Tag: emerging threats
4717 articles

Poland to Mass-Produce Low-Cost Barracuda Cruise Missiles
Poland is set to start mass-producing the game-changing Barracuda cruise missiles, a precise, affordable, and electronic warfare-resistant defense system, in partnership with Anduril Industries. This breakthrough move comes after a memorandum was successfully converted into a production program, paving the way for thousands of missiles to bolster the Polish Armed Forces.

Writer AI Flaw Exposes Session Tokens Across Tenants
A critical flaw in Writer AI, dubbed WriteOut, could let an outsider hijack any account and take over an entire organization with just a single link - no login credentials required. This shocking vulnerability highlights the urgent need for robust security measures in AI-powered platforms.

China-Aligned Hackers Exploit Roundcube Flaws to Infiltrate Universities
China-aligned hackers have launched a sneaky attack on universities, exploiting two flaws in the popular Roundcube webmail client to steal credentials and gain persistent access. At least a few dozen universities are believed to be affected, with Proofpoint researchers confirming fewer than 10 intrusions so far.

FBI Traces Scattered Spider Hacker via Persistent Windows Device ID
In a brazen ransom email, the attackers boldly declared, "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY," leaving no doubt about their malicious intentions. The hackers infiltrated the retailer's network through a clever help-desk ploy, tricking staff into resetting passwords and gaining control of critical accounts.

China Unveils JL-3 Submarine-Launched Ballistic Missile
China has just revealed its latest game-changer: the JL-3, or 'Giant Wave 3', a third-generation intercontinental-range submarine-launched ballistic missile that's set to take the country's military capabilities to new depths.

GitHub Actions Expose Vulnerability in CI/CD Pipelines
A single misstep in a GitHub Actions workflow can become a four-step chain to permanent credential exposure, putting your entire CI/CD pipeline at risk. Researchers have uncovered a class of vulnerabilities, dubbed Cordyceps, that can be exploited in a surprisingly simple way.

Google Sues Chinese Scammers Over Gemini AI Misuse
Google is taking a stand against scammers, suing a group called Outsider Enterprise that uses its Gemini AI feature to create fake websites and scam people through text messages. The group, which operates on Telegram, offers phishing-as-a-service, making it easy for non-tech-savvy scammers to target victims.

Scattered Spider Morphs into Decentralized Cybercrime Network
Meet Scattered Spider, a notorious cybercrime collective that's evolved into a decentralized network of independent clusters, sharing tactics and tools to wreak havoc online. This fresh analysis by Group-IB shatters the traditional view of a single, unified gang, revealing a more complex and dynamic threat.

Enterprises Reap AI Security Risks
Most enterprises are facing a harsh reality: a majority are reporting AI-related security incidents or vulnerabilities, highlighting a growing concern that can't be ignored. This stark statistic sets the tone for a crucial conversation about the intersection of AI and security.

AI Reshapes Software Supply Chain Security Risks
The software supply chain security landscape has dramatically shifted in just 20 months, with AI tools and models now integral to building, deploying, and running software - and bringing new risks to the table. The old question of "what's in your code?" has given way to a more complex concern: what happens when AI coding assistants and autonomous agents start suggesting or producing code?

Linux Flaw Enables VM Escape on Intel, AMD Devices
A newly disclosed 16-year-old Linux kernel vulnerability, dubbed Januscape, allows hackers to easily escape virtual machines and compromise their host systems - all with just a few clicks from within the guest system. This shocking security flaw, tracked as CVE-2026-53359, has been lurking in the kernel for nearly two decades.

Spain Arrests Alleged Pro-Russia Hacktivist Tied to Cyber Attacks
Hacktivists aligned with Russia are wreaking havoc on UK organizations with denial-of-service attacks that may be simple, but have a significant impact by disrupting essential services. These attacks can overwhelm important websites and online systems, leaving people unable to access the services they rely on daily.

Microsoft Teams Users Targeted by Fake IT Support Scam
Beware of fake IT support scammers on Microsoft Teams who are tricking unsuspecting workers into installing malware by posing as tech support staff. These impostors are using the popular collaboration platform to deceive and compromise employee devices.

UK Government's Cyber Resilience Pledge Gains 60 Signatories
The UK government's Cyber Resilience Pledge has gained momentum with 60 signatories, demonstrating a united front against cyber threats. By signing the pledge, businesses acknowledge that cyber resilience is a top priority, not just an IT issue, but a business imperative.

China-Aligned Hackers Exploit Roundcube Flaws at Universities
China-aligned hackers are exploiting vulnerabilities in Roundcube email servers to gain access to sensitive university networks, specifically targeting physics and engineering departments with national security ties. They've cleverly designed their attacks to fly under the radar, using tactics like compromised senders and spoofed domains to reach their targets.

UK Government Unveils Cyber Resilience Pledge with Over 60 Signatories
Joining forces to combat cyber threats, the UK government has launched a groundbreaking Cyber Resilience Pledge, signed by over 60 organisations, to strengthen board-level accountability and supply chain security. By making three key commitments, signatories can bolster their defences and stay ahead of emerging threats.

BeyondTrust Software Flaws Expose Risk of Authentication Bypass
Critical software flaws in BeyondTrust's Remote Support and Privileged Remote Access products could allow hackers to bypass authentication and gain unauthorized access, potentially putting your system integrity at risk. Two vulnerabilities, CVE-2026-40138 and CVE-2026-40139, have been identified, highlighting the urgent need for an update.

Adobe ColdFusion Flaw Exploited in Targeted Attacks
With 775 exposed ColdFusion instances online, a newly patched flaw is being exploited by attackers, putting countless systems at risk. Adobe has urgently warned customers to apply updates immediately to protect against this and 10 other critical vulnerabilities.

Tenda Router Firmware Exposes Hidden Admin Backdoor
A critical vulnerability in Tenda router firmware, tracked as CVE-2026-11405, allows hackers to bypass password verification and gain full administrative control of your device. This hidden backdoor puts your online security at risk, and a patch is still pending.

Microsoft Tests Cloud Rebuild Feature to Streamline Windows 11 Recovery
Say goodbye to tedious reinstallation processes! Microsoft is testing a game-changing Cloud Rebuild feature in Windows 11, allowing users to restore their PC to a clean state with a simple, full OS reinstall - even if Windows won't boot.

BeyondTrust Fixes Auth Bypass Flaws in Remote Support Software
BeyondTrust has patched critical flaws in its Remote Support and Privileged Remote Access software that could let hackers take control of affected systems - but you can safeguard yours with a simple update to version 25.3.3 or higher.

China Conducts Pacific Test of Submarine-Launched Ballistic Missile
China's People's Liberation Army Navy successfully tested a submarine-launched ballistic missile in the Pacific Ocean on July 6, with the missile accurately landing in a predetermined sea area. The drill was part of routine annual military training, with relevant countries notified in advance, according to the PLAN.

Ukraine Faces Acute Shortage of Patriot Interceptors
Ukraine's capital was left vulnerable to a devastating Russian attack due to a critical shortage of Patriot interceptor missiles, which failed to shoot down a barrage of ballistic and hypersonic missiles that killed at least 20 people. The alarming gap in Ukraine's air defenses has raised urgent concerns about the country's ability to protect its citizens.

Democracies Need Critical-Minerals Stockpile Alignment
Democratic governments are taking a proactive approach to securing their critical mineral supplies, with Australia's recent announcement of a Critical Minerals Strategic Reserve being the latest example. This move is part of a growing trend to build resilience and reduce reliance on vulnerable supply chains dominated by a single country.