Emerging Threats

60% of Security Leaders: Stunning, Critical Threat Shift
Sixty percent of security leaders warn that threat actors are evolving too quickly for organizations to keep up. Commodified cybercrime, automation and an expanding attack surface are squeezing defenders’ time to detect, respond and contain — and the consequences are real.

85,000 Pet Owner Records Exposed: Exclusive Critical Risk
A misconfigured database left 85,000 pet‑owner records — from names and addresses to medical notes and microchip IDs — publicly accessible, creating a roadmap for scammers, identity thieves and even pet‑theft. Here’s what was exposed, how it happened, and simple steps to protect your pet and family.

WestJet Alerts Americans: Exclusive Serious Data Breach
WestJet data breach: the airline says a June intrusion may have exposed passport numbers, loyalty IDs and travel details for about 1.2 million U.S. customers—here’s why that raises your scam risk and what to do next.

145,000 Healthcare Records Exposed Exclusive Severe Breach
Imagine your most private medical moments sitting on a public server — thats what happened when a misconfigured database left roughly 145,000 healthcare records exposed. Names, contact details and treatment notes were accessible online, raising urgent questions about who saw them and how to prevent the next breach.

5M Records Exposed Exclusive: Severe Auto Insurance Leak
Heads up: an unsecured database exposed more than 5 million auto-insurance records—names, policy numbers, VINs and claims—available to anyone with a link. That makes drivers prime targets for phishing, fake claims and identity theft, and could spell major legal and reputational headaches for insurers.

5M Records Exposed Exclusive: Alarming Auto Insurance Leak
5M Records Exposed: a password-free database left names, policy numbers, VINs and claims data for more than five million auto insurance customers readable by anyone with a browser. That simple lapse turns everyday details into easy fodder for phishing, fake claims and identity theft — and shows how a tiny mistake can create big, long-lasting risk.

WestJet Exclusive Alert: Critical Data Breach Notified
WestJet Exclusive Alert: A June cyber intrusion may have exposed travel and loyalty-account data for roughly 1.2 million customers—including U.S. residents—so check your accounts now. WestJet says it’s working with forensic experts and law enforcement, but this notice is your cue to watch for phishing, reset passwords, and protect your identity.

WestJet Notifies Americans of Exclusive Data Breach Risk
WestJet told U.S. customers that a criminal intrusion discovered in June may have exposed personal and loyalty-account information—potentially affecting hundreds of thousands to over a million travelers—and has raised tough questions about who safeguards the sensitive travel data airlines collect. More than an operational headache, the breach highlights how legacy systems and third‑party connections can turn travel records into prime targets for phishing and identity fraud.

5M Records Exposed: Exclusive Damaging Auto Insurance Leak
Imagine a stranger flipping through the policies that underwrite your life on the road: more than five million auto insurance records—names, policy numbers, VINs and claims—were left in an unsecured online database anyone could download. Heres what went wrong, whos at risk, and what you can do to protect yourself.

LockBit Exclusive: Critical New Victims Identified
LockBit’s latest iteration is back—and meaner: researchers found a cross-platform strain in September that can encrypt Windows, Linux and VMware ESXi in a single strike, shrinking defenders’ response window and multiplying damage. If you haven’t expanded EDR to Linux and hypervisors or tested immutable backups yet, now’s the time.

LockBit Exclusive: Critical New Victims Revealed
LockBit keeps changing its playbook—September telemetry uncovered roughly a dozen incidents, about half tied to a new strain that can hit Windows, Linux and hypervisors. That cross‑platform reach broadens the blast radius from a single breach and forces defenders to rethink old assumptions.

Threat Actors: Exclusive Surge in Dangerous App Exploits
Exclusive: Threat actors are unleashing a dangerous surge in app exploits—here’s what’s driving the spike and quick, practical steps to keep your apps and users safe.

LockBit Ransomware Exclusive: Severe Victims Revealed
An updated LockBit variant—faster, stealthier and able to run native payloads on Windows, Linux and VMware ESXi—has been tied to a dozen recent intrusions, dramatically shrinking the window defenders have to detect and stop catastrophic outages.

Pakistani-Linked Hacker Group: Exclusive Threat to India
Pakistan-linked operators are quietly slipping DeskRAT into Indian government networks to siphon secrets — a stealthy espionage campaign that makes stronger detection, logging and diplomatic response urgent.

Pakistani-Linked Hacker Group: Exclusive Severe India Hack
A Pakistani-linked hacker group reportedly pulled off a severe, exclusive cyberattack on India — here’s who’s behind it and why the fallout matters for national and regional security.

Lazarus Group Exclusive: Critical Threat to Europe’s Defense
Who’s stealing Europe’s drone blueprints — and why? Investigators now point to North Korea’s Lazarus Group and Operation DreamJob, a stealthy campaign targeting small defense firms to grab design files, accelerate domestic drone programs, and probe weaknesses in Europe’s nascent “drone wall.”

Pakistani-Linked Hacker Group Exclusive: Major India Breach
A Pakistan-linked group called TransparentTribe quietly deployed the DeskRAT trojan to infiltrate Indian government networks, harvesting credentials and sensitive documents over months. The patient, espionage-focused campaign raises urgent questions about when cyber intrusions become acts of war.

Lazarus Group Exclusive: Stunning Threat to EU Defense
Europe’s drone industry is being stalked by North Korea’s Lazarus Group, which used fake recruitment DreamJob lures to slip malware into engineers’ inboxes and siphon designs, test data and R&D secrets. The campaign shows how porous modern research networks are—and how cyber espionage can become a direct, strategic threat to EU defence and supply‑chain security.

Lazarus Group Exclusive: Dire Threat to European Defense
Who watches the watchers? Researchers say North Korea’s Lazarus Group—behind Operation “DreamJob”—has quietly infiltrated European drone and counter‑UAS R&D to steal designs, credentials and test data, putting the continent’s push for a layered “drone wall” at real risk of espionage, sabotage and costly setbacks.

Lazarus Group Exclusive: DreamJob Threatens EU Defenses
“If you build it, they will steal it” — North Korea’s Lazarus Group is quietly targeting EU drone engineers, lifting schematics, firmware, and supplier data to speed or sabotage adversaries’ emulation of Western platforms. The result: stolen designs and corrupted files that can derail production and readiness without a single shot fired.

Lumma Stealer Exclusive: Vidar 2.0 Fuels Dangerous Rise
The Lumma Stealer leak has supercharged Vidar 2.0, recycling stolen credentials and exposed code into a stealthier, cheaper toolkit for criminals. Trend Micro warns defenders to brace for rising Vidar 2.0 activity through Q4 2025.

Lumma Stealer Exclusive: Upgraded Vidar 2.0 Sparks Threat
A marketplace leak proves Vidar 2.0 (Vidar 20) is evolving into a commercially sold, regularly updated threat—Trend Micro warns it will surge through Q4 2025, so defenders must choose urgent action over complacency.

Lumma Stealer Vacuum Exclusive Dangerous Vidar 2.0 Upgrade
From the public doxxing of Lumma Stealer to the resurfacing of Vidar 2.0, the cybercrime scene is behaving more like a ruthless software market — and that escalation puts millions of credentials and finances at risk. Security teams take note: analysts expect a rise in sophisticated stealer activity through Q4 2025.

Scattered Lapsus$ Hunters Reveal Exclusive Dangerous Shift
What happens when the gang you expected to fight splinters into thousands of anonymous, paid hands? Researchers warn that Scattered Lapsus$ Hunters are weaponizing tiny bitcoin bounties to crowdsource harassment, creating plausible deniability and a whole new kind of security nightmare.