Tag: emerging threats
4866 articles

Vulnerability Exploitation Surges in Data Breaches
Vulnerability exploitation is now the top attack vector, responsible for a staggering one-third of all data breaches. This alarming trend highlights the urgent need for robust patch management and cybersecurity measures to stay ahead of threats.

Microsoft Vulnerabilities Spike in Critical Areas
A single critical flaw, like CVE-2025-55241, can give attackers unrestricted access to any tenant, highlighting the alarming rise in critical Microsoft vulnerabilities, which doubled in 2025 despite a stable overall number of vulnerabilities. This sharp increase in high-impact weaknesses demands attention and action.

Drupal Warns of Imminent Core Security Updates, Urges Site Prep
Drupal is warning site owners to prepare for imminent core security updates, urging them to reserve time on May 20, 2026, between 5-9 p.m. UTC, to apply crucial patches and protect against potential exploits. Don't miss this window to safeguard your site and stay ahead of potential threats!

OAuth Grants Expose Hidden Risk Below MFA Perimeter
In just five weeks, a phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organizations across five countries by exploiting a clever trick: instead of stealing passwords, it convinced users to hand over OAuth refresh tokens, granting attackers long-term access to sensitive data like mailboxes, drives, and calendars. This sneaky tactic allowed hackers to bypass traditional security measures, including multi-factor authentication.

AI-Powered Tools Elevate Vulnerability Detection, Pressing Secure-by-Design Mandate
With AI-powered tools, companies can now instantly detect and fix software vulnerabilities, making ignorance a thing of the past when it comes to cybersecurity. As Hans de Vries of ENISA notes, this shift makes a secure-by-design approach not just best practice, but a pressing mandate.

SEPPMail Gateway Vulnerabilities Expose Remote Code Execution Risk
Critical vulnerabilities in SEPPMail's Secure E-Mail Gateway could allow hackers to read all mail traffic, gain entry into internal networks, and even execute remote code - putting your entire system at risk. These flaws could have devastating consequences, from data breaches to full-scale system compromise.

Grafana Labs Discloses Source Code Theft by Hackers
Hackers recently breached Grafana Labs' security, gaining unauthorized access to a GitHub token that allowed them to download the company's source code, and subsequently attempting to extort payment to keep it under wraps. The incident was swiftly investigated, and the compromised token was promptly invalidated.

Agentic AI Turbo Boosts Mobile App Attacks
The alarming rise of mobile app attacks is no longer looming on the horizon - it's here, with a staggering 87% of monitored apps facing threats in 2026, a drastic jump from 55% in 2022, fueled by the rapid adoption of AI models. This explosive growth in attacks is a wake-up call for businesses to bolster their mobile app security.

Microsoft Disables Windows Updates in Restricted Networks
If you've installed the January 2026 optional non-security preview updates on a restricted Windows network, you might face update failures - a frustrating issue that could leave your system vulnerable. Specifically, affected devices may still download February's security update, but then get stuck, unable to receive crucial updates from March onwards.

Nx Console Extension Exploited to Steal Developer Credentials
A malicious version of the popular Nx Console Extension was published to the VS Code Marketplace, compromising over 2.2 million installations and putting developer credentials at risk. Within seconds of opening a workspace, the extension silently fetched and executed a hidden payload, allowing attackers to steal sensitive information.

Hackers Exploit Human Behavior to Bypass Security Tools
As cyber threats evolve at an alarming rate, hackers are exploiting human behavior to outsmart security tools, forcing organizations to rethink their defensive strategies. With identity abuse and data extortion on the rise, businesses must stay ahead of the game to protect themselves.

Mini Shai-Hulud Campaign Targets npm Ecosystem with Malicious AntV Packages
A large-scale attack has infected hundreds of popular npm packages, including widely-used data visualization and React components, with malicious updates, putting a vast number of projects and applications at risk. The attackers published 639 malicious versions across 323 unique packages in a fast-moving supply chain operation.

GitHub Actions Supply Chain Attack Exfiltrates CI/CD Credentials
A sneaky supply chain attack on GitHub Actions has led to the theft of CI/CD credentials, with hackers using a clever trick to redirect tags to fake commits that hide malicious code. By masquerading as legitimate commits, attackers were able to execute arbitrary code and evade pull request reviews.

US Leads Shift to Allied Security Web in Indo-Pacific
Imagine a strategic anchor in the Indo-Pacific, where a cutting-edge security network is being woven to safeguard a vital waterway - the Strait of Malacca, which carries a quarter of global trade and nearly 30 percent of seaborne oil. Guam is at the forefront of this revolutionary shift, transforming into a hub of interconnected security, deterrence, and defense systems.

Russia Unveils Two-Seat Variant of Su-57 Felon Fighter
Russia just revealed a game-changing two-seat version of its Su-57 Felon fighter, designed to serve as a flying command center for coordinated air operations. This new variant, spotted undergoing taxi trials, boasts a redesigned fuselage and tandem cockpit.

Pentagon Names Five Winners in Drone Lethality Challenge
The Pentagon has announced the five winners of its Drone Lethality Challenge, a competition seeking payload solutions compatible with small drones, and the solutions must be scalable and cost-effective. The winners - Bravo Ordnance, Kela Defense, Kraken Kinetics, Mountain Horse, and Northrop Grumman - have successfully met the government's requirements for payloads that can be used on Group 1 drones.

India Advances Nuclear Deterrent with Second MIRV Missile Test
India just took a giant leap in defence preparedness with the successful test of its Advanced Agni missile, equipped with a game-changing Multiple Independently Targeted Re-Entry Vehicle (MIRV) system, capable of taking out multiple targets across a vast geographical area. This milestone marks a significant boost to the country's deterrent capabilities against growing threats.

Army Seeks Low-Cost Patriot Interceptor Under $1 Million
The Army is launching a competitive quest for a game-changing, low-cost interceptor that could slash the Patriot system's unit price to under $1 million - a fraction of the current cost. Industry players are invited to submit proposals for innovative designs that could revolutionize missile defense.

Southeast Asia Shifts Defence Strategy to Counter China with Mobile Strike Capabilities
To counter China's growing influence, Southeast Asian nations can bolster their defence by prioritizing mobile strike capabilities, leveraging affordable and agile equipment like strike missiles, drones, and surface-to-air missiles. By doing so, they can significantly raise the stakes for China and make any potential aggression a costly endeavour.

Interpol Disrupts Cybercrime Ops Across 13 Countries
In a major win against cybercrime, Interpol's Operation Ramz has resulted in 201 arrests, 53 servers seized, and nearly 4,000 victims identified across 13 countries in the Middle East and North Africa. This groundbreaking four-month sweep marks a significant milestone in the fight against online crime.

US Soldiers Train to Identify Drones by Sound
US soldiers are now on high alert for a new kind of threat - and it's not just about keeping their eyes on the ground. They're learning to tune in to the unique sounds of drones, like Sgt. 1st Class Tyler Harrington, who's training to distinguish between different types, including one-way attack drones.

US, Israel Escalate Pressure on Iran with Airstrikes, Sanctions
President Donald Trump revealed on Truth Social that he was asked by top Middle Eastern leaders to delay a planned military attack on Iran, which was set to happen the following day. He instructed the military to stand down, but remain ready to launch a full-scale assault if negotiations fail.

China's Influence in Solomons Resists Leadership Shift
Solomon Islands' new Prime Minister Matthew Wale is vowing to shake things up, warning that his country isn't immune to geopolitics and promising that "change is coming" after ousting his pro-China predecessor. Will this leadership shift mark a new direction for the island nation, one that's less aligned with Beijing?

AI Agents Expose Blind Spots in APAC Enterprise Security
Attackers are now targeting AI agents embedded within APAC enterprises, exploiting weaknesses in non-human identities to gain access to sensitive systems, data, and workflows. This emerging threat highlights a significant blind spot in enterprise security, one that's ripe for exploitation by malicious actors.