivering a stunning, devastating blow to criminal money‑movement rails. The takedown shows how improved tracing and private‑sector cooperation can unmask operators — even as some legitimate users lose a layer of convenience.

New npm Malware Campaign Exclusive: Severe Crypto Redirects
When the libraries you trust become trapdoors, developers are in for a rude awakening: a new npm malware campaign by dino_reborn hides in seven packages and uses cloaking and fake CAPTCHAs to selectively redirect victims to cryptocurrency phishing flows. This supply‑chain‑style attack evades scanners by activating only under certain conditions, turning convenience into a costly risk.

AI and Voter Engagement: Must-Have Strategies for Success
AI can supercharge voter engagement—translating policy, targeting outreach, and lowering barriers to participation—but without guardrails its power for hyper‑targeted persuasion and synthetic media could erode trust; here’s how to keep the gains and stop the harms.