Tag: emerging threats
5090 articles

Microsoft Deploys Fix for Windows Start Menu Search Disruption
Microsoft has swiftly deployed a server-side fix to resolve a frustrating issue that left some Windows 11 23H2 users unable to access the Start Menu search feature. This quick action means you should now be able to search with ease again.

Iran-Linked Hackers Target Internet-Exposed PLCs in US Infrastructure
Iran-affiliated hackers are launching targeted cyber attacks on internet-exposed devices controlling US critical infrastructure, including power plants, water systems, and manufacturing lines. This urgent threat requires immediate attention to protect vulnerable systems from devastating intrusions that can diminish functionality and manipulate operations.

Pentagon Pursues Software Upgrade to Enhance Aerial Awareness
The Pentagon is on a mission to supercharge its aerial awareness with a cutting-edge software upgrade, helping older planes to better detect and communicate with each other on the battlefield. This game-changing tech will enable legacy aircraft to stay ahead of the curve, even as the threat landscape evolves at breakneck speed.

Ransomware Ecosystem Evolves Amid Profitability Decline
The ransomware ecosystem is evolving, with the threat remaining alarmingly widespread across industries and regions, yet the business model fueling it is showing signs of strain. This paradox has emerged as ransomware-as-a-service and specialization have driven its growth, despite declining profitability.

Researchers bypass Grafana AI with stealthy data exfiltration technique
Imagine a tool meant to reveal operational insights being turned into a stealthy spy, siphoning off sensitive corporate secrets - that's what happened when researchers exploited Grafana's AI with a cunning technique called indirect prompt injection. Dubbed GrafanaGhost, this attack bypasses Grafana's defenses, exfiltrating data without leaving a digital trail.

US Military Unveils Details of Daring F-15E Rescue Operation in Iran
Imagine being trapped deep inside enemy territory with no clear escape route - that's exactly what happened to an F-15E weapon systems officer, and the daring rescue operation that followed is a heart-stopping tale of bravery and precision. A newly detailed account reveals the thrilling story behind the high-risk extraction effort that saved the officer's life.

Kaspersky Uncovers Horabot Campaign Targeting Mexico
Kaspersky's Security Operations Center has uncovered a complex Horabot campaign targeting Mexico, and is now sharing crucial insights on how it works and how to detect it. This critical threat intelligence will help defenders in Mexico and beyond prioritize their resources and stay one step ahead of the threat.

DarkSword Exploit Chain Spreads Across Threat Actors
A single iOS exploit chain, known as DarkSword, has been spreading rapidly among threat actors, allowing multiple groups to fully compromise iPhones across several countries. This compact, multi-vulnerability exploit leverages zero-day vulnerabilities to achieve complete device takeover, and was first detected in the wild in November 2025.

Iran-Backed Hackers Infiltrate US Industrial Controls
US cyber and intelligence agencies have sounded the alarm: pro-Iran hackers have infiltrated and disrupted critical US infrastructure, including water and energy systems, posing a pressing threat to national security. These foreign actors have breached government networks and industrial controls, sparking urgent concerns about the vulnerability of America's essential services.

FBI Report Exposes Soaring Cybercrime Losses
Cybercrime losses have skyrocketed 26% to a staggering $20.9 billion in 2025, but the true extent of the damage is likely much worse, as many victims suffer in silence, never reporting the crimes they endure.

TeamPCP Infiltrates Security Infrastructure with Multi-Stage Supply Chain Attack
When security tools meant to safeguard networks become the entry point for attacks, trust is shattered - and that's exactly what's happening with TeamPCP's multi-stage supply chain attacks on security infrastructure. This sinister tactic lets threat actors turn protectors into launchpads for wider compromise.

Mandiant Report Reveals Evolving Cyber Threat Tactics
Discover the alarming evolution of cyber threats in Mandiant's M-Trends 2026 report, which reveals a stark reality: attackers are now operating under two distinct playbooks, drastically changing the detection, response, and risk landscape. The report uncovers a significant increase in global median dwell time to 14 days, with some attacks lingering for as long as 122 days.

Kaspersky Report Exposes Shifting Cyberattack Landscape
Get ready to face the future of cyber threats! The Kaspersky Security Services report delivers eye-opening insights into the evolving cyberattack landscape, combining real-world incident response findings with hard data from its Managed Detection and Response service.

RQ-180 Stealth Drone Spotted Flying Over Greece in Broad Daylight
A top-secret stealth drone, the massive RQ-180, has been spotted flying in broad daylight over Greece, revealing new details about its design and presence. The unusual daytime sighting of this covert aircraft is providing fresh insights into its configuration and capabilities.

Feds Warn of Iranian Cyberattacks on US Energy, Water Systems
US government agencies have issued an urgent warning that Iranian hackers are launching targeted cyberattacks on America's energy and water infrastructure, posing a serious threat to the communities that rely on them. These attacks have already caused harm to victims in the past month, highlighting the need for immediate vigilance.

Unit 42 Uncovers Axios Supply Chain Attack's Far-Reaching Consequences
When a trusted software pathway is compromised, the consequences can be far-reaching - as Unit 42's recent analysis of the Axios supply chain attack starkly reveals, threatening digital trust and resilience. The team's detailed examination exposes the attack's full chain, from initial dropper to forensic cleanup.

North Korea-linked actor compromises axios NPM package
A shocking discovery by Google Threat Intelligence Group has exposed a vulnerability in the popular axios NPM package, which has over 100 million weekly downloads, and has raised urgent questions about the trustworthiness of software supply chains. A malicious dependency was secretly introduced into axios releases, putting countless applications at risk.

Kaspersky Uncovers Coruna Exploit Kit Linked to Operation Triangulation
Kaspersky's researchers have made a significant discovery: the Coruna exploit kit, now targeting iPhones, uses an updated kernel exploit linked to the notorious Operation Triangulation. This finding highlights the evolving threat landscape, where offensive code is repurposed to target new devices.

APAC Firms Scramble to Bolster Cloud Security Amid Rising Identity Risks
As APAC firms rush to adopt cloud technology, they're faced with a daunting dilemma: do they risk advancing without a plan, or delay and let identity-related risks leave them vulnerable? With identity issues already causing the majority of cloud breaches in the region, the clock is ticking to get cloud security right.

Unit 42 Research Exposes Risks in Amazon Bedrock's Multi-Agent AI Systems
Unit 42's latest research reveals a hidden threat: multi-agent AI systems on Amazon Bedrock can be vulnerable to new and alarming risks, including prompt injection attacks that practitioners can't afford to ignore. Learn how to safeguard your AI applications from these emerging threats.

Feds Disrupt Russia-Backed Espionage Network Infecting 18,000 Devices
Federal authorities have successfully disrupted a massive Russia-backed espionage operation that had infiltrated nearly 18,000 devices, stealing sensitive account credentials and tokens by hijacking internet traffic. This significant takedown thwarts the efforts of Forest Blizzard, a notorious threat group linked to Russia's GRU.

China's PLA Revives Explosive Tactics in Modern Warfare
The People's Liberation Army is dusting off old-school explosive tactics, deploying high-explosive satchels and makeshift charges in modern warfare, a move that suggests even simple tools can still pack a punch on the battlefield. This revival is reportedly inspired by lessons learned from the war in Ukraine, where humble explosive charges proved their continued relevance.

VMware vSphere Ecosystem Targeted by BRICKSTORM Malware Attacks
Imagine an attacker sneaking past your trusted operating system and into the hidden infrastructure that powers your virtual machines - that's the risk posed by BRICKSTORM malware, which targets the VMware vSphere ecosystem. This stealthy threat allows adversaries to operate undetected, evading traditional endpoint tools by establishing persistence at the virtualization layer.

Malicious AI Gateway Exposes Data Through Supply Chain Breach
A recent analysis of LiteLLM, a popular AI gateway, revealed a supply chain breach that embedded malicious code designed to steal sensitive data, highlighting the vulnerability of even the most trusted components. This breach turned a multifunctional gateway meant to enhance AI agents into a vector for data theft, putting countless users at risk.