Tag: emerging threats
5050 articles

Microsoft Update Disrupts Remote Desktop Security Warnings
Microsoft's latest update aimed at boosting Remote Desktop security may have an unintended consequence: a display-scaling bug that makes crucial security warnings hard to read or even unreadable. This glitch comes at a critical time, as the update was designed to protect against phishing attacks that exploit .rdp files.

Governance Gaps Exposed in AI Agent Deployments
To safely deploy AI agents, enterprises must first tighten up governance for the humans, bots, and machine identities that serve as their authority sources, since AI agents aren't independent actors but rather delegated ones. By reframing AI governance as a delegation issue, we can shift the focus from novelty to effective oversight.

Mandiant VP Warns of Resurgent Cybersecurity Risks in AI Deployments
As organizations rush to adopt AI, they're reviving long-standing cybersecurity failures, warns Mandiant VP Jurgen Kutscher, who urges a focus on basic security controls over new AI-specific threats. Neglecting these fundamentals leaves AI-enabled environments vulnerable to measurable operational weaknesses.

Microsoft Unveils Option to Uninstall Copilot on Enterprise Devices
Microsoft just made it easier for IT admins to breathe a sigh of relief: you can now uninstall Copilot from enterprise devices without any disruptions. The new RemoveMicrosoftCopilotApp policy setting is here to give you more control over your organization's devices.

Tropic Trooper Exploits SumatraPDF to Deploy AdaptixC2
Meet Tropic Trooper, a notorious cyber threat group that's been wreaking havoc since 2011, and learn how they've cleverly exploited SumatraPDF to deploy their AdaptixC2 malware. Their latest tactic involves using GitHub as a command-and-control platform to target Chinese-speaking individuals in Taiwan, as well as users in South Korea and Japan.

LMDeploy Vulnerability Exploited Within 13 Hours of Disclosure
A critical vulnerability in LMDeploy's vision-language module was exploited in the wild just 13 hours after its disclosure, allowing attackers to access sensitive resources and internal networks. This server-side request forgery flaw, tracked as CVE-2026-33626, affects all versions of the toolkit prior to 0.12.0.

UK Bans Journalists from Digital ID Forum
The UK government is calling on ordinary citizens to share their thoughts on a proposed Digital ID system, and you don't need to be an expert to join the conversation. Around 36,000 people have been invited to participate in the People's Panel on Digital ID, which will involve in-person meetings and online sessions to discuss how a Digital ID system should be designed for the UK.

Malware Targets Developers with Worm-Like Npm Supply Chain Attack
Malware is targeting developers through a sneaky npm supply chain attack, executing malicious code the moment a package is installed, and harvesting sensitive data to spread across ecosystems. Over 6,700 weekly downloads of one affected package show just how widespread the threat could be.

Researchers Uncover Pre-Stuxnet Cyber-Sabotage Malware
Meet fast16, a stealthy cyber-sabotage malware that went undetected until now, marking a new era in covert statecraft. Discovered by SentinelOne researchers, this silent threat has been hiding in plain sight since 2016.

Flaws in EV Charger Security Expose Cities to Denial-of-Service Attacks
A security researcher recently demonstrated how easily electric vehicle chargers can be hacked, leaving cities vulnerable to denial-of-service attacks with just a few clicks. In a stunning Black Hat Asia presentation, he showed how typing a simple charger ID into a custom-built script could instantly render a charging port useless.

China Builds Covert Hacker Networks with Compromised Routers
China-nexus cyber actors have dramatically changed their game, ditching solo operations for massive networks of hacked devices - and it's a threat you need to know about. A joint advisory from top cyber agencies worldwide warns of this new tactic, urging vigilance in the face of large-scale cyber attacks.

Navy Overhauls Refueling Tactics Amid Iranian Attacks
When Iranian missile and drone attacks disrupted traditional refueling operations, the US Navy was forced to rethink its logistics strategy, shifting from fixed port hubs to a more agile approach using commercially chartered tankers to fuel ships at sea. This pivot, dubbed a move from port hubs to "tanker treadmills," has been a game-changer for keeping naval vessels operational in the region.

US Military Embraces Autonomous Weapons for Future Warfare
The US military is betting big on autonomous weapons, with Joint Chiefs Chairman Gen. Dan Caine declaring they'll be a crucial part of future warfare, driving innovation in areas like drones and command-and-control systems. Gen. Caine is pushing for a cultural shift within the Pentagon to fully harness the power of AI and autonomous technology.

Surveillance campaigns exploit telecom vulnerabilities with commercial tools
Researchers have uncovered a shocking truth: telecom vulnerabilities are being exploited by covert surveillance campaigns using commercial tools, putting global telecommunications security at risk. This alarming trend allows unknown parties to track targets undetected, highlighting a pressing need for tighter regulations.

US Navy Bolsters Drone Defenses with Hellfire Missiles
The US Navy is ramping up its drone defense capabilities by arming its defenses with Longbow Hellfire missiles, a move driven by recent operational experiences that highlighted the need for enhanced protection. This upgrade is part of a rapid fielding effort to bolster the defenses of its most advanced carrier strike groups.

New Malware ZionSiphon Targets Water Plants, Falls Flat
A new piece of malware called ZionSiphon, reportedly targeting Israeli water facilities, has been found to be surprisingly inept, with experts describing it as broken and showing little understanding of its supposed targets. The malware's code includes strings referencing the Israeli water sector and politically charged messaging, but its overall incompetence has downplayed initial alarm.

Army Explores Apache Helicopters as Counter-Drone Solution
A single idea from a seasoned warrant officer is revolutionizing the Army's approach to counter-drone warfare - and it all started with a bold proposal to repurpose Apache helicopters as drone hunters. This innovative concept has sparked a program of experimentation, Operation Flyswatter, which aims to provide a more economical and effective solution to combating unmanned aerial systems.

Hackers Exploit Cisco Firewalls with Persistent Backdoor
A custom implant called Firestarter can infiltrate Cisco network security devices, evading patches and routine reboots by manipulating device boot configuration to restore itself. Only a hard reboot, physically disconnecting the device from its power supply, can clear the persistence mechanism from memory.

US Targets Iran's Small Boats in Escalating Strait of Hormuz Conflict
President Donald Trump has ordered the US Navy to take drastic action against Iranian small boats laying mines in the Strait of Hormuz, vowing to shoot and kill any vessels involved. The US is also ramping up demining efforts in the strategic waterway, tripling its operations to ensure safe passage.

Vercel Breach Exposes Wider Fallout in Developer Ecosystem
A recent Vercel breach has sent shockwaves through the developer ecosystem, with threat intel revealing a sophisticated attack that distributed malware to hunt for valuable tokens and keys. The incident has had far-reaching consequences, impacting multiple downstream environments and a small number of accounts.

Pentagon Overhauls Counter-Drone Strategy After Ukraine-Style Exercise
The Pentagon has overhauled its counter-drone strategy after conducting a Ukraine-style exercise, dubbed Operation Clear Horizon, which simulated the "spiderweb" drone attacks used by Ukrainian forces against Russia. This hands-on test helped shape the military's priorities for countering the growing threat of drones.

Iran's IRGC Consolidates Power, Shuns US Talks
Behind the scenes, a powerful force is driving Iran's tough stance - and it's not what you might think. A new generation of hardline commanders has taken the reins within the IRGC, making diplomatic efforts like Pakistan's mediation a tough nut to crack.

Pentagon's Golden Dome Project Advances Amid Skepticism
The Pentagon's Golden Dome project is gaining momentum, with Gen. Michael Guetlein assuring the public that progress is being made, contracts are being awarded, and milestones are being met on schedule and on budget. The project aims to turn a high-profile national security concept into tangible reality.

US Misjudged Iran, Paving Way for Decades of Conflict
In 1977, President Jimmy Carter hailed Iran as an "island of stability" - a label that proved drastically off the mark just months later when mass demonstrations erupted, fueled by deep-seated economic and social divisions. His glowing praise of Shah Mohammad Reza Pahlavi's leadership had ominously overlooked the warning signs of a revolution brewing.