Skip to main content

Emerging Threats

85,000 Pet Owner Records Exposed in Major Data Breach

85,000 Pet Owner Records Exposed in Major Data Breach

Turns out your pet’s medical chart can be a treasure map for crooks — over 85,000 pet and owner records were left publicly accessible, exposing names, contact details, microchip and medical data. What starts as spam can quickly turn into targeted fraud, identity theft or even false ownership claims, putting families and animals at real risk.

Analyst 207
ShinyHunters Orchestrate Widespread Corporate Extortion

ShinyHunters Orchestrate Widespread Corporate Extortion

ShinyHunters have kicked off a sweeping campaign of corporate extortion—leaking stolen data and demanding ransoms—so read on to see how companies are fighting back and what it means for you.

Analyst 207
WestJet Notifies U.S. Consumers of Data Breach

WestJet Notifies U.S. Consumers of Data Breach

WestJet has notified U.S. customers of a recent data breach—find out what happened and the simple steps you can take now to protect your information. Stay informed and act quickly to safeguard your accounts.

Analyst 207
Feds Tie Scattered Spider Duo to $115M in Ransoms

Feds Tie Scattered Spider Duo to $115M in Ransoms

U.S. prosecutors say 19‑year‑old Thalha Jubair helped power Scattered Spiders telecom‑focused extortion ring, allegedly netting at least $115 million through SIM‑swap scams, social engineering and account takeovers. The cross‑border indictment is a stark wake‑up call that human trust, lax recovery policies and reused credentials—not exotic malware—still fuel major ransoms.

Analyst 207
Stark Industries Evades EU Sanctions via Bulletproof Host

Stark Industries Evades EU Sanctions via Bulletproof Host

When the EU sanctioned Stark Industries in May 2025 — a bulletproof host tied to Kremlin-linked cyberattacks — the operation simply rebranded and shifted assets, proving how shell companies and rapid infrastructure swaps let illicit networks shrug off penalties. It’s a wake-up call: sanctions alone can’t stop a well‑engineered cyber hydra.

Analyst 207
Bulletproof Host Stark Industries Evades EU Sanctions

Bulletproof Host Stark Industries Evades EU Sanctions

Think sanctions shut down bad actors? When Stark Industries was sanctioned, it vanished and reemerged under new names within days — a stark reminder that bulletproof hosting’s rapid rebrands and shell-game tactics let Kremlin-linked cyber and disinformation networks keep running despite EU measures.

Analyst 207
investment scam: Shocking, Risky Deepfake Google Ads

investment scam: Shocking, Risky Deepfake Google Ads

Scammers are buying top search spots and using AI deepfakes to impersonate Singapore officials, creating convincingly official sites that trick investors into wiring funds. Learn simple checks—verify .gov.sg domains and contact agencies directly—to avoid falling for these high-tech cons.

Analyst 207
National Time Service Center: Exclusive Risky Attack

National Time Service Center: Exclusive Risky Attack

China’s MSS claims the NSA used 42 cyber tools to tamper with the National Time Service Center—a charge that, if true, would turn the country’s clocks into a powerful tool for disrupting finance, telecoms and critical infrastructure. Dramatic as the allegation is, the lack of a public forensic dossier leaves the claim hanging between serious threat and strategic rhetoric.

Analyst 207
insider risk: Essential Defenses Against Costly Breaches

insider risk: Essential Defenses Against Costly Breaches

Insider risk is now a frontline threat—77% of organizations have suffered data loss—so prioritize least-privilege access, zero-trust IAM, and integrated DLP/UEBA/SIEM while building a people-first culture that balances privacy with protection. These must-have defenses stop costly breaches before trusted channels become exit ramps.

Analyst 207
BeaverTail and OtterCookie: Stunning Critical Threat

BeaverTail and OtterCookie: Stunning Critical Threat

Cisco Talos warns a North Korean group is fusing BeaverTail’s credential-theft with OtterCookie’s browser persistence into single, stealthier JavaScript malware that’s harder to spot — defenders should start hunting for blended behaviors and tighten basics like MFA, patching, and anomaly detection now.

Analyst 207
payment data breach: Stunning Alarming Risk Exposed

payment data breach: Stunning Alarming Risk Exposed

About 180,000 people had names and payment details left exposed — putting them at heightened risk of fraud and identity theft; here’s what to do now to protect yourself and why companies must tighten their defenses.

Analyst 207
rewire democracy: Exclusive Best Reforms

rewire democracy: Exclusive Best Reforms

Join Nathan E. Sanders and me in Cambridge on October 22 for talks at Harvard Kennedy School’s Ash Center and a book signing at Cambridge Public Library, then tune in online on October 23 for a virtual discussion with Data & Society as we unpack how algorithms, platforms, and data are reshaping democracy—and what practical steps can make civic systems more resilient.

Analyst 207
Rewiring Democracy: Stunning Risks Ahead

Rewiring Democracy: Stunning Risks Ahead

What if the platforms that expanded our public square began shaping what we think? In Rewiring Democracy, Bruce Schneier shows how AI-driven persuasion, automated governance, and synthetic media could rewrite politics — and urges us to decide who will redraw our democratic wiring.

Analyst 207
AI and governance: Stunning Risks and Best Fixes

AI and governance: Stunning Risks and Best Fixes

Think politics is messy now? Bruce Schneier warns AI will rewrite the rules — promising smarter governance and wider participation while risking manipulation, bias, and concentrated power, and his new book kickstarts a crucial debate about whether these tools will strengthen or unravel democracy.

Analyst 207
ShinyHunters extortion: Stunning Risky Corporate Threat

ShinyHunters extortion: Stunning Risky Corporate Threat

Imagine waking up to find your company’s secrets posted online unless you pay up — that’s the stark reality dozens of firms now face after ShinyHunters launched a brazen public extortion site. This escalation — tied to prior Salesforce, Discord, and Red Hat breaches — raises the stakes for stronger security, faster incident response, and clearer vendor transparency.

Analyst 207
ShinyHunters Exclusive: Dangerous Corporate Extortion

ShinyHunters Exclusive: Dangerous Corporate Extortion

ShinyHunters has escalated from voice‑phishing to a public extortion site threatening to dump data from dozens of Fortune 500 companies. That shift puts customers and companies at risk and makes strengthening human‑centric defenses and zero‑trust controls urgently necessary.

Analyst 207
WestJet data breach: Urgent Exclusive Warning

WestJet data breach: Urgent Exclusive Warning

WestJet says a recent cybersecurity incident may have exposed U.S. customers’ travel and payment info — if you’ve flown with them recently, check your accounts, be on the lookout for phishing, and watch for the airline’s updates as the investigation continues.

Analyst 207
Scattered Spider Shocking $115M Ransom Scandal

Scattered Spider Shocking $115M Ransom Scandal

How did a 19‑year‑old become the alleged face of a criminal group accused of extracting $115 million in ransoms? U.S. prosecutors say Thalha Jubair and a co‑conspirator tied to Scattered Spider used social engineering and stolen credentials to hit hospitals, transit and retailers—proof that stronger defenses and international cooperation are now essential.

Analyst 207
ransomware payments: Stunning Risky Surge to $3.6M

ransomware payments: Stunning Risky Surge to $3.6M

Ransomware payments jumped 44% to an average $3.6M in 2025 as attackers shift to fewer, higher-value strikes—forcing organizations to weigh grim pragmatism against costly downtime, data leaks, and regulatory fallout.

Analyst 207
Askul ransomware attack: Stunning, Risky supply-chain hit

Askul ransomware attack: Stunning, Risky supply-chain hit

When Muji paused online orders after logistics partner Askul was hit by ransomware, it exposed a stark truth: a single third-party breach can freeze entire retail operations. This outage is a wake-up call for brands to map dependencies, tighten vendor security, and treat supply-chain risk as an ongoing priority.

Analyst 207
NoRobot malware: Exclusive Dangerous Threat

NoRobot malware: Exclusive Dangerous Threat

When LostKeys was exposed this spring, Coldriver didn’t fold — they reinvented, rolling out a lean, modular strain called NoRobot that sneaks past signatures, steals credentials, and blends into normal traffic. Defenders now need behavior-based detection, stronger identity controls like MFA, and faster threat-sharing to keep up with this smarter, stealthier pivot.

Analyst 207
Lumma Stealer: Shocking Risky Reputation Exposure

Lumma Stealer: Shocking Risky Reputation Exposure

A rival cybercrime group has publicly doxxed the operators behind Lumma Stealer, ripping away their secrecy and wreaking reputational havoc while creating both intelligence opportunities—and dangerous misinformation—for defenders, victims, and investigators.

Analyst 207
three new malware families: Exclusive Critical Threat

three new malware families: Exclusive Critical Threat

Heads-up: Google TAG says Russia-linked COLDRIVER has churned out three new malware families and is retooling them within days—an accelerated development pace that makes signature-based defenses brittle and raises the urgency for MFA, behavior-based EDR, and proactive threat hunting.

Analyst 207
Snappybee malware: Alarming Risky Breach of EU Telecoms

Snappybee malware: Alarming Risky Breach of EU Telecoms

A major European telecom was breached after attackers exploited a Citrix NetScaler flaw to deploy Snappybee — a modular espionage toolkit tied to the China-linked Salt Typhoon group — showing how trusted remote-access appliances can become gateways for stealthy data theft. The incident is a wake-up call to prioritize patching, segmentation, and behavioral detection before the next exploit hits.

Analyst 207