Skip to main content

Tag: emerging threats

4867 articles

Empty college corridor with students and faculty showing subtle concern.

Instructure Discloses Double Breach Amid ShinyHunters' Data Leak Threat

In a shocking security breach, Instructure, the creator of Canvas, revealed not one, but two separate intrusions into its system, leaving thousands of schools and students scrambling for access to crucial course materials during final exams. The breaches come as an extortion group, ShinyHunters, threatens to leak a massive 3.65 TB of stolen data.

Analyst 207
General Motors vehicle drives down California road with smartphone screen displaying abstract data in foreground.

GM Faces $12.75M Penalty for Illicit Driver Data Sales

General Motors has been hit with a record $12.75 million penalty for selling California drivers' data without their consent, despite promising to protect their privacy. This landmark case marks a major victory for data protection, with California's Attorney General Rob Bonta leading the charge.

Analyst 207
Security professional stands before a cityscape window with looming digital threats.

Security Teams Overlook AI-Driven Threats in Cloud Risk Management

Stay ahead of the threats: are you managing cloud risk effectively, or is it still siloed and vulnerable to AI-driven attacks? Recent research from Google Threat Intelligence Group reveals a new wave of AI-augmented operations that are scaling and accelerating compromises.

Analyst 207
Water utility industrial setting with computer systems in background.

UK Water Utility Exposed: Hackers Hid Undetected for 20 Months

In a shocking revelation, hackers secretly lurked on South Staffordshire Water's corporate network for 20 months, evading detection until a performance issue sparked an investigation in July 2022. The stealthy attackers gained unauthorized access via a September 2020 phishing attack, harvesting credentials and even attempting to deploy ransomware before being finally uncovered.

Analyst 207
A Windows computer workstation with file explorer open in a dimly lit office setting.

GhostLock Exploits Windows API to Disrupt File Access

Meet GhostLock, a proof-of-concept that cleverly exploits Windows API to disrupt file access, causing operational downtime without data loss, similar to the impact of ransomware. By manipulating the CreateFileW sharing parameter, GhostLock effectively locks files, leaving other processes in the dark with a sharing violation error.

Analyst 207
Jenkins plugin page on a computer screen shows a warning message with a blurred software development workspace background.

Checkmarx Plugin Compromised with Infostealer in Supply-Chain Attack

A rogue version of Checkmarx's Jenkins Application Security Testing plugin was compromised by the TeamPCP hacker group, who left a taunting message in the about section, claiming another supply-chain attack success. The group has been linked to a string of similar breaches, delivering credential-stealing malware.

Analyst 207
Blurred laptop screen on cluttered desk with scattered papers and office supplies.

Gentlemen Ransomware Group Hit by Data Breach

A recent data breach has exposed the inner workings of the notorious Gentlemen ransomware group, revealing a treasure trove of sensitive information, including chats, images, and operational practices. This rare glimpse into the ransomware ecosystem could provide valuable insights for cybersecurity experts and researchers.

Analyst 207
Developer workstation with laptop, code editor, and cluttered desk in a bright office.

Malware Exploits Chromium Interface to Steal Dev Secrets

Malware is masquerading as a legitimate software installer, tricking developers into spilling their secrets by exploiting the Chromium interface. A simple search ad has become the conduit for this malicious campaign, leading unsuspecting devs down a path of deceit.

Analyst 207
Researchers work on code and data visualizations at a computer terminal in a university research setting.

AI Researchers Tackle SIEM Migration Bottleneck with Automation Tool

Researchers have made a breakthrough in streamlining SIEM migration with an innovative automation tool called ARuleCon, which can slash months of manual rule rewrites into mere batch operations. This game-changing system uses a three-stage conversion pipeline and large language models to rapidly translate complex rules, cutting conversion time to just 140 seconds.

Analyst 207
Laptop screen displays Jenkins plugin interface with code environment, beside blurred smartphone and sticky notes.

TeamPCP Breaches Checkmarx Jenkins Plugin Again

If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.

Analyst 207
Technicians walk through a server room with rows of computer equipment and storage systems near a workstation with a laptop.

cPanel Flaw Exploited to Deploy Filemanager Backdoor

Over 2,000 attacker source IPs worldwide are currently involved in automated attacks exploiting a critical cPanel vulnerability, CVE-2026-41940, which allows remote attackers to gain elevated control and deploy malicious backdoors. This flaw has been targeted by multiple actors for a range of malicious outcomes, including cryptocurrency mining and ransomware.

Analyst 207
UAE military personnel operate a modern counter-drone system at a defense facility.

UAE Deploys Homegrown Counter-Drone Tech in Iran Conflict

The UAE successfully countered over 80-85% of incoming drones using its homegrown counter-drone technology during the recent Iran conflict, showcasing the country's reliance on locally developed solutions. This locally grown tech, including jammers and spoofers, allowed for an immediate response, operating from day one without delays.

Analyst 207
Cluttered office desk with laptop and papers near a window overlooking a cityscape.

Small Businesses Exposed to Growing Cyber Threats Without Cybersecurity Leadership

Small businesses are playing with fire, exposing themselves to devastating cyberattacks that can cost over $250,000 - a staggering amount that's roughly equivalent to the salary of a chief information security officer (CISO). By not investing in cybersecurity leadership, they're essentially rolling the dice against increasingly automated threats.

Analyst 207
Prime Minister Evika Siliņa stands at a podium with a subtle Latvian flag in the background, addressing reporters with a…

Latvian Defense Minister Resigns Amid Drone Response Failures

Latvian Prime Minister Evika Siliņa has requested the resignation of Defense Minister Andris Sprūds, citing a loss of trust in his handling of recent drone airspace violations. The move comes after an extraordinary coalition meeting where Siliņa publicly expressed her and the public's lack of confidence in Sprūds.

Analyst 207
A cluttered office desk with laptop, coffee cup, and papers, in a brightly-lit open-plan setting.

Threat Actors Leverage AI for Vulnerability Exploitation and Cyber Operations

Google Threat Intelligence Group has spotted a threat actor using a zero-day exploit likely developed with AI, marking a chilling new trend in cybercrime. This game-changing tactic turbocharges exploit development, malware autonomy, and access to premium AI services.

Analyst 207
Law enforcement officers in a briefing room with laptops and notes, daylight from tall windows behind.

Police Disrupt Relaunched German-Language Cybercrime Forum

In a major breakthrough, international authorities have shut down a notorious German-language cybercrime forum that had attracted over 22,000 users and 100 vendors peddling stolen data, drugs, and forged documents. A 35-year-old German national was arrested in Mallorca and faces charges for allegedly masterminding the illicit platform.

Analyst 207
Researcher working in clean-room setting with laptop displaying code editor.

Google Researchers Uncover AI-Developed Zero-Day Exploit

Google researchers have made a groundbreaking discovery - a zero-day exploit that was developed with the help of artificial intelligence, which could have led to a large-scale attack if not caught in time. Thankfully, the vulnerability has been patched after Google alerted the affected vendor.

Analyst 207
Drone on a pedestal with technical equipment in a bright laboratory setting.

US Export Laws Hinder Ukraine Defense Tech Cooperation

US export laws are putting the brakes on game-changing defense tech collaborations between Ukraine and the US, sparking concerns that regulatory hurdles could stifle innovation. Amidst this, Ukrainian startups like Swarmer are defying odds, with one AI firm's shares skyrocketing 700% on its market debut.

Analyst 207
Developer workstation with code on laptop, coffee, and notes, with a large open-source project repository in the blurred…

Anthropic's Mythos AI Falls Short in Bug-Hunting Test

Anthropic's highly-hyped Mythos AI failed to impress in a recent bug-hunting test against cURL's codebase, with results that were largely dismissed as overhyped marketing. The limited test, run by cURL developer Daniel Stenberg, revealed that Mythos fell short of expectations.

Analyst 207
Laptop screen displays code on minimalist desk in bright tech lab setting.

Google Exposes AI-Driven Zero-Day 2FA Bypass Exploit

Google's Threat Intelligence Group just uncovered a zero-day exploit that was likely crafted by AI, highlighting the rapidly evolving threat landscape. This AI-driven attack uses a Python script with telltale signs of large language model-generated code.

Analyst 207
Cluttered workstation with researcher in background looking at laptop.

Linux Distributions Scramble to Patch Dirty Frag Kernel Vulnerabilities

A critical vulnerability known as Dirty Frag has been discovered in the Linux kernel, allowing attackers with local access to gain root privileges across major distributions. Linux distributions are now racing against the clock to patch this chained local privilege escalation flaw.

Analyst 207
Software development team works at a continuous-integration workstation with laptop and monitor displaying a plugin…

Checkmarx Plugin Sabotaged in Fresh TeamPCP Intrusion

Checkmarx issued a warning on May 9, 2026, that a tampered version of its Jenkins AST plugin had been released on the Jenkins Marketplace, posing a risk to continuous-integration pipelines. The company quickly responded by urging customers to update to a trusted version, 2.0.13-829.vc72453fa_1c16, to safeguard their systems.

Analyst 207
Hotel lobby with reception desk and blank computer screen, hinting at unease.

BWH Hotels Reservation Data Exposed to Cybercrooks

BWH Hotels guests are being warned to stay vigilant after a data breach exposed reservation information to cybercriminals, and customers are urged to watch out for potential phishing scams.

Analyst 207
Brightly-lit educational hallway with scattered papers and laptops displaying blank screens.

Hackers Exploit Canvas Flaw to Deface Instructure Portals

In a shocking breach, hackers exploited a flaw in Canvas to infiltrate Instructure portals, making off with a staggering 3.6 terabytes of data and putting 8,809 educational organizations at risk. The attackers, known as ShinyHunters, claimed to have stolen 275 million records in a brazen heist.

Analyst 207