Tag: emerging threats
4760 articles

Scammers Exploit Shop App to Fuel Callback Phishing Attacks
Beware of scammers exploiting the popular Shop app, with 50 million downloads, to trick you into callback phishing attacks with fake purchase receipts and phony support agents. They're impersonating big brands like Norton and Apple to steal your account credentials and sensitive info.

Microsoft Extends Free Windows 10 Security Updates to 2027
Microsoft just gave you an extra year of protection: the free Windows 10 Extended Security Updates program for personal devices now runs through October 12, 2027. That's a welcome extension of security updates for your Windows 10 device, giving you more time to consider your next move.

Loitering Munitions Converge on Long-Range Strike Designs
Loitering munitions have revolutionized long-range strikes, as seen in Ukraine's recent launch of hundreds of LMs at multiple regions, including a daring attack on Russia's Gazprom Neft Moscow Oil Refinery, just 14 km from the Kremlin. This new class of munitions has eliminated the need for high-cost platforms, allowing for more flexible and affordable precision strikes.

Pentagon seeks $5B to overhaul 'deteriorating' research labs
The Pentagon's research labs are in a state of disrepair, posing safety risks and technical limitations that threaten the US military's ability to stay ahead of the curve. A recent review led by Assistant Secretary for Science & Technology Joseph Jewell calls for a $5B overhaul to modernize these critical facilities.

Pakistan Accelerates Low-Cost Cruise Missile Development
Pakistan is shaking up the game with its low-cost cruise missile development, focusing on a key factor that sets its missiles apart: a powerful warhead and manageable weight. This strategic approach allows for a heavier payload and sustained range, making it a contender in the global shift towards affordable, mass-producible cruise technology.

Perimeter Devices Exposed as Vulnerability in Authentication Bypass Attacks
A recent emergency directive from CISA revealed a shocking vulnerability in Check Point Remote Access VPN, allowing attackers to bypass authentication and gain trusted user access since early May. This critical flaw, with a CVSS score of 9.3, enables remote attackers to establish a fully authenticated VPN session without a valid password, essentially turning a security gateway into an entry point for intruders.

UK Tests Low-Cost Deep-Strike Weapons for Ukraine
The UK has successfully tested three low-cost, long-range strike weapons designed to give Ukraine a powerful defense boost, with the goal of delivering a cheap and effective deep-strike capability. These British-made weapons can fly over 500 km and pack a 225 kg punch, all at an affordable price tag of around £400,000 each.

Minnesota Hacker 'Snoopy' Sentenced for DraftKings Breach Role
A 21-year-old Minnesota hacker known as "Snoopy" has been sentenced to 18 months in prison for his role in a massive credential stuffing attack that compromised nearly 60,000 DraftKings user accounts. He'll also serve three years of supervised release, pay over $1.3 million in restitution, and forfeit $463,000.

Researchers Expose LLM Vulnerability to Prompt Injection Attacks
Researchers have made a startling discovery about the vulnerability of Large Language Models (LLMs) to prompt injection attacks, tracing it back to a simple yet flawed design element - role tags that were meant to be a formatting trick but have become the model's de facto security architecture. This role confusion is the surprising reason why LLMs are susceptible to these types of attacks.

Cellebrite Tool Exploited by Russia to Infiltrate Activist's Phone
Russian authorities exploited a loophole in Cellebrite's UFED tool, using it to extract data from activist Andrey Pivovarov's phone, even after the device was no longer receiving updates. This security gap allowed the authorities to access the phone's data as far back as June 2021.

Kendall Warns of Lethal Autonomy Control Challenges
The challenge with lethal autonomy control is that it's incredibly hard to define - and therefore regulate - because its core capabilities exist on a spectrum with no clear boundaries. This makes it nearly impossible to draw a line between acceptable and banned systems, leaving us with a daunting question: how can we create an effective arms control regime?

Judge Strikes Down Trump's Election-Focused Executive Order
In a major blow to Trump's agenda, a federal judge has ruled that the President has no constitutional power over elections, striking down key sections of an executive order aimed at reshaping ballot and voter list management. The decision declares that presidential actions are not above review, and that the administration cannot dictate how states manage their elections.

Army Tests AI Limits in Tactical Planning, Finds Mixed Results
The US Army's 3rd Mobile Brigade Combat Team experimented with AI in tactical planning for a year, with Col. Ryan Bell revealing that while AI showed promise, it had limitations - particularly with large language models struggling to grasp three-dimensional space. By training AI on military doctrine, the team aimed to speed up planning and response times.

US Defense Base Exposes Strategic Vulnerability
With US President Donald Trump invoking the Defense Production Act, the Department of Defense can now collaborate with private providers to speed up supply chains and address critical bottlenecks. This move comes as global alliances shift, with North Korea's recent endorsement of China's "One China" principle raising questions about the region's future dynamics.

macOS Malware Embeds Fake Errors to Evade AI Analysis
Meet macOS.Gaslight, a sneaky new malware family from a North Korean-linked threat actor that's got a clever trick up its sleeve - embedding 38 fake system messages to throw off AI analysis tools. This tiny 3.5 KB payload is packed with deception, making it a formidable foe for cybersecurity experts.

Healthcare Sector Braces for Looming Cyberattack Threats
With AI now a staple in 93% of healthcare practices, the stage is set for a new wave of technological advancements - but also for looming cyberattack threats that have 61% of organizations bracing for a potentially fatal impact within the next five years.

Iranian Hackers Exploit Credentials in Cal Water Breach
Cal Water swiftly sprang into action when an Iranian-linked group, Handala, claimed to have hacked their system, activating their cybersecurity response plan and launching a thorough investigation. Thankfully, experts from Mandiant found that the breach was limited to third-party accounts, containing no evidence of a larger-scale attack.

Authorities Disrupt PirloTV Sports Piracy Network, Seize 44 Domains
In a major blow to sports piracy, authorities have shut down PirloTV, a notorious network that illegally streamed live sports to over 950 million visitors worldwide each year. The operation, involving UEFA, UC3, and Mexican authorities, seized 44 domains used to distribute unauthorized streams.

Bluekit Phishing Kit Enhances Login Theft with Browser-in-the-Middle Tactics
Bluekit's phishing kit just got a sinister upgrade, now using browser-in-the-middle tactics to steal logins in real-time. This move has led to a massive expansion of its infrastructure, with nearly 70 new hostnames appearing in just one week.

Google Warns of Cisco Vulnerability Exploited as Zero-Day Months Before Disclosure
Google sounded the alarm on a Cisco vulnerability that was exploited as a zero-day months before its disclosure, putting users of Cisco Catalyst SD-WAN products on high alert. This critical flaw, tracked as CVE-2026-20245, allows authenticated local attackers to wreak havoc due to insufficient validation of user input in the command-line interface.

Popular Chrome Ad Blocker Exposes Script Injection Risk
A popular Chrome ad blocker with over 10 million installs, Adblock for YouTube, has been found to have a shocking vulnerability that could allow hackers to inject malicious JavaScript into any website, all with just a single server-side tweak. This means users could be exposed to serious security risks without even realizing anything has changed.

Fraud Prevention Strategies Target Multiple Elevation Levels
Fraudsters are constantly evolving, and a single-layer defense just won't cut it - that's why IPQS advocates for a layered approach to fraud prevention, because what may seem like a secure transaction to you might be just the tip of the iceberg to a sophisticated scammer. By monitoring at multiple levels, you can stay one step ahead of even the most cunning attackers.

Smart TVs Compromised by Proxyware Vulnerabilities Plague 24-Year-Old Curl AI Emerges in Cybercrime Forums Hackers Exploit Microsoft Teams Legacy Credentials Fuel Data Breaches
Over a third of smart TV apps, including clocks, screensavers, and games, contain residential proxy software, putting your device at risk. Researchers found that 42.5% of LG webOS and 26.9% of Samsung Tizen apps harbour these vulnerabilities.
