Tag: emerging threats
4687 articles

Australian Cyber Agency Warns of Global CMS Exploitation Campaign
Beware: a large-scale cyber attack is targeting content management systems worldwide, including in Australia, putting many small- to medium-sized businesses at risk of service disruption, credential theft, and malware installation. The Australian Cyber Security Centre warns that this global campaign is actively scanning for vulnerabilities and compromising websites.

Ghostcommit Exposes AI Code Reviewers to Secret Theft via Image Steganography
Researchers have uncovered a sneaky way to steal secrets from AI code reviewers using image steganography, as demonstrated in a proof-of-concept on GitHub. This Ghostcommit technique hides malicious instructions inside PNG images, exploiting a gap in the review process.

Zimbra Warns of Stored XSS Flaw in Classic Web Client
Zimbra is urging customers to update their Classic Web Client immediately due to a critical vulnerability that could allow hackers to access sensitive mailbox information and execute malicious code via specially crafted emails. Installing the update, specifically upgrading to Zimbra Collaboration Suite version 10.1.19, will help protect against this threat.

US Deploys F-22 Raptors to England After Iran Operations
US Air Force F-22 Raptors have arrived at RAF Fairford in England after playing a key role in precision missions against Iranian air defenses and nuclear infrastructure. The stealth fighter jets, part of the 1st Fighter Wing at Langley Air Force Base, flew in from Israel where they were deployed since late February.

CISA Bolsters Protections After Major Credential Leak
CISA swiftly sprang into action after discovering a major credential leak on May 15, taking swift and decisive steps to halt the breach and prevent further damage. By sharing their incident response experience, CISA aims to help other organizations bolster their defenses and avoid similar security mishaps.

Armenian National Pleads Guilty to Ryuk Ransomware Conspiracy
Karen Serobovich Vardanyan, an Armenian national, has pleaded guilty to conspiracy charges for his role in a massive Ryuk ransomware scheme that raked in over $15 million in ransom payments from US-based organizations. The guilty plea marks a major win in the fight against cybercrime, as Vardanyan admitted to his part in the global extortion plot.

The Gentlemen Ransomware Expands Reach with Lucrative Affiliate Model
Meet The Gentlemen, a ransomware group that's rapidly risen to notoriety with a game-changing affiliate model that dishes out a whopping 90% payout to its partners. This lucrative approach has helped them scale from a small operation to one of 2026's most active ransomware-as-a-service programs in record time.

Russia Weighs Intelligence Sharing with North Korea Over Satellite Tech Transfer
North Korea's recent launch of the Malligyong-1 satellite marks a significant tech milestone, but the real challenge lies ahead: developing a network of coordinated satellites to monitor the Korean Peninsula and US military hubs in the Western Pacific. A single satellite just isn't enough for effective surveillance.

U-Boot Flaws Expose Devices to Stealthy Firmware Attacks
Researchers uncovered six critical vulnerabilities in U-Boot's firmware signature verification code, leaving devices open to stealthy attacks that can execute malicious code at startup. These flaws, ranging from denial of service to arbitrary code execution, highlight a major security risk that needs to be addressed.

Progress Disrupts ShareFile Storage Over Unspecified Security Threat
Progress Software has urgently advised ShareFile customers to take their Windows servers offline due to a credible external security threat, acting swiftly to protect user data despite having no evidence of unauthorized access. The company is working closely with security experts to resolve the issue and restore services.

U-Boot Flaws Expose Devices to Code Execution, Crashes
Six newly discovered flaws in U-Boot, a widely used bootloader, leave devices from home routers to data-center servers vulnerable to code execution and crashes, posing a significant risk to everything that loads after it. These vulnerabilities can be exploited before the operating system even starts, undermining the entire security chain.

GitHub Compromise Injects Malicious npm Packages with Wallet-Key-Stealing Code
A malicious actor hijacked a trusted GitHub account and used it to inject wallet-key-stealing code into 18 npm packages, including Injective Labs' SDK, by exploiting the project's pipeline. This sneaky move allowed the attacker to spread the backdoor through a series of seemingly legitimate updates.

Microsoft Uncovers GigaWiper Backdoor with Ransomware, Wiping Capabilities
Microsoft has uncovered a highly destructive backdoor, dubbed GigaWiper, which combines ransomware and wiping capabilities, marking a concerning shift in the evolution of wiper malware. This modular threat can both extort and destroy, posing significant real-world consequences.

Ryuk Ransomware Operative Pleads Guilty, Faces 15-Year Sentence
A 34-year-old Armenian man, Karen Serobovich Vardanyan, has pleaded guilty to masterminding a brazen ransomware scheme that raked in around $15 million by infiltrating hundreds of computer networks and deploying Ryuk ransomware. Vardanyan's guilty plea comes after his extradition from Ukraine, where he was arrested in April 2025.

Progress Warns ShareFile Customers of Credible Security Threat
Progress Software has alerted ShareFile customers to a credible external security threat targeting their Storage Zone Controllers, prompting an urgent directive to take immediate action. To protect themselves, customers are advised to shut down their Windows servers hosting these controllers right away.

Dutch Police Expose Suspects in Odido Hacking Case
The Dutch National Police have cracked the Odido hacking case, revealing that suspects impersonated an IT employee in a phone call with customer service, tricking the company into divulging sensitive info through phishing. This clever ruse led to a massive data theft in February.

CISA Exposes Lessons from AWS GovCloud Key Incident Response
When a security researcher uncovered exposed credentials in a public GitHub repository, CISA sprang into action, swiftly mitigating any potential exposure to its cloud resources and code repositories. Thanks to the researcher's sharp eyes and KrebsOnSecurity's reporting, CISA was able to respond quickly and contain the incident.

Bulgarian Money Launderer Accused of Stealing Seized Crypto
Rossen G. Iossifov, already serving 121 months for a money laundering scheme, now faces new charges for allegedly trying to steal $290,000 in government-seized cryptocurrency while behind bars. He and his co-conspirators are accused of moving the digital assets to prevent seizure, according to a federal indictment in Kentucky.

Laser Attack Exploits Tangem Wallet's Unpatchable Flaw
A newly discovered exploit allows attackers to reset the password on Tangem crypto-wallet cards using a precisely timed laser pulse, giving them full control over the wallet and its contents. This physical attack, which requires specialized equipment and possession of the card, leaves all existing Tangem cards vulnerable and unfixable by software.

Microsoft Exposes GigaWiper Malware's Dual Espionage, Destructive Capabilities
Microsoft researchers have uncovered a highly sophisticated malware, GigaWiper, that masterfully combines espionage and destructive capabilities, allowing threat actors to operate efficiently and wreak havoc on infected systems. This multi-purpose backdoor enables attackers to quietly gather intel while packing a punch with its suite of destructive options.

Hackers exploit auth bypass in Gitea Docker image
Hackers are actively exploiting a critical flaw in the Gitea Docker image, using a single header to bypass authentication and gain access - and security teams are only just catching on. In fact, researchers detected the first real-world hit just 13 days after the vulnerability was disclosed.

Pakistan Charts Middle East Course Between Iran and Saudi Arabia
Pakistan is emerging as a key player in the Middle East, leveraging its diplomatic prowess to broker a historic ceasefire between the US and Iran in April 2026, and positioning itself at the centre of a region in flux. This bold move has sparked debate about Iran's growing ambitions and Islamabad's role in shaping the region's future.

AI Alters Human Speech Patterns
Imagine interacting with ChatGPT and receiving a response that sounds like a robotic, three-part formula - it's a pattern that's distinctly non-human and may be changing the way we communicate. From affirmations to multiple-choice queries, these new rhythms of reply are a far cry from the emotional ebbs and flows of live speech.

AI Surveillance Poses Profound Threat to Social Progress
Imagine a world where AI surveillance systems don't just watch, but also notice, record, and punish even the smallest infractions - essentially becoming automated enforcers that can fine you on the spot. China is already demonstrating the power and pitfalls of this technology, using it to publicly shame and penalize citizens who step out of line.