Tag: emerging threats
4867 articles

EU Curbs Chinese Solar Inverter Funding Over Cybersecurity Fears
The European Commission has pulled the plug on EU funding for solar projects using Chinese-made inverters, citing serious cybersecurity threats that could lead to countrywide blackouts and unauthorized access to sensitive operational data. This move comes after risk assessments confirmed the potential for manipulation of electricity production and disruption of generation.

Malicious PyTorch Lightning Package Exploits Supply Chain to Steal Credentials
A malicious version of the popular PyTorch Lightning package, downloaded over 11 million times, was found to contain a stealthy backdoor that steals credentials by silently executing a heavily obfuscated JavaScript payload. The compromised package, version 2.6.3, triggers the malicious routine automatically when imported, putting users at risk.

US Approves $8.6 Billion Arms Sales to Middle East Allies, Bypassing Congressional Review
The US has greenlit an $8.6 billion arms deal with its Middle East allies, sidestepping Congressional review by declaring an emergency that requires immediate action to protect national security interests. This massive sale involves four key partners: Qatar, Kuwait, Israel, and the United Arab Emirates.

Data Centers Emerge as Prime Targets in Cyber Warfare
In today's digital age, data centers have become a high-stakes battleground in cyber warfare, with modern economies, militaries, and corporations relying heavily on digital infrastructure to stay competitive and operational. A recent attack in the Middle East that took out cloud data centers served as a wake-up call, highlighting a critical vulnerability that could have far-reaching consequences.

DARPA Hands Over Space-BACN Laser Link Project to DIU
Imagine a universal key that lets satellites from different constellations communicate seamlessly - that's the game-changing potential of Space-BACN, a reconfigurable satellite laser link developed by DARPA and now handed over to DIU. This innovative technology could unlock a new era of collaboration and data sharing between previously incompatible optical communications systems.

Lawsuit Alleges Dating App Meete Exploits Users' Likenesses
A Tennessee lawsuit claims dating app Meete used a young woman's TikTok video in an ad without her consent, sparking concerns over user exploitation. The case highlights the alarming trend of apps profiting from users' likenesses without permission.

Indo-Pacific Emerges as Crucial Hub in Global Spyware Market
The Indo-Pacific region is now a critical hotspot in the global spyware market, playing a pivotal role in determining the fate of efforts to curb the proliferation of spyware. Its influence will have far-reaching consequences for governments, civil society, and even criminal networks.

US Launches Project Freedom to Secure Strait of Hormuz Shipping
The US has launched Project Freedom, a mission aimed at safeguarding the vital Strait of Hormuz shipping route, ensuring that merchant vessels can transit freely and safely. Two US-flagged vessels have already successfully navigated the strait under this new protection plan.

Attackers Exploit Amazon SES to Bypass Email Security in Phishing Campaigns
Phishing campaigns are now using Amazon's Simple Email Service to make malicious messages look legit, bypassing standard email security checks and putting victims at risk of revealing sensitive data. By exploiting Amazon SES's trusted reputation and authentication features, attackers are making it harder to spot phishing emails.

Trellix Breach Exposes Source Code Repository
Trellix has confirmed a security incident involving unauthorized access to part of its source code repository, and is working closely with forensic experts and law enforcement to investigate. The company is reviewing the breach and will share updates as more information becomes available.

Cybercrime Groups Exploit AI for Rapid, High-Impact Attacks
Cybercrime groups are leveraging AI to launch lightning-fast, high-impact attacks, outpacing security patches and leaving devastating consequences in their wake. This week, a critical vulnerability in cPanel and WHM was exploited, leading to website wipes, botnet deployments, and ransomware attacks.

Cybersecurity Experts Imprisoned for Ransomware Extortion Scheme
Two American cybersecurity experts, Ryan Goldberg and Kevin Martin, have been sentenced to prison for their roles in a brazen 2023 ransomware campaign that targeted companies across the United States. Their crimes have brought to light the severe consequences of cyberattacks and the importance of protecting businesses from such threats.

AI-BOMs Tackle Shadow AI Risks in Enterprise Supply Chains
Imagine biting into a cake without knowing the recipe, ingredients, or who's behind the baking - it's a risk you wouldn't take, right? Similarly, without AI-BOMs, enterprises are left in the dark about the AI components powering their supply chains, leaving them vulnerable to shadow AI risks.

Fraudsters Target Credit Unions with Structured Loan Scams
Fraudsters are now targeting credit unions with sophisticated loan scams, using stolen identities and social engineering to exploit lending workflows. In fact, auto lending fraud exposure is expected to hit $9.2 billion by 2025, making it a lucrative target for these scammers.

Progress Warns of MOVEit Automation Authentication Bypass Flaw
Progress Software has patched a critical authentication-bypass flaw in its MOVEit Automation product, and is strongly urging users to upgrade to the latest version to avoid low-complexity attacks by remote threat actors. Upgrading to version 2025.1.5, 2025.0.9, or 2024.1.8 and above will fix the vulnerability.

Silver Fox Targets India, Russia with ABCDoor Malware via Tax Phishing
Meet Silver Fox, a China-based cybercrime group that's using tax phishing scams to deliver a sneaky new malware called ABCDoor, targeting India and Russia with cleverly crafted emails that masquerade as official tax notices. The group's tactics involve PDFs with links to infected archives, tricking victims into downloading the malware.

AI-Assisted Attacks Surge as Barrier to Entry Drops
A 17-year-old with no coding experience was recently arrested for hacking into Kaikatsu Club and stealing 7 million users' personal data - his motive? To fund his Pokémon card habit. This shocking case highlights a disturbing trend: nontechnical individuals are now using AI-powered tools to launch devastating cyberattacks.

CISA Warns of Active Linux Exploit
A newly discovered Linux kernel bug, dubbed "Copy Fail," allows unprivileged users to gain root privileges on unpatched systems, prompting urgent warnings from CISA and researchers. If your Linux system was built between 2017 and the recent patch, you're at risk - and need to act fast to protect yourself.

cPanel Vulnerability Exploited to Target Gov't, MSP Networks
A critical cPanel vulnerability, CVE-2026-41940, is being actively exploited by attackers to bypass authentication and gain control of government, military, MSP, and hosting provider networks. This alarming threat uses hard-coded credentials and cleverly defeats CAPTCHA protections to wreak havoc on vulnerable systems.

Microsoft Updates Disrupt Third-Party Backup Apps on Windows
Microsoft's latest Windows security update has caused disruptions to third-party backup apps, adding a vulnerable kernel driver to its blocklist to protect users from potential exploits. This change aims to prevent attackers from escalating privileges or executing arbitrary code, but has unfortunately caused failures in some backup products.

Voter Data Exposes Personal Info to Potential Abuse
Your voter data is at risk of being exposed and used against you, with publicly available registration files potentially revealing sensitive information about you and your family. Even redacted files can be easily linked to other public datasets, making it simple for employers, fraud rings, or others to access your personal info.

Global Crackdown Targets Crypto Scam Centers, Arrests 276
In a major global crackdown, authorities have arrested 276 suspects and shut down nine cryptocurrency scam centers, dealing a significant blow to fraudsters targeting Americans from abroad. This coordinated effort, led by Dubai Police and involving the FBI and China's Ministry of Public Security, sends a clear message: scammers can't hide from the law, no matter where they are in the world.

Pakistan Accelerates Multi-Domain Defence Build-Up
Pakistan is rapidly bolstering its defence capabilities, with recent milestones including the launch of its fifth dedicated remote-sensing satellite and the commissioning of the advanced Hangor-class submarine, PNS/M Hangor, marking a return to long-endurance submarine operations. This strategic boost is set to significantly enhance the country's naval prowess.

Israel Bolsters Air Force with F-15IA and F-35I Squadrons
Israel's air defense is taking a massive leap forward with the government's approval of not one, but two cutting-edge fighter squadrons - the F-15IA and F-35I Adir - set to bolster the Israeli Air Force like never before. Prime Minister Benjamin Netanyahu proudly declared, "Israel is stronger than ever, and Israel must always be significantly stronger than our enemies."