Tag: emerging threats
4746 articles

Cyberattacks on SMBs Surge via AI Tool Lures
Small and medium-sized businesses are under siege, with a staggering 33,352 cyberattacks detected in just four months as scammers disguise malware as popular AI tools. This alarming surge highlights how quickly cybercriminals are leveraging the latest tech trends to target vulnerable businesses.

Chinese Hackers Target Southeast Asia's Energy, Government Sectors
Chinese hackers have launched a stealthy assault on Southeast Asia's energy and government sectors, infiltrating at least ten organizations between October and December 2025. This sophisticated threat, tracked as CL-STA-1062, has been lurking in the shadows since March 2022, using clever tactics like hard-coded encryption keys to evade detection.

Iran Strikes Cargo Vessel, Halts Strait of Hormuz Evacuation Plan
The International Maritime Organization has hit the pause button on an evacuation plan for hundreds of vessels in the Persian Gulf after a cargo ship was struck in the Strait of Hormuz, citing safety concerns. The move aims to ensure that necessary safety guarantees remain in place for ships in the region.

FCC Tightens Cybersecurity Rules for Emergency Alert Systems, Undersea Cables
The FCC has just tightened cybersecurity rules for emergency alert systems and undersea cables to prevent vulnerabilities that could be exploited by rogue actors, foreign governments, or cybercriminals to spread chaos and misinformation. This move aims to safeguard the nation's primary public-warning platforms, including the Emergency Alert System and Wireless Emergency Alerts.

Securing Agentic AI Workspaces Requires Unified Governance
Nine out of 10 organisations are already harnessing AI assistants, but many are flying blind - unsure if these powerful tools have been compromised. As AI agents assume their own identities and access rights, a misconfigured or compromised agent can quickly become a high-speed pathway for data breaches and credential abuse.

China's Space Debris Surge Threatens Low Earth Orbit Satellites
China's recent surge in space debris is alarming, with a staggering 51 spent rocket bodies abandoned in low Earth orbit (LEO) above 650 kilometers in just four years - a rate that's more than double the country's total from the previous five years. This reckless pace is cluttering LEO with long-lived debris, posing a significant threat to the growing number of satellites in this critical orbit.

Qihoo 360 Unveils AI Bug-Finder to Rival Anthropic's Mythos
Qihoo 360 CEO Zhou Hongyi has unveiled an AI bug-finder, positioning it as a powerful countermeasure to restricted Western tools, likening Anthropic's Mythos to a "cyber nuclear weapon". This new Chinese innovation aims to level the playing field in cybersecurity.

Mistic Backdoor Exposes Link to Corporate Network Access Broker
Meet Mistic, a sneaky new backdoor that allows attackers to secretly access and control corporate networks for months on end, all while erasing its digital tracks. This stealthy threat can execute remote payloads in memory, upload and download files, and even self-destruct to avoid detection.

Poland Disrupts SIM-Swapping Gang Linked to Crypto Heists
In a major breakthrough, Polish authorities have dismantled a notorious SIM-swapping gang that used social engineering and specialized software to orchestrate a string of crypto heists, with four suspects now facing charges. The successful takedown was made possible through a collaborative effort with the FBI and Homeland Security Investigations.

Huntress Insider Leak Exposes Potential Security Breach
A shocking security breach at Huntress has come to light, with a former analyst claiming that a colleague may have compromised the company's integrity by passing sensitive law enforcement communications to a notorious cybercriminal. The explosive allegations have left many questions unanswered about the breach and its potential impact.

Scammers Exploit Shop App to Fuel Callback Phishing Attacks
Beware of scammers exploiting the popular Shop app, with 50 million downloads, to trick you into callback phishing attacks with fake purchase receipts and phony support agents. They're impersonating big brands like Norton and Apple to steal your account credentials and sensitive info.

Microsoft Extends Free Windows 10 Security Updates to 2027
Microsoft just gave you an extra year of protection: the free Windows 10 Extended Security Updates program for personal devices now runs through October 12, 2027. That's a welcome extension of security updates for your Windows 10 device, giving you more time to consider your next move.

Loitering Munitions Converge on Long-Range Strike Designs
Loitering munitions have revolutionized long-range strikes, as seen in Ukraine's recent launch of hundreds of LMs at multiple regions, including a daring attack on Russia's Gazprom Neft Moscow Oil Refinery, just 14 km from the Kremlin. This new class of munitions has eliminated the need for high-cost platforms, allowing for more flexible and affordable precision strikes.

Pentagon seeks $5B to overhaul 'deteriorating' research labs
The Pentagon's research labs are in a state of disrepair, posing safety risks and technical limitations that threaten the US military's ability to stay ahead of the curve. A recent review led by Assistant Secretary for Science & Technology Joseph Jewell calls for a $5B overhaul to modernize these critical facilities.

Pakistan Accelerates Low-Cost Cruise Missile Development
Pakistan is shaking up the game with its low-cost cruise missile development, focusing on a key factor that sets its missiles apart: a powerful warhead and manageable weight. This strategic approach allows for a heavier payload and sustained range, making it a contender in the global shift towards affordable, mass-producible cruise technology.

Perimeter Devices Exposed as Vulnerability in Authentication Bypass Attacks
A recent emergency directive from CISA revealed a shocking vulnerability in Check Point Remote Access VPN, allowing attackers to bypass authentication and gain trusted user access since early May. This critical flaw, with a CVSS score of 9.3, enables remote attackers to establish a fully authenticated VPN session without a valid password, essentially turning a security gateway into an entry point for intruders.

UK Tests Low-Cost Deep-Strike Weapons for Ukraine
The UK has successfully tested three low-cost, long-range strike weapons designed to give Ukraine a powerful defense boost, with the goal of delivering a cheap and effective deep-strike capability. These British-made weapons can fly over 500 km and pack a 225 kg punch, all at an affordable price tag of around £400,000 each.

Minnesota Hacker 'Snoopy' Sentenced for DraftKings Breach Role
A 21-year-old Minnesota hacker known as "Snoopy" has been sentenced to 18 months in prison for his role in a massive credential stuffing attack that compromised nearly 60,000 DraftKings user accounts. He'll also serve three years of supervised release, pay over $1.3 million in restitution, and forfeit $463,000.

Researchers Expose LLM Vulnerability to Prompt Injection Attacks
Researchers have made a startling discovery about the vulnerability of Large Language Models (LLMs) to prompt injection attacks, tracing it back to a simple yet flawed design element - role tags that were meant to be a formatting trick but have become the model's de facto security architecture. This role confusion is the surprising reason why LLMs are susceptible to these types of attacks.

Cellebrite Tool Exploited by Russia to Infiltrate Activist's Phone
Russian authorities exploited a loophole in Cellebrite's UFED tool, using it to extract data from activist Andrey Pivovarov's phone, even after the device was no longer receiving updates. This security gap allowed the authorities to access the phone's data as far back as June 2021.

Kendall Warns of Lethal Autonomy Control Challenges
The challenge with lethal autonomy control is that it's incredibly hard to define - and therefore regulate - because its core capabilities exist on a spectrum with no clear boundaries. This makes it nearly impossible to draw a line between acceptable and banned systems, leaving us with a daunting question: how can we create an effective arms control regime?

Judge Strikes Down Trump's Election-Focused Executive Order
In a major blow to Trump's agenda, a federal judge has ruled that the President has no constitutional power over elections, striking down key sections of an executive order aimed at reshaping ballot and voter list management. The decision declares that presidential actions are not above review, and that the administration cannot dictate how states manage their elections.

Army Tests AI Limits in Tactical Planning, Finds Mixed Results
The US Army's 3rd Mobile Brigade Combat Team experimented with AI in tactical planning for a year, with Col. Ryan Bell revealing that while AI showed promise, it had limitations - particularly with large language models struggling to grasp three-dimensional space. By training AI on military doctrine, the team aimed to speed up planning and response times.
