Emerging Threats

New npm Malware Campaign Exclusive: Severe Crypto Redirects
When the libraries you trust become trapdoors, developers are in for a rude awakening: a new npm malware campaign by dino_reborn hides in seven packages and uses cloaking and fake CAPTCHAs to selectively redirect victims to cryptocurrency phishing flows. This supply‑chain‑style attack evades scanners by activating only under certain conditions, turning convenience into a costly risk.

AI and Voter Engagement: Must-Have Strategies for Success
AI can supercharge voter engagement—translating policy, targeting outreach, and lowering barriers to participation—but without guardrails its power for hyper‑targeted persuasion and synthetic media could erode trust; here’s how to keep the gains and stop the harms.

DoorDash Confirms Data Breach: Exclusive Alarming Details
DoorDash data breach confirmed — get our exclusive, alarming details on what was exposed, who’s at risk, and the quick steps you can take right now to protect your information.

Kraken Exclusive: Dangerous Ransomware Threat Escalates
Meet Kraken ransomware: an emergent cartel that borrows proven playbooks—exploiting SMB flaws, stalking networks for days, then encrypting systems and threatening data leaks—to squeeze big payouts. Cisco Talos warns this shift from scattershot attacks to precision double‑extortion raises the stakes for already overstretched defenders and demands smarter, faster responses.

US: Exclusive Five Plead Guilty in Damaging NK IT Fraud
Five people in the U.S. pleaded guilty this year to helping North Korean hackers secure remote IT jobs with American companies — a wake-up call that remote hiring can be manipulated to mask origins, launder pay, and funnel talent and cash back to Pyongyang.

Cyber-Attack Deals Stunning Costly $258m Q2 Blow to JLR
A major ransomware incident cost Jaguar Land Rover $258m in Q2 and helped drive a $639m loss — a stark wake‑up call that a single cyber‑intrusion can paralyze networked factories for weeks. The outage halted production, delayed deliveries and squeezed suppliers as JLR prioritised a cautious, forensic‑led recovery over a rushed restart.

Akira Ransomware Stunning $244M Haul Sparks Severe Alarm
Akira ransomware has pulled in roughly $244 million since September 2025—and in some attacks thieves exfiltrated data in as little as two hours. By exploiting unpatched VPN/firewall appliances and neutralizing MFA with automated playbooks, Akira’s affiliates turn trusted defenses into rapid exit routes for high-speed extortion.

Operation Endgame 3.0: Exclusive Critical Malware Takedown
Law enforcement’s multinational takedown that removed the Rhadamanthys infostealer, neutralized VenomRAT and dismantled the Elysium botnet is a major win for international cooperation — but as malware becomes an industrialized, modular business, experts warn this victory may only be a temporary setback for adaptable criminal networks.

Cyber-Insurance Payouts Soar 230% UK Stunning Costly Spike
Think cyber insurance is a safety net? With UK payouts up 230% in 2024, rising ransoms and recovery bills are forcing businesses and regulators to rethink who will shoulder the real cost of cyber attacks.

WhatsApp Malware Exclusive: Brazil Banks’ Worst Threat
Imagine the app you use to call your mother being used to rob her bank — thats Brazils new reality as researchers link a WhatsApp-spread program called Maverick to the Coyote banking malware family. Built in .NET to decrypt, monitor and inject into banking sessions, this WhatsApp-delivered threat marks a worrying leap in scale and sophistication against Brazilian users and banks.

Qilin Ransomware Exclusive: Damaging Surge Hits Small Firms
Qilin ransomware has evolved into a commercialized threat that turns simple security lapses—phishing, weak credentials or exposed remote access—into crippling double‑extortion attacks on small and mid-sized firms. With affiliates and leak sites amplifying its reach, now’s the time for SMBs to shore up the basics before opportunistic criminals profit.

AI Companies: Stunning 65% Leak of Dangerous Secrets
A new study finds about 65% of leading AI companies have accidentally exposed sensitive secrets in public Git repositories like GitHub. Researchers warn those leaks — from API keys to model endpoints — could create stealthy “shadow access” and threaten roughly $400 billion in assets.

NCA Campaign Exclusive: Critical Crypto Scam Warning
Dont miss this NCA-exclusive crypto scam warning — learn the latest tricks scammers use and quick, practical steps to keep your crypto safe.

Sandworm Exclusive: Deadly New Wiper in Ukraine
When code refuses to start, who do you call? Fresh reports say the Russian-linked Sandworm group unleashed a new wiper malware that’s erasing backups and crippling Ukraine’s government, energy, logistics and grain networks—threatening cascading disruptions from ports to hospitals.

Gootloader malware: Exclusive alert on Dangerous Ransomware
Gootloader malware is back — a JavaScript loader that can turn a single click into a full domain takeover in roughly 17 hours. Learn how its stealthy delivery and lightning-fast lateral movement make fast, modern defenses essential.

Rigged Poker Games: Exclusive Warning on Corrupt Play
Think poker’s just luck and skill? A federal indictment reveals a high‑tech ring that rigged high‑stakes poker games—using altered shufflers, hidden cameras and covert signals—to siphon millions from unsuspecting players.

SonicWall Exclusive: State Crew Tied to Severe Breach
Think spies, not crooks — SonicWall says a state‑backed crew accessed customer firewall configuration backups, exposing blueprints for precise, targeted attacks. If you used their cloud backups, assume compromise: rotate keys and credentials, run a forensic review, and lock down remote access now.

AI-Enabled Malware: Exclusive Warning of Dangerous Rise
Imagine code that writes its own crimes — AI-generated ransomware is already spawning bespoke, evasive attacks and tailored phishing that outpace traditional defenses. Security teams worldwide are racing to detect and stop these faster, smarter threats.

Google Forecasts Stunning 2026 EU Cyber-Physical Threats
Google warns Europe is likely to face a surge of cyber-physical attacks in 2026 — digital intrusions paired with disinformation that could disrupt power, transport and industry. With legacy control systems, rushed digitization and weak third-party security widening the attack surface, now’s the time to shore up defenses.

Operation Chargeback Exclusive: Devastating €300m Fraud
Operation Chargeback uncovers a devastating €300m fraud — an exclusive look at how investigators dismantled the scheme and what you need to know to protect yourself.

Gemini AI Exclusive: Dangerous Thinking Robot Malware
What if the AI meant to amplify our thinking could be turned into thinking robot malware that rewrites itself to hide from defenders? New research shows attackers chaining prompt- and log-injection tricks to weaponize Gemini into self-modifying, persistent surveillance agents that sidestep many standard safeguards.

M&S Exclusive: Stunning £136M Cyber Cleanup Fuels Slump
Which is worse — a day of down tills or a quiet drain on cash and trust? For M&S, Aprils cyberattack did both: systems are back, but a £136m cleanup bill now threatens cash, customer confidence and the retailer’s recovery.

SMS Fraud Losses: Exclusive 11% Relief by 2026
Juniper Research predicts an 11% drop in global SMS fraud losses by 2026 — about $9 billion less — good news, but with smishing, SIM farms and brittle phone-number trust still rampant, it may be just the first step in a much bigger fight to secure SMS.

Malware-Laden Apps: Stunning Threat in 41M Play Store Installs
Think the Play Store is safe? Researchers found hundreds of malicious Android apps that slipped past vetting and amassed tens of millions of installs—using hijacked SDKs, repackaged binaries and delayed activation to turn everyday apps into stealthy attack platforms.