Tag: emerging threats
4867 articles

TrickMo Trojan Adopts TON Blockchain for Evasive C2 Routing
A new variant of the TrickMo Trojan, tracked as TrickMo C, has emerged, cleverly using The Open Network (TON) blockchain to disguise its command-and-control traffic, making it even harder to detect. This sneaky malware targets banking and wallet users in France, Italy, and Austria through convincing TikTok-themed lures on Facebook ads.

PowerShell Stealer Targets Devs via Fake Claude Code Pages
Developers beware: a sneaky PowerShell Stealer is targeting you through fake Claude Code pages, putting your organization's most sensitive assets at risk. Clicking on innocent-looking sponsored search results could be the first step in a devastating cyberattack.

Ivanti, Palo Alto Networks Flaws Exploited in Active Attacks
Meet Quasar Linux RAT, a sneaky malware that combines remote access, evasion, and data theft capabilities, making it a potent threat to Linux systems. This powerful tool lets hackers secretly control infected hosts, harvest sensitive info, and even create a network of compromised devices that communicate with each other.

Active Directory Breaches Persist After Password Resets
Resetting passwords isn't enough to keep hackers at bay, especially in Active Directory environments where cached credentials and sync delays can leave gaping security holes. Even after a password reset, attackers can still find ways to exploit outdated credentials and gain unauthorized access.

Hackers Leverage AI to Develop Zero-Day Vulnerability
The AI vulnerability race is no longer on the horizon - it's already underway, with hackers leveraging AI to identify and exploit zero-day vulnerabilities, as seen in a recent coordinated operation. Google Threat Intelligence Group has uncovered the first observed case of cybercriminals using AI to produce weaponized code and bypass security protections.

Google Exposes AI-Generated Zero-Day Exploit Used by Hackers
Google's Threat Intelligence Group has made a groundbreaking discovery - a zero-day exploit, potentially crafted with AI, was used by hackers to bypass two-factor authentication in a widely-used open-source tool. This alarming finding highlights the emerging threat of AI-generated cyber attacks.

Autonomous Teaming Closes Defenders' Speed Gap
The alarmingly rapid pace of cyber threats has left defenders scrambling to keep up, with the time from vulnerability disclosure to working exploit dwindling from 56 days in 2024 to a staggering 10 hours in 2026. Meanwhile, defenders are still stuck on human time, struggling to match the lightning-fast speed of attackers who now operate in seconds.

Checkmarx Disrupts TeamPCP Intrusion via Sabotaged Jenkins Plugin
Checkmarx sprang into action to stop a TeamPCP intrusion after a Jenkins plugin was sabotaged, ruining engineers' weekend plans with a Saturday attack. The swift response thwarted another attempted breach by the same cyber actor.

FCC Extends Security Update Deadline for Banned Routers
The FCC is giving banned routers a lifeline with an extended security update deadline, ensuring they stay safe and functional with continued software and firmware updates. This move comes after the commission banned the import and sale of certain foreign-made routers in March 2026 due to national security concerns.

ShinyHunters Targets Education Sector with School-by-School Ransom Push
ShinyHunters has launched a targeted ransom attack on the education sector, exploiting a vulnerability in Canvas Learning Management System to steal a staggering 275 million records from nearly 9,000 schools and universities. The timing couldn't be more critical, with exams already underway and academic years wrapping up.

ShinyHunters Breach Exposes 200,000 Zara Customers
A massive data breach at fashion giant Zara has exposed the sensitive information of over 197,000 customers, including email addresses, order details, and support ticket info, after a hacking group called ShinyHunters gained unauthorized access to the company's systems. The breach was quickly contained, with parent company Inditex alerting authorities and assuring customers that no names, passwords, or payment details were compromised.

TrickMo Malware Adopts TON Blockchain for Covert Command-and-Control
Meet Trickmo.C, a sneaky new variant of the TrickMo Android banker that's been hiding in plain sight as a TikTok or streaming app, targeting unsuspecting users in France, Italy, and Austria since January. This cunning malware has evolved to use the TON blockchain for covert command-and-control, making traditional domain takedowns a thing of the past.

Vulnerabilities in TETRA Radio System Expose Global Security Risks
A single misstep in a radio system can send critical infrastructure crashing down - as Taiwan's bullet train system learned the hard way when a university student's clever hack with a radio and online kit brought the entire network to a standstill for nearly an hour. The incident highlights the urgent need for robust defenses to safeguard our global security.

Malicious Repo Exploits OpenAI Model to Deliver Info Stealer
A malicious repository disguised as OpenAI's legitimate Privacy Filter model racked up 244,000 downloads and became the #1 trending project on Hugging Face, but actually hid a sneaky Rust-based information stealer targeting Windows machines. The fake repository, Open-OSS/privacy-filter, expertly impersonated OpenAI's release, even copying the official model card to gain users' trust.

Police Disrupt Relaunched Crimenetwork Dark Web Marketplace
In a major blow to dark web crime, a 35-year-old German citizen was arrested in Mallorca for relaunched Crimenetwork marketplace. He built an entirely new online infrastructure just days after the previous version was shut down.

Nobel Economist Warns AI Exacerbates Disinformation Crisis
Nobel laureate Joseph Stiglitz warns that AI is supercharging the disinformation crisis, echoing his famous phrase "garbage in, garbage out." Without government intervention, AI will only worsen the spread of false information, threatening the very fabric of our information ecosystem.

US Navy Bolsters Iran Blockade with 20 Warships Deployed
The US Navy has significantly ramped up its presence in the region, deploying over 20 warships to enforce a robust blockade of Iran, successfully redirecting 61 commercial vessels and disabling at least four that attempted to breach the blockade. This massive show of force is a clear demonstration of the Navy's commitment to maintaining maritime security in the area.

Pakistan Bolsters Military with Rapid Modernization Push
Pakistan is rapidly modernizing its military, with Lieutenant General Ahmed Sharif Chaudhry revealing that only 10 percent of its military potential has been showcased to India, and unveiling an impressive array of new defense capabilities. The country has established the Army Rocket Force Command, a game-changing unified command that consolidates its ballistic missiles, cruise missiles, and drones under one umbrella.

Australia's Infrastructure Failures Erode National Security
Australia's broken promises on infrastructure are compromising its national security, with crucial projects like the Inland Rail - a game-changing freight line from Melbourne to Brisbane - stalled due to flawed assumptions, politics, and the passage of time. This has left the nation's supply chain resilience, regional industry, and agricultural competitiveness hanging in the balance.

Hackers Exploit Google Ads, AI Chats to Spread Mac Malware
Malicious hackers are exploiting Google ads and AI chat platforms to trick Mac users into downloading malware, using a sneaky tactic that involves fake installation guides and Terminal commands. Clicking on what seems to be a legitimate ad can lead to a malware-ridden surprise, thanks to a vulnerability in Claude's shared-chat feature.

German Police Disrupts Crimenetwork Marketplace, Arrests Admin
In a major blow to darknet crime, German police have arrested a 35-year-old man suspected of running a rebooted version of the notorious Crimenetwork marketplace, thanks to a slick cross-border operation. The suspect, detained in Mallorca by Spanish police, will face justice in a German court.

Ollama Vulnerability Exposes Servers to Remote Memory Leak
A newly discovered vulnerability in Ollama, dubbed "Bleeding Llama," exposes over 300,000 servers worldwide to a severe remote memory leak, with a CVSS score of 9.1. This critical flaw, tracked as CVE-2026-7482, allows attackers to exploit a weakness in the GGUF model loader.

Drones Transform Battlefield Logistics Amid Resource Scarcity
In Ukraine, a staggering 50-80% of frontline resupply is now handled by drones, revolutionizing battlefield logistics and transforming the way troops receive vital supplies. This seismic shift is driven by the simple math of cost and risk: drones are cheaper and safer than traditional trucks and soldiers.

DARPA Pursues Autonomous Drone Swarm Containers
Imagine a fleet of up to 500 drones, working together in perfect sync, launched and managed by autonomous containers that can recharge, refuel, and redeploy them over multiple days. DARPA is pushing the boundaries of innovation with its pursuit of autonomous drone swarm containers that can revolutionize sustained operations.