Skip to main content

Emerging Threats

Scattered Lapsus$ Hunters Reveal Exclusive Dangerous Shift

Scattered Lapsus$ Hunters Reveal Exclusive Dangerous Shift

What happens when the gang you expected to fight splinters into thousands of anonymous, paid hands? Researchers warn that Scattered Lapsus$ Hunters are weaponizing tiny bitcoin bounties to crowdsource harassment, creating plausible deniability and a whole new kind of security nightmare.

Analyst 207
Scattered Lapsus$ Hunters: Exclusive Alarming Tactic Shift

Scattered Lapsus$ Hunters: Exclusive Alarming Tactic Shift

Scattered Lapsus$ Hunters are reportedly swapping big-data breaches for micropaid crowdsourcing: tiny Bitcoin bounties to many contributors to flood executives with calls, DMs and mentions. Its a cheap, scalable harassment‑for‑hire tactic that blurs into extortion and could leave platforms and regulators flat-footed.

Analyst 207
Singapore Officials Targeted in Stunning Damaging Scam

Singapore Officials Targeted in Stunning Damaging Scam

A stunning Singapore officials scam has exposed shocking vulnerabilities—discover how the damaging scheme unfolded and what it means for public trust.

Analyst 207
Scattered Spider Duo: Exclusive Shocking $115M Ransom Link

Scattered Spider Duo: Exclusive Shocking $115M Ransom Link

Imagine lights going out at your hospital or your commute being held hostage — and the alleged architects are teenagers. The newly unsealed indictment accuses Scattered Spider of using social engineering and telecom hacks to extract at least $115M in ransoms, turning account takeovers into real‑world chaos.

Analyst 207
ShinyHunters Exclusive: Damaging Corporate Extortion Wave

ShinyHunters Exclusive: Damaging Corporate Extortion Wave

The ShinyHunters campaign has escalated from quiet database dumps to brazen public extortion—naming victims, posting timetables, and using voice‑phishing plus massive file thefts that could turn single breaches into a supply‑chain crisis. Corporations now face a stark choice: pay ransoms or risk a public dump of sensitive customer and corporate data.

Analyst 207
Massive tangled worm emerges from cracked package box amidst shattered screens and wires, with ominous cityscape looming in…

Self-Replicating Worm: Stunning Threat Hits 180+ Packages

A stark wake-up call: a self-replicating worm has infected 187+ NPM packages, stealing and publicly exposing developer tokens during installs. By weaponizing automated installs and transitive dependencies, it turns every npm install into a potential propagation engine.

Analyst 207
Bulletproof Host Exclusive: Stark’s Controversial EU Evasion

Bulletproof Host Exclusive: Stark’s Controversial EU Evasion

When the EU froze Stark Industries Solutions — a notorious bulletproof hosting provider tied to Kremlin-linked cyberattacks — the aim was to choke off dangerous infrastructure, but months later the same IPs and services resurfaced under new shells. That rapid reconstitution shows how sanctions on paper can fail when operators lean on bulletproof hosting to keep malware, botnets, and disinformation campaigns alive.

Analyst 207
Person in shadows sits before laptop with eerie glow, amidst scattered papers and a remote, with a cityscape of India in…

APT36 Exclusive: Critical Golang DeskRAT Threat to India

Heres the scoop: a targeted spear-phishing campaign installed DeskRAT—a compact, Golang-based remote access tool linked to APT36—into Indian government systems, letting attackers read emails, capture keystrokes and siphon sensitive files. Lightweight and cross-platform, DeskRAT underscores how APT36’s patient social-engineering playbook keeps compromising high-value targets.

Analyst 207
APT36 Exclusive: Golang DeskRAT Threatens India

APT36 Exclusive: Golang DeskRAT Threatens India

This autumn, a seemingly innocent spear-phish opened the door to DeskRAT, a Golang-based remote-access trojan tied to APT36 (Transparent Tribe) that slipped into Indian government networks to harvest credentials and siphon documents. Analysts warn the groups move to Go makes these cross-platform implants smaller, stealthier, and tougher to pin down—an unnerving evolution in a decade-long espionage playbook.

Analyst 207
APT36 Exclusive: Critical Golang DeskRAT Threat Hits India

APT36 Exclusive: Critical Golang DeskRAT Threat Hits India

Think a phishing email cant threaten national security? In summer 2025, tailored spear-phishing delivered Golang DeskRAT into Indian government networks — a stealthy APT36 tool that turns a single click into a strategic risk.

Analyst 207
3,000 YouTube Videos Exposed: Exclusive Malicious Network

3,000 YouTube Videos Exposed: Exclusive Malicious Network

Imagine the how‑to video you trust quietly installing a trojan — researchers have uncovered a malicious network behind 3,000+ YouTube uploads that lure viewers to downloads which deploy credential stealers, cryptominers and remote‑access trojans. By posing as tutorials and fixes and using lightweight loaders, this scalable scheme turns platform trust into a repeatable infection machine.

Analyst 207
YouTube Videos Exposed: Exclusive Dangerous Malware Alert

YouTube Videos Exposed: Exclusive Dangerous Malware Alert

Think twice before clicking — researchers have uncovered a coordinated network that’s published over 3,000 malicious videos, baiting viewers with fake tools and links that install credential stealers, cryptominers, and remote-access trojans.

Analyst 207
GlassWorm Exclusive: Dangerous VS Code Supply-Chain Attack

GlassWorm Exclusive: Dangerous VS Code Supply-Chain Attack

Meet GlassWorm: a self‑propagating supply‑chain worm hiding in VS Code extensions (Open VSX and the Microsoft Marketplace) that uses install‑time scripts and stolen CI tokens to publish more malicious packages, turning developer convenience into a fast‑moving attack vector.

Analyst 207
ThreatsDay Exclusive: Critical Crypto Fine, AI Hijack Alert

ThreatsDay Exclusive: Critical Crypto Fine, AI Hijack Alert

ThreatsDay peels back how criminals are weaponizing trust — not by inventing new tech but by exploiting convenience, stale components and lax controls, from a billion‑dollar crypto collapse to AI‑assisted hijacks and targeted smishing. Find out why ordinary systems and trusted channels are the new attack surface, and who should be closing the door.

Analyst 207
Magento Stores Hit by Stunning Critical Breach, 250+

Magento Stores Hit by Stunning Critical Breach, 250+

Heads-up: a critical vulnerability in Adobe Commerce and Magento Open Source is being actively exploited — Sansec logged 250+ attack attempts in 24 hours. Merchants should patch immediately, rotate sessions, and hunt for suspicious activity to prevent account takeovers, fraud, and data leaks.

Analyst 207
Iran-Linked MuddyWater Exclusive: Damaging 100+ Targets

Iran-Linked MuddyWater Exclusive: Damaging 100+ Targets

Imagine one hijacked mailbox becoming the battering ram: Iran‑linked MuddyWater used a trusted account, attacker‑controlled VPNs and the Phoenix backdoor to quietly worm into 100+ MENA government networks and siphon sensitive policy and personnel intelligence over months.

Analyst 207
Iran-Linked MuddyWater Exclusive Dangerous Global Espionage

Iran-Linked MuddyWater Exclusive Dangerous Global Espionage

Iran-Linked MuddyWater is executing a dangerous, far-reaching espionage campaign — find out how this covert groups tactics put organizations worldwide at risk and what steps you can take to defend against them.

Analyst 207
Researchers Identify New LockBit Ransomware Victims

Researchers Identify New LockBit Ransomware Victims

LockBit is back—and meaner: its new cross‑platform payloads can hit Windows, Linux and VMware ESXi, turning a single break‑in into a crisis for hospitals, utilities and virtualized environments. Defenders must speed up containment and broaden detection beyond traditional endpoints or risk irreversible damage.

Analyst 207
ToolShell Gains Traction as Public App Exploits Surge

ToolShell Gains Traction as Public App Exploits Surge

When did a routine update become a battleground? ToolShell has quietly moved from niche reconnaissance to a go‑to exploit chain that turns public apps into launchpads for credential theft, lateral movement and ransomware — a wake‑up call that exposed services and slow patching can let attackers topple whole networks.

Analyst 207
Iran-linked MuddyWater Breach Hits 100+ Government Networks

Iran-linked MuddyWater Breach Hits 100+ Government Networks

How did one compromised mailbox become a battering ram against more than 100 government networks? Researchers say Iran-linked MuddyWater used a hijacked account and its own VPN to send convincing phishing across the Middle East and North Africa, quietly stealing credentials and siphoning sensitive intelligence — a reminder that simple, trusted tools can inflict huge damage.

Analyst 207
Shadowy figure stands before cracked screen displaying Russia map, with shattered phone and documents nearby.

Cyber Executive Charged with Selling Secrets to Russia

How does the steward of Americas cyber defenses become the seller of its secrets? A former Trenchant executive is accused of trading zero‑day exploits and offensive tools to a Russian buyer for $1.3 million — an alleged betrayal prosecutors say endangers U.S. operations and national security.

Analyst 207
Mysterious Russian Drone Spotted in Combat Zone

Mysterious Russian Drone Spotted in Combat Zone

Imagine spotting a flying doughnut over the front lines — Ukrainian electronic‑warfare specialists say Russian units are testing an unusual annular ring‑wing drone that looks nothing like the usual quadcopters. Its circular design could trade wingspan for endurance, potentially changing how drones loiter, scout and strike.

Analyst 207
60% of Security Leaders Warn of Rapid Threat Evolution

60% of Security Leaders Warn of Rapid Threat Evolution

Sixty percent of security leaders say attackers are evolving faster than defenses — a wake‑up call as crime gets industrialized into automated, turnkey attacks that prey on cloud, supply‑chain and IoT gaps. The upshot: rising costs, eroding trust and a simple choice for organizations — act now to close the gap or accept escalating risk.

Analyst 207
85,000 Pet Owner Records Exposed in Major Data Breach

85,000 Pet Owner Records Exposed in Major Data Breach

Turns out your pet’s medical chart can be a treasure map for crooks — over 85,000 pet and owner records were left publicly accessible, exposing names, contact details, microchip and medical data. What starts as spam can quickly turn into targeted fraud, identity theft or even false ownership claims, putting families and animals at real risk.

Analyst 207