Tag: emerging threats
4722 articles

Adobe ColdFusion Flaw Exploited in Ongoing Attacks
A critical Adobe ColdFusion vulnerability, CVE-2026-48282, is under attack - and it's crucial to patch now to prevent remote code execution on your system. This maximum-severity flaw affects ColdFusion releases 2025.9, 2023.20, and earlier, and can be exploited without privileges.

Google Disrupts NetNut Residential Proxy Botnet
Google teamed up with the FBI, Lumen, and other partners to take down the NetNut residential proxy network, disabling key Google accounts and services used by the threat actors to control malware. This move helps keep everyday devices and systems safe from being exploited as footholds for attacks.

Sainsbury's Expands Facial Recognition to Combat Shoplifting
Sainsbury's is taking a bold stance against shoplifting by expanding its facial recognition technology to nearly 200 stores by 2026, but is this move a step too far for customer privacy? The supermarket giant's system has already shown promising results, with 90 percent of identified individuals choosing not to return.

China-nexus Hackers Deploy DcRAT via Fake Indian Tax Utility
Cyber attackers with ties to China are pulling out all the stops to scam Indian taxpayers, using a sophisticated fake tax utility to deploy malware and pilfer sensitive info. Their precision-crafted phishing campaign, dubbed Operation DragonReturn, sends convincing emails and PDFs that even cite real laws to trick victims.

AI SOC Platforms Face Test of Predictive Power
Meet Mike Shannon, Guardant Health's Director of Security Engineering, who's ditched manual queries for Exabot - a game-changing AI solution that's revolutionizing the way security teams operate. By harnessing the power of AI SOC platforms, organizations can now automate core security tasks, freeing up teams to focus on high-stakes threats.

ShinyHunters Breach Exposes 2.3M Moody Bible Institute Accounts
A massive data breach at Moody Bible Institute has exposed the sensitive information of over 2.3 million people, including names, addresses, phone numbers, and more, after being targeted by the notorious extortion group ShinyHunters. The stolen data, which was leaked on June 23, puts countless individuals at risk of identity theft and cyber attacks.

Sysdig Exposes First Fully Agentic Ransomware Campaign
Meet JadePuffer, the groundbreaking ransomware campaign that's fully driven by a large language model (LLM) and can launch a devastating attack in as little as 31 seconds. This AI-powered threat uses an adaptive and automated approach to exploit vulnerabilities and extort its targets.

QuimaRAT Exposes Cross-Platform Threat Capabilities
Meet QuimaRAT, a commercialized remote access trojan package that's being sold as a malware-as-a-service, threatening security across multiple platforms with its flexible subscription tiers. This Java-based tool is marketed for a surprisingly low price, ranging from $150 for a month to $1,200 for lifetime access.

TrojPix Exploits Video Cables to Leak Air-Gapped Data
Meet TrojPix, a sneaky technique that can stealthily siphon air-gapped data at lightning-fast speeds of up to 1 megabyte per second - fast enough to exfiltrate a 100MB file in under two minutes while the monitor appears dark and inactive.

NCA Warns Parents of AI Exploitation of Shared Child Photos
As a parent, sharing photos of your child online can be a minefield - with AI technology now being used to create and spread disturbing child abuse content at an alarming rate, with a 26,000% annual increase in AI-generated videos reported in just one year.

Opera GX Flaw Enables Silent Mod Installs to Steal User Data
Researchers have discovered a security flaw in Opera GX that allows for silent mod installs, potentially putting user data at risk, and surprisingly, this vulnerability can be exploited with just a single page visit. This alarming issue enables malicious mods to be installed without user consent, highlighting a concerning gap in the browser's security.

Malicious AI Skills Evade Scanners With Self-Extracting Packing
Researchers have developed a sneaky tool called SKILLCLOAK that can disguise malicious AI skills, making them slip past scanners undetected more than 90% of the time. This unsettling breakthrough challenges the reliability of static AI skill reviews, leaving a gaping hole in security defenses.

KMT Budget Cuts Stifle Taiwan's Drone Defense Push
Taiwan's bid to bolster its drone defense has hit a roadblock after the Kuomintang-led legislature slashed a special military budget from $40 billion to $25 billion, stripping out crucial domestic programs and a plan for 200,000 small drones. This cut threatens to leave Taiwan vulnerable, undermining its goal of becoming a formidable "hedgehog" that can defend itself against threats.

White House Escalates Iran War Spending with $87.6 Billion Supplemental Request
The White House is ramping up its Iran war spending with a staggering $87.6 billion supplemental request, with a whopping $21 billion dedicated to restocking depleted munitions. This massive allocation is part of a broader effort to fuel the war effort, with $67.1 billion going directly to the Pentagon.

Banks Expose Accounts to Thieves by Making MFA Optional
Leaving multi-factor authentication optional has left countless bank accounts vulnerable to theft, with devastating consequences - just ask the 84-year-old victim who lost nearly $30,000 when thieves exploited this security gap. By making MFA optional, banks are inadvertently rolling out the red carpet for thieves.

China Revives Soviet-Era Anti-Aircraft Gun in Drone Defense Debate
China is considering reviving a Soviet-era anti-aircraft gun, the 57mm PG59, to defend against drone attacks - a low-cost solution that could provide crucial protection for logistics nodes. By bolting on a modern fire-control system, this old-school gun could get a high-tech makeover and a second life as a point-defense weapon.

Ransomware Operation Exploits AI to Automate Cyberattack
Meet JadePuffer, a notorious ransomware operation that's taking cyberattacks to the next level with the power of AI, automating attacks with ease. In a shocking example, JadePuffer used a large language model agent to encrypt a staggering 1,342 Nacos service configuration items.

US Government Entity Pays $1 Million to Thwart Data Leak
A US government entity was forced to pay a hefty $1 million ransom to prevent a massive data leak, after a group called Kairos threatened to release 1.6 million files unless their demand was met. The payment was the culmination of a month-long negotiation that began with a $3 million opening demand.

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign
North Korean hackers have unleashed a massive wave of malware, publishing 108 malicious packages and web browser extensions across popular platforms like npm, Packagist, Go, and Google Chrome as part of their sneaky PolinRider campaign. This ongoing operation has already produced 162 malicious release artifacts and compromised thousands of systems worldwide.

Confidential Computing Flaws Expose Trust Risks
Researchers have uncovered alarming flaws in confidential computing, including a high-severity vulnerability rated 7.5, which can trick cryptographic systems into verifying the wrong machine, putting trust at risk. This weakness was found in protocols like attested TLS, which failed to ensure sensitive data reaches its intended destination.

Baykar's KIZILELMA Conducts First Fully Indigenous Guidance Test with ASELSAN's TOYGUN
Baykar's KIZILELMA drone has successfully completed its first fully indigenous guidance test, using ASELSAN's TOYGUN system to locate and strike a ground target with precision-guided bombs. This milestone achievement marks a major breakthrough in Türkiye's drone technology, showcasing the power of domestic innovation.

India Bolsters Air Defence with ₹52,000 Crore Arms Clearance Focused on Counter-Drone Tech
India is set to significantly boost its air defence capabilities with a ₹52,000 crore arms deal focused on cutting-edge counter-drone technology and layered air defence systems, following a key approval from the Defence Acquisition Council. This major move is aimed at strengthening the Army, Navy, and Air Force with advanced defence solutions.

Ukraine Targets Russian Air Base in Crimea with Drone Strikes
Ukraine just landed a major blow to Russia's military capabilities with a daring drone strike on the Saki Air Base in Crimea, taking out multiple hangars and at least seven aircraft, including Su-30SM, Su-30, and Su-24 fighter jets and bombers. The bold operation, claimed by the Ukrainian Security Service, dealt a significant hit to Russia's aviation assets.

Flock Cameras Enable Surveillance of Vehicles Without License Plates
Flock Cameras are revolutionizing vehicle surveillance by enabling law enforcement to track vehicles even without license plates. With Flock's innovative Vehicle Fingerprint technology, officers can gather crucial details like decals, bumper stickers, and temporary state tags to build a case.