Tag: emerging threats
4873 articles

Musk's OpenAI Lawsuit Threatens $852 Billion AI Empire
Elon Musk is taking on OpenAI in a lawsuit that could shake up the $852 billion AI industry, claiming the company's shift from nonprofit to profit-driven motives betrays its founding promise to develop technology for the public benefit. He's asking the court to undo OpenAI's corporate transition and restore its original mission.

FBI Disrupts Global Crypto Scam Network
In a massive global crackdown, US and international authorities have dismantled a notorious network of cryptocurrency scam centers, arresting at least 276 individuals across the Middle East and Southeast Asia. This historic operation marks one of the largest US-assisted enforcement efforts against transnational cybercrime networks to date.

WordPress Plugin Exposes 70,000 Sites to Backdoor Vulnerability
A shocking security vulnerability has been uncovered in a popular WordPress plugin, leaving over 70,000 sites open to backdoor attacks that can inject malicious code on demand. The issue was discovered in the Quick Page/Post Redirect plugin, which was infected with a hidden backdoor five years ago.

Hackers exploit Qinglong flaws for cryptomining deployments
Hackers are taking advantage of two major flaws in the Qinglong open-source task scheduler, CVE-2026-3965 and CVE-2026-4047, which can be combined to gain remote control of vulnerable systems. These authentication-bypass vulnerabilities affect Qinglong versions 2.20.1 and older, and have been exploited for cryptomining deployments.

UK Biobank Data Surfaces for Sale on Alibaba Amid Security Probe
UK Biobank data was mysteriously listed for sale on Alibaba, but thankfully, the listings were swiftly removed with the help of the UK and Chinese governments, and no sales were made. The sensitive data, which includes genomic information, health records, and medical imaging, had been shared with researchers but was de-identified to protect participants' identities.

Researchers Develop Powerful GPS Interference Detector
Meet the game-changing GPS interference detector from Oak Ridge National Laboratory, designed to safeguard navigation systems from spoofing and jamming threats - and it's hitting the road first. This portable powerhouse uses cutting-edge tech to filter out fake signals and noise, giving drivers and fleets a reliable route to accurate location data.

Microsoft to Discontinue Legacy TLS Versions in Exchange Online by July 2026
Microsoft is putting the brakes on outdated security protocols, announcing that it'll start blocking legacy TLS 1.0 and 1.1 connections to Exchange Online in July 2026 - so it's time to upgrade and stay secure! This move marks the end of an era for older clients that still rely on these outdated protocols.

Microsoft Patch Fails to Quell Russian Spy Exploitation of Windows Flaw
Microsoft's latest patch isn't enough to stop Russian spies from exploiting a Windows flaw, leaving sensitive information vulnerable to exposure. The incomplete fix is linked to a previously patched vulnerability from February, highlighting the urgent need for a more robust solution.

Ukrainian Police Disrupt Roblox Account Hacking Ring
Ukrainian police have cracked down on a massive Roblox account hacking ring, arresting three suspects who hijacked over 610,000 accounts and resold them for a staggering $225,000 profit. The bust in Lviv also yielded a haul of $35,000 in cash and dozens of digital devices.

Navy Unveils Advanced Sonobuoys to Counter Submarine Threats
The Navy is supercharging its sonar arsenal with next-gen sonobuoys that can slam into the ocean surface at 100Gs, giving enemy subs a serious reason to hide. These advanced devices are being designed to sense and communicate in contested waters, bringing critical capabilities closer to the action.

Belgium Pursues $1.3B Counter-Drone Systems Upgrade
Belgium is taking a major leap in defense tech with a whopping $1.3 billion counter-drone systems upgrade, aiming to bolster its security with cutting-edge tech. The 10-year project, with an option for two more years, is part of a long-term plan to deploy robust counter-drone systems.

Air Force Accelerates Low-Cost Cruise Missile Buys
The Air Force is gearing up to supercharge its munitions inventory with a massive buy of nearly 27,000 low-cost cruise missiles, dubbed the Family of Affordable Mass Missile, with a whopping $12 billion allocated to stockpile the game-changing weapon. This aggressive plan aims to rapidly replenish stockpiles and expand production.

Pakistan ARFC Deploys Fatah-II Missile in Training Launch
Pakistan's Army Rocket Force Command has successfully launched the Fatah-II missile in a training exercise, showcasing its unique trajectory and marking a significant milestone in crew proficiency and readiness. This latest test validates the system's technical capabilities and paves the way for enhanced accuracy and survivability.

EU Advances Mandatory Online Age Verification Despite Security Risks
The European Commission's recent findings have revealed that Meta failed to protect minors, with a staggering 12% of European children under 13 reportedly accessing Facebook or Instagram, sparking concerns over online safety. This has led to a push for mandatory online age verification, despite security risks.

Firefox Exposed: AI Model Uncovers 271 Zero-Day Vulnerabilities
Meet the AI model that just supercharged Firefox security, uncovering a whopping 271 zero-day vulnerabilities that have now been squashed in the latest update to Firefox 150. This game-changing collaboration between Firefox and Anthropic's cutting-edge tools has made the browser safer than ever.

CISA Warns of Data Theft Bug in NSA-Built OT Networking Tool
A critical vulnerability, CVE-2026-6807, has been discovered in an NSA-built networking tool that could allow hackers to steal sensitive information by exploiting an XML parsing weakness. If left unpatched, this flaw could lead to devastating data breaches.

Malware Targets SAP npm Packages in Supply Chain Attack
A new supply-chain attack campaign, dubbed mini Shai-Hulud, is targeting SAP-related npm packages, delivering credential-stealing malware that threatens JavaScript and cloud applications. This sneaky attack puts sensitive data at risk, and experts are warning of a potentially massive impact.

cPanel Rushes Emergency Update to Fix Auth Bypass Bug
A critical security vulnerability in cPanel software has been discovered, allowing unauthorized access to the control panel, prompting immediate action from providers like Namecheap to protect customers. cPanel has since rushed out an emergency update to fix the authentication bypass bug affecting all currently supported versions.

North Korea Targets Developers with AI-Generated npm Malware
Security researchers have uncovered a sneaky malware campaign targeting developers, involving a malicious npm package called @validate-sdk/v2 that's designed to steal sensitive secrets, including crypto-wallet credentials. This tainted package, linked to a North Korean threat actor, was cleverly disguised as a utility SDK for legitimate tasks like hashing and validation.

Cursor Flaw Exposes Developer API Keys to Unrestricted Access
A single design flaw in the AI-powered development tool Cursor has been found to expose developer API keys to unrestricted access, earning a high-severity CVSS score of 8.2. This vulnerability stems from Cursor's weak storage design, which stores sensitive authentication data in a locally accessible SQLite database without proper protection.

Ransomware Drives 90% of Manufacturing Cyber Losses
Ransomware is wreaking havoc on the manufacturing sector, responsible for a staggering 90% of total cyber losses - despite accounting for just a small fraction of claims. When ransomware strikes, the financial blow is severe, highlighting the urgent need for robust security measures.

Police Disrupt €50 Million Crypto Investment Fraud Ring
A massive €50 million crypto investment fraud ring has been dismantled thanks to a joint investigation by Austrian and Albanian authorities, supported by Europol and Eurojust, resulting in the arrest of 10 suspects and the seizure of cash and electronic devices. The alleged scammers, operating from call centres in Albania, left a trail of financial devastation across Italy, Germany, Greece, Spain, Canada, and the UK.

AI-Assisted Code Targets Crypto Wallets via Malicious npm Dependency
Researchers have uncovered a sneaky malicious npm campaign, dubbed PromptMink, linked to North Korean hackers Famous Chollima, which targets crypto developers with fake utility packages that secretly steal sensitive info and funds. The campaign's clever tactics even involve an AI-assisted code commit to fly under the radar.

OAuth Breach Risks Expose AI-Driven Enterprise Vulnerability
A single misstep with a trial AI tool led to a major breach: a Vercel employee's casual OAuth grant to Context.ai created a lasting vulnerability that attackers exploited when Context.ai was compromised. This incident highlights the alarming ease with which AI-driven tools can become enterprise security weak spots.