Skip to main content

Tag: emerging threats

5110 articles

Cybercrooks Exclusive: Devastating Cargo Heists Exposed

Cybercrooks Exclusive: Devastating Cargo Heists Exposed

Meet the new face of cargo theft: software-savvy criminals breach freight systems and team up with on-the-ground hijackers to divert high‑value shipments—creating faster, stealthier heists that ripple through supply chains and national security.

Analyst 207
Dark cityscape with cracked window, eerie glows, and ghostly figure in hoodie in front of laptop screen.

New GDI Flaws: Exclusive Critical Windows RCE Risk

Imagine the Graphics Device Interface — the decades-old Windows component that renders windows, text and images — suddenly becoming an open door for attackers: researchers disclosed GDI flaws that can enable remote code execution or sensitive data leaks via crafted images or fonts. Until patches arrive, treat untrusted images and documents cautiously, tighten monitoring, and apply least-privilege controls to reduce risk.

Analyst 207
BankBot-YNRK Exclusive: Critical Trojans Steal Funds

BankBot-YNRK Exclusive: Critical Trojans Steal Funds

If your phone suddenly knows more about your bank account than you do, this is why: researchers uncovered banking trojans BankBot‑YNRK and DeliveryRAT that harvest credentials, hijack sessions, and even dodge detection by spotting emulators and sandboxes. They spread through sideloaded or re‑packaged apps and abuse high‑risk permissions to steal funds and control devices.

Analyst 207
HttpTroy Exclusive: Dangerous VPN Invoice Backdoor in Korea

HttpTroy Exclusive: Dangerous VPN Invoice Backdoor in Korea

HttpTroy exposes a dangerous VPN invoice backdoor in Korea. Find out how attackers are slipping into billing systems and what you can do to stay protected.

Analyst 207
Conti Suspect Shocking Court Debut Shows Damaging Leads

Conti Suspect Shocking Court Debut Shows Damaging Leads

A Ukrainian national’s U.S. court debut in a Conti-related ransomware case pulled back the curtain on how cybercrime now moves like commerce—crossing borders, inflicting massive economic harm, and leaving a trail of damaging leads. The indictment is just the opening move in a complex fight to hold this near‑industrial extortion trade to account.

Analyst 207
Leak Site Ransomware Victims: Alarming 13% Spike Exclusive

Leak Site Ransomware Victims: Alarming 13% Spike Exclusive

Wake-up call: ransomware victims in Europe surged 13% year‑on‑year as criminals adopt stealthy, profit-driven tactics—RATs, data theft and public leak sites—to extract bigger payoffs. Businesses, governments and households need to rethink defenses now before they become the next target.

Analyst 207
Attackers Reinstall Malware on Cisco: Stunning Risk

Attackers Reinstall Malware on Cisco: Stunning Risk

Meet BADCANDY — an implant that watches for removal and quietly reinstalls itself on unpatched Cisco IOS XE devices, turning cleanup into a dangerous game of whack-a-mole that puts enterprise networks and critical infrastructure at risk. If you manage routers or switches, consider this your wake-up call to inventory, patch, and harden before attackers make persistence permanent.

Analyst 207
Nation-State Hackers Deploy Dire Exclusive Airstalk Malware

Nation-State Hackers Deploy Dire Exclusive Airstalk Malware

Think your MDM keeps devices safe? Think again — a suspected nation-state is using the AirWatch API to deploy Airstalk malware, hijacking trusted management channels to stealthily compromise fleets of phones.

Analyst 207
Conduent Data Breach: Stunning, Severe Impact on 10.5M

Conduent Data Breach: Stunning, Severe Impact on 10.5M

A single contractor’s lapse exposed the financial and personal records of 10.5 million people — the Conduent data breach shows how concentrated services can turn vendors into high-stakes targets. Read on to learn what went wrong, who’s at risk, and what comes next.

Analyst 207
China-Linked Hackers Exploit Windows Flaw: Exclusive Threat

China-Linked Hackers Exploit Windows Flaw: Exclusive Threat

What looks like a harmless Windows shortcut can be a Trojan at the gate—China-linked UNC6384 used malicious .lnk files in ZIPs to invoke PowerShell and DLL sideloading, quietly breaching diplomatic and government targets across Europe in Sept–Oct 2025.

Analyst 207
China-Linked Tick Group Exclusive: Critical Lanscope 0-day

China-Linked Tick Group Exclusive: Critical Lanscope 0-day

Think of it as the patch arriving after someone already walked through the door — a critical CVE‑2025‑61932 (CVSS 9.3) zero‑day in Motex Lanscope has been weaponized in the wild by the China‑linked Tick group. The flaw allows unauthenticated SYSTEM‑level command execution on on‑prem Lanscope servers, so if you run Lanscope, find exposed instances, isolate them from untrusted networks, and apply mitigations or updates immediately.

Analyst 207
Chinese-Linked Hackers Stunning Windows Spy Damages Envoys

Chinese-Linked Hackers Stunning Windows Spy Damages Envoys

Chinese-linked UNC6384 is exploiting a Windows vulnerability to plant stealthy spyware in diplomatic and commercial networks—an unsettling upgrade in tradecraft that challenges whether governments, companies, and users can patch porous defenses before quiet probes turn into loud alarms.

Analyst 207
Clearview AI Faces Stunning, Damaging Complaint in Austria

Clearview AI Faces Stunning, Damaging Complaint in Austria

Austria’s criminal complaint against Clearview AI escalates a cross-border privacy showdown, turning years of regulatory scrutiny into potential criminal liability. If regulators can pursue firms across borders, what protection remains for people whose faces sit in scraped databases?

Analyst 207
NHS Exclusive: Critical PCs Blocked from Windows 11 Rollout

NHS Exclusive: Critical PCs Blocked from Windows 11 Rollout

A handful of suppliers refusing to sign off on Windows 11 compatibility are forcing NHS trusts to pause upgrades—pitting vital clinical continuity against security and compliance and leaving staff to decide which devices come first.

Analyst 207
CISA Exclusive: Critical VMware Zero-Day in Active Attacks

CISA Exclusive: Critical VMware Zero-Day in Active Attacks

When a tool meant to simplify management becomes an intruder’s doorway, you need to act fast. CISA has added CVE-2025-41244 to its Known Exploited Vulnerabilities list after active attacks on VMware Tools and Aria Operations — patch or mitigate immediately.

Analyst 207
Broken crown lies on cracked asphalt with shattered glass and debris, laptop and smartphone nearby.

Elementor King Addons Exclusive Flaw Hits 10k Sites

A widespread flaw in Elementor King Addons has now affected over 10,000 sites. Find out what went wrong and the quick steps you can take right now to protect your site.

Analyst 207
Dark cityscape with ominous server room and silhouetted figures huddled around a laptop screen.

Threat Actors Utilize AdaptixC2: Exclusive Critical Attacks

It’s alarming: attackers are hijacking AdaptixC2—an emulation framework built for defenders—to run stealthy, hard-to-disrupt ransomware campaigns, forcing security teams to rethink the tools they once trusted.

Analyst 207
Invisible npm malware: Exclusive, Dangerous Token Theft

Invisible npm malware: Exclusive, Dangerous Token Theft

PhantomRaven quietly slipped into the npm registry, turning routine installs into token theft by harvesting credentials during install and letting attackers publish malicious updates without touching your code. One stolen token can cascade through thousands of projects—here’s why supply‑chain hygiene and MFA matter now.

Analyst 207
Shadow AI: Stunning Risk as 1 in 4 Use Unapproved Tools

Shadow AI: Stunning Risk as 1 in 4 Use Unapproved Tools

What if a quarter of your team were quietly sharing company secrets with unapproved AI? Shadow AI—employees turning to consumer models to speed tasks—is convenient but can expose PII, IP and trigger costly compliance headaches.

Analyst 207
Proton Exclusive: Alarming 300M Records Compromised

Proton Exclusive: Alarming 300M Records Compromised

More than 300 million records have surfaced on the dark web — a startling tally that often mixes new leaks, resurfaced data and partial overlaps. Here’s what that number really means for your emails, passwords and IDs, and the simple steps you can take right now to protect yourself.

Analyst 207
Postcode Lottery Exclusive: Damaging Data Slip

Postcode Lottery Exclusive: Damaging Data Slip

People’s Postcode Lottery says a “technical error” briefly exposed some customer data and has since fixed the fault. But with no clear details on what leaked, how many were affected, or what protections are being offered, customers are understandably left wondering who will cover the fallout.

Analyst 207
Defense Contractor Guilty in Stunning Costly Zero-Day Sale

Defense Contractor Guilty in Stunning Costly Zero-Day Sale

What happens when the person entrusted to build the locks quietly sells the keys? An indictment alleges a former Trenchant manager sold zero‑day exploits and offensive cyber tools to a Russian broker for about $1.3 million, potentially turning U.S. capabilities into weapons against American systems and allies.

Analyst 207
Cracked smartphone screen with shattered lock and cityscape background, symbolizing security breach and vulnerability.

Chromium Critical Flaw: Exclusive Unpatched Alert

An unpatched Chromium flaw in the Blink rendering engine can crash browsers — and even freeze whole machines — in seconds, creating a real operational and security risk. If you manage desktops, kiosks or enterprise systems, this is one bug you need to take seriously now.

Analyst 207
Chrome Mandates HTTPS in 2026: Exclusive Best Practices

Chrome Mandates HTTPS in 2026: Exclusive Best Practices

Big news: in October 2026 Chrome 154 will default to HTTPS-only connections and refuse to load plain HTTP, risking instant traffic loss for sites that dont upgrade. Our exclusive best practices show how to implement TLS quickly, prevent downtime, and keep your users safe.

Analyst 207