Tag: emerging threats
4867 articles

Pentagon Exposes New Unidentified Phenomena Files
The Pentagon has just dropped a bombshell, releasing a batch of previously classified images and footage of Unidentified Anomalous Phenomena, some of which date all the way back to the 1940s. Get ready to dive into the fascinating and often bizarre world of UAPs like never before!

US Military Aircraft Breach Austrian Airspace
The Austrian Air Force sprang into action, scrambling Eurofighter Typhoons not once, but twice, after US military aircraft strayed into its airspace on consecutive days. On both occasions, the Austrian defenders swiftly identified the intruders - two PC-12 turboprops - and escorted them out, with the second incident prompting a Priority A response at 12:31.

Russia's Scaled-Back Parade Exposes Kremlin's Ukraine War Vulnerability
Russia's muted Victory Day parade in Red Square has raised eyebrows, with experts reading it as a telling sign of the Kremlin's growing vulnerability in its war with Ukraine. By citing security concerns, Moscow watered down its usual display of military might, sparking whispers of weakness.
Android 17 Bolsters Defenses Against Banking Scams, Device Theft
Stay one step ahead of scammers with Android 17's cutting-edge security features, including robust protection against banking scam calls and device theft. Android 17 will work hand-in-hand with banking apps to detect and block spoofed calls, giving you an added layer of defense against financial threats.

Ransomware Evolves With Post-Quantum Encryption, New Extortion Tactics
Ransomware attacks may be on the decline, but don't let your guard down - attackers are getting smarter, ditching encryption, and selling stolen data, with the manufacturing sector alone losing a whopping $18 billion in just three quarters. The threat may have evolved, but the damage and risk remain very real.
Pakistan's Khyber Pakhtunkhwa Police Bear Brunt of Underfunding
On Pakistan's turbulent western frontier, the Khyber Pakhtunkhwa Police are fighting a losing battle against terror, with chronic underfunding exacerbating the threat to their lives. The devastating May 9 attack in Fateh Khel, Bannu, which claimed 15 policemen's lives, is just the latest tragic reminder of this mismatch between threat and reward.

US Air Force Revives ARRW Hypersonic Missile with Anti-Ship Upgrade
The US Air Force is reviving its ARRW Hypersonic Missile program with a game-changing upgrade, adding an anti-ship capability that enables the missile to track and take down moving targets, including ships at sea. The service is seeking over $296 million in funding to turn this ambitious concept into a tested reality.

Taiwan's Defense Budget Cuts Imperil Porcupine Strategy
Taiwan's defence capabilities are in jeopardy after lawmakers approved a slashed defence budget of $25 billion, down from President Lai's proposed $40 billion, with the reduced funds leaving the island's Porcupine Strategy vulnerable. This cut comes as a significant blow, with a senior research fellow warning it weakens Taiwan's defence capabilities.

Google Bolsters Android Security to Counter Spyware Vendors
Google's new Intrusion Logging feature is a game-changer in the fight against spyware, helping digital forensics researchers uncover sophisticated attacks on Android devices. By recording security incidents like device unlocking and spyware installation, it provides crucial evidence to investigate and take down these threats.

Department of Energy Drives Modernization Push Amid Rising Threats
The Department of Energy is putting modernization at the forefront of its agenda, recognizing its critical role in driving technological leadership, securing critical infrastructure, and bolstering national energy resilience. By making modernization its top priority, the department aims to tackle rising threats and achieve key national objectives.

Google Exposes AI-Built Zero-Day Threat That Nearly Sparked Mass Attack
The game-changing moment came when a zero-day threat, nearly sparking a mass attack, was uncovered - and forensic evidence revealed its exploit code was astonishingly built by an AI model. This breakthrough highlights how AI is revolutionizing exploit development, making it faster and more accessible to malicious actors.

Pentagon Reverses Course, Revives Boeing E-7 Wedgetail Funding
The Pentagon is breathing new life into the Boeing E-7 Wedgetail, reversing its plan to cancel the program and instead sending a budget amendment to revive funding. Defense Secretary Pete Hegseth confirmed the change, citing the aircraft's potential to fill critical gaps on the modern battlefield.

RubyGems Disrupts Signups Amid Malicious Package Surge
RubyGems has temporarily halted new account registrations amid a significant surge in malicious packages, with security experts warning of a major attack on the platform. The move comes as Mend.io, the organization responsible for securing RubyGems, works to contain the incident.

Škoda Discloses Data Breach After Online Shop Hack
Škoda's online shop was recently hacked, exposing customer data after attackers exploited a vulnerability in the e-commerce software. The company has since fixed the issue, alerted authorities, and is working with a forensics team to investigate.

AI Adoption Exposes New Vulnerabilities in APAC Cybersecurity
As AI systems increasingly become integral to business operations, they're also emerging as a major insider threat, with 7 in 10 APAC organisations now identifying AI as their top data security risk. This new breed of threat is forcing companies to rethink their cybersecurity strategies and take a closer look at the vulnerabilities AI can introduce.

Malware Targets TanStack npm Packages in Supply Chain Attack
Malware attackers have infiltrated the TanStack npm packages, modifying 84 artifacts in a supply chain attack that could compromise major developer ecosystems. The malicious code, aimed at stealing credentials, was published across 42 packages on May 11, with some, like @tanstack/react-router, downloaded over 12 million times weekly.

OpenAI Launches Daybreak to Bolster Secure Software Development
OpenAI has launched Daybreak, an innovative initiative that helps developers build secure software from the ground up, accelerating cyber defenders and continuously securing software. By integrating cutting-edge models like GPT-5.5, Daybreak shifts security to the forefront of the software development lifecycle.

US Bank Self-Reports Data Leak to Unauthorized AI App
A US bank has taken swift action, self-reporting a data leak that exposed sensitive customer information to an unauthorized AI app, sparking concerns over the volume and sensitivity of the compromised data. The bank's proactive disclosure to regulators and customers highlights its commitment to transparency in the face of a data-handling lapse.

TrickMo Trojan Exploits TON Network for Android Pivots
Meet TrickMo C, a sneaky new variant of the Android banking trojan that's turning infected devices into programmable network pivots, allowing hackers to intercept sensitive data from banking and cryptocurrency wallet users in France, Italy, and Austria. This malicious software is packed with powerful tools, including reconnaissance, SSH tunnelling, and SOCKS5 proxying capabilities.

Cybercriminals Leverage ClickFix with PySoxy for Persistent Attacks
Cybercriminals are using a potent combination of ClickFix and PySoxy to launch persistent attacks, with experts warning that their deliberate preparation shows a sinister intent for continued access. This sophisticated tactic allows attackers to survive removal attempts and endpoint blocks, making it a major threat.

TanStack npm packages compromised in cache-poisoning attack
Malicious attackers have launched a lightning-fast cache-poisoning attack on TanStack npm packages, flooding the supply chain with 84 tainted versions loaded with credential theft and disk-wiping code. This six-minute blitz highlights the vulnerability of software supply chains to swift and devastating strikes.

Shai Hulud Campaign Targets Developers with Malicious npm Packages
Malicious actors have unleashed a barrage of 84 tainted versions of popular software packages, cleverly disguising them with legitimate credentials to deceive developers. The Shai Hulud campaign, linked to the TeamPCP threat group, has been wreaking havoc on the software supply chain since September.

Security Teams Lag Behind on Agentic AI Risks
The alarming truth is that agentic AI is already live in many production environments, but security teams are largely in the dark about the risks they're facing. This emerging threat can be categorized into three key areas: coding and productivity agents like Claude Code and GitHub Copilot, vendor-built agents, and custom-built agents.

SAP Patches Critical Flaws in Commerce Cloud and S/4HANA
SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.