Tag: emerging threats
4687 articles

Threat Actors Leverage AI-Generated Scripts to Accelerate Active Directory Attacks
Cyber attackers are now using AI-generated scripts to supercharge their Active Directory attacks, allowing them to quickly map and exploit sensitive domains, users, and computers. This alarming trend was uncovered by Huntress researchers, who analyzed a sophisticated PowerShell script that bore hallmarks of AI assistance.

Autonomous AI Transforms SOC with Analyst Copilots
Imagine sitting with a Fortune 50 CISO, witnessing a critical moment of clarity: "This is exactly what is wrong with how most security teams are designing their AI architecture right now." It turns out, current AI designs in the SOC are misguided, asking the wrong part of the decision process to do the wrong work.

Cyber-attackers Exploit OAuth Client ID Spoofing in Cloud Environments
Cyber-attackers are increasingly using OAuth Client ID spoofing to infiltrate cloud environments, with multiple campaigns emerging, each with unique tools and infrastructure. This technique allows attackers to cleverly abuse Microsoft Entra ID by mimicking legitimate authentication requests.

Infostealer Infection Enables Argentine FA Breach
A single compromised computer with high-level access likely gave hackers the keys to the Argentine Football Association's database and internal email system, thanks to an infostealer infection that went undetected for months. The breach, traced back to September 8, 2025, highlights the devastating impact of a simple infection on a high-privilege machine.

Progress Software Probes External Threat to ShareFile Storage
Progress Software has alerted ShareFile customers to a credible external security threat targeting its Storage Zone Controllers, and is urging immediate action to protect sensitive data. The company has promised to provide an update within 24 hours and recommends that affected customers disable account access and shut down servers.

EU Targets Russian Hackers with Sanctions Over Europe Cyberattacks
The European Union is cracking down on Russian hackers, imposing sanctions on nine individuals and four entities linked to malicious cyber operations that threaten the continent's security and stability. This move targets those behind a foiled attack on Poland's critical infrastructure, which could have left 500,000 people in the dark during winter.

Australia, India Forge Deeper Security Ties to Counter Regional Threats
Australia and India are taking their defence partnership to the next level with a new Joint Declaration, aiming to boost interoperability and information sharing between their forces to tackle regional threats. This landmark deal marks a significant step towards closer coordination and consultation on defence matters between the two nations.

Germany, Ukraine Partner to Co-Produce BARS Missile-Drone
Ukraine and Germany have joined forces to co-produce the game-changing BARS missile-drone, a powerful jet-powered strike weapon that's proven its mettle in targeting deep into Russian territory, including Moscow. The historic deal, signed on the sidelines of the NATO summit, cements a major boost to Ukraine's defence capabilities.

Pakistan Eyes New Army Aviation Assets to Bolster Counterinsurgency Push
Pakistan is gearing up to supercharge its counterinsurgency efforts with fresh army aviation assets, as part of a massive and ongoing operation in Balochistan. The move marks a major revival of the Pakistan Army Aviation Corps' large-scale operations after a decade-long hiatus.

AI-Generated Code Exposes Governance Gaps in Security Debt
AI-generated code is being produced at alarming rates, but with a catch: nearly half of it contains security flaws, highlighting a pressing need for new approaches to managing security debt. As software creation accelerates, companies must adapt their security strategies to keep pace with the rapid accumulation of vulnerabilities.

Progress Disrupts ShareFile Servers Over External Security Threat
If you're a ShareFile customer, take immediate action: shut down your Storage Zone Controller servers now to protect against a critical external security threat. Progress Software has already disabled access to affected accounts, but manual shutdown is crucial for safeguarding your data.

Russian Hackers Target Routers Globally, Warn Cybersecurity Agencies
A brazen plot by Russian hackers to disrupt global networks was thwarted, but not before cybersecurity agencies warned of a potentially catastrophic attack that could have left 500,000 citizens shivering in the dark. The hackers, linked to Russia's Federal Security Service, targeted vulnerable routers worldwide using simple and easily exploitable passwords.

Ryuk Ransomware Operative Pleads Guilty in US Court
A major player behind the notorious Ryuk Ransomware gang has taken responsibility for their crimes, with Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleading guilty in a US court to conspiracy and computer fraud. As part of his plea deal, Vardanyan will pay over $1.1m in restitution for his role in the massive cyberattack that netted over $15m in bitcoin payments.

Russian Hackers Target Critical Infrastructure via Router Exploits
Russian state-backed hackers have infected 18,000 routers in 120 countries, sparking a multinational warning about the threat to critical infrastructure networks. The alarming campaign is linked to Russia's Federal Security Service (FSB) Centre 16, notorious for exploiting poorly configured routers to gain access to sensitive networks.

Evilginx Phishing Ops Expose Microsoft 365 MFA Weaknesses
A French security firm stumbled upon a live Microsoft 365 phishing operation when a simple Python command was left exposed in a readable file, revealing a treasure trove of sensitive data. This lucky discovery shed light on the alarming weaknesses in Microsoft 365's multi-factor authentication.

Joomla Flaws Exploited as Zero-Days in Active Attacks
A critical vulnerability in the iCagenda extension for Joomla, known as CVE-2026-48939, has been exploited as a zero-day since June 15, 2026, allowing attackers to upload arbitrary files via the component's file attachment feature. This severe flaw, scoring 10.0 on the CVSS scale, has already sparked a wave of automated attacks against popular content-management-system extensions.

OpenAI Lifts GPT-5.6 Sol Usage Limits Amid Surging Demand
Big news for ChatGPT fans: OpenAI has temporarily lifted usage limits for Plus, Pro, and Business plans, giving you more time to tap into the power of its most advanced model. This move comes after a surge in demand over the past 48 hours, with the company also resetting current usage for all customers.

Australia Urged to Empower ACSC as Cybersecurity Regulator
As cyber threats increasingly put Australia's critical infrastructure, economy, and national resilience at risk, the country faces a critical choice: rely on voluntary measures or establish a robust cybersecurity regulator with the power to enforce minimum standards and hold organizations accountable. Empowering the Australian Cyber Security Centre (ACSC) as a formal regulator could be the key to bolstering the nation's cyber defenses.

RedHook Android Malware Exploits Wireless ADB for Shell Access
Meet RedHook, a sneaky Android malware that's taking advantage of Wireless ADB and Accessibility features to gain shell-level control over your device - and it can be controlled remotely with 53 server-issued commands. This clever malware tricks victims into granting permissions, then takes control, making it a serious threat to your digital security.

PLAAF Aviation Brigade Signals Shift with Mixed Aircraft Types
A surprising twist in China's military lineup has caught attention, as a single PLAAF Aviation Brigade was spotted with not one, but two different aircraft types on parade, defying the conventional one-brigade-one-aircraft-type model. This unusual display hints at a potential shift in the PLAAF's strategic approach.

Pakistan Launches Operation Shaban to Counter Balochistan Insurgency
Pakistan is taking a bold stance against insurgency in Balochistan with Operation Shaban, a powerful two-front offensive aimed at eradicating militant groups. The operation, launched in early July 2026, promises to run with full force until every last militant is eliminated.

Ukraine Disrupts Russian Shipping in Sea of Azov with Drone Strikes
Ukraine's daring drone strikes have dealt a significant blow to Russian shipping in the Sea of Azov, with a single night's operation taking out 21 tankers, 4 tugs, 2 cargo vessels, and 1 special-purpose vessel. The bold move is just the latest in a series of targeted attacks by Ukraine's elite drone unit, known as "Magyar's Birds".

China, India-Aligned Hackers Target Pakistani Law Enforcement in Espionage Campaigns
Cyber attackers have launched a stealthy espionage campaign targeting Pakistani law enforcement agencies, breaching sensitive data like biometric records, criminal files, and personnel info. The compromised assets included servers managing police and citizen data at organizations like Balochistan Police.

Compromised jscrambler NPM Package Drops Rust Infostealer
A malicious version of the jscrambler NPM package, 8.14.0, was published on July 11, 2026, and could silently infect your system with a Rust-based infostealer just by installing it, no extra steps required. Merely running the install command was enough to trigger the payload on vulnerable systems.