Skip to main content

Tag: emerging threats

4760 articles

Person looks concerned while checking phone in cluttered living room with open laptop and shopping boxes nearby.

Scammers Exploit Shop App to Fuel Callback Phishing Attacks

Beware of scammers exploiting the popular Shop app, with 50 million downloads, to trick you into callback phishing attacks with fake purchase receipts and phony support agents. They're impersonating big brands like Norton and Apple to steal your account credentials and sensitive info.

Analyst 207
Windows 10 laptop on a desk with a blurred screen and a calendar showing a date in 2027.

Microsoft Extends Free Windows 10 Security Updates to 2027

Microsoft just gave you an extra year of protection: the free Windows 10 Extended Security Updates program for personal devices now runs through October 12, 2027. That's a welcome extension of security updates for your Windows 10 device, giving you more time to consider your next move.

Analyst 207
Drones fly over a large industrial refinery with smokestacks and storage tanks.

Loitering Munitions Converge on Long-Range Strike Designs

Loitering munitions have revolutionized long-range strikes, as seen in Ukraine's recent launch of hundreds of LMs at multiple regions, including a daring attack on Russia's Gazprom Neft Moscow Oil Refinery, just 14 km from the Kremlin. This new class of munitions has eliminated the need for high-cost platforms, allowing for more flexible and affordable precision strikes.

Analyst 207
Worn laboratory interior with outdated equipment and scientists working in background.

Pentagon seeks $5B to overhaul 'deteriorating' research labs

The Pentagon's research labs are in a state of disrepair, posing safety risks and technical limitations that threaten the US military's ability to stay ahead of the curve. A recent review led by Assistant Secretary for Science & Technology Joseph Jewell calls for a $5B overhaul to modernize these critical facilities.

Analyst 207
Low-cost cruise missile displayed on a metal surface with neutral background.

Pakistan Accelerates Low-Cost Cruise Missile Development

Pakistan is shaking up the game with its low-cost cruise missile development, focusing on a key factor that sets its missiles apart: a powerful warhead and manageable weight. This strategic approach allows for a heavier payload and sustained range, making it a contender in the global shift towards affordable, mass-producible cruise technology.

Analyst 207
A generic VPN gateway device sits on a rack in a brightly-lit data center.

Perimeter Devices Exposed as Vulnerability in Authentication Bypass Attacks

A recent emergency directive from CISA revealed a shocking vulnerability in Check Point Remote Access VPN, allowing attackers to bypass authentication and gain trusted user access since early May. This critical flaw, with a CVSS score of 9.3, enables remote attackers to establish a fully authenticated VPN session without a valid password, essentially turning a security gateway into an entry point for intruders.

Analyst 207
Long-range missile on a launchpad against a daylight coastal landscape.

UK Tests Low-Cost Deep-Strike Weapons for Ukraine

The UK has successfully tested three low-cost, long-range strike weapons designed to give Ukraine a powerful defense boost, with the goal of delivering a cheap and effective deep-strike capability. These British-made weapons can fly over 500 km and pack a 225 kg punch, all at an affordable price tag of around £400,000 each.

Analyst 207
Young man with somber expression sits in federal courtroom surrounded by institutional architecture.

Minnesota Hacker 'Snoopy' Sentenced for DraftKings Breach Role

A 21-year-old Minnesota hacker known as "Snoopy" has been sentenced to 18 months in prison for his role in a massive credential stuffing attack that compromised nearly 60,000 DraftKings user accounts. He'll also serve three years of supervised release, pay over $1.3 million in restitution, and forfeit $463,000.

Analyst 207
Naval personnel surround unmanned vehicles on a Hawaiian pier with ships in the background under a clear blue sky.

RIMPAC Launches with Emphasis on Unmanned Systems Experimentation

Analyst 207
Researchers examine code and data visualizations on a computer screen in a bright, minimalist lab setting.

Researchers Expose LLM Vulnerability to Prompt Injection Attacks

Researchers have made a startling discovery about the vulnerability of Large Language Models (LLMs) to prompt injection attacks, tracing it back to a simple yet flawed design element - role tags that were meant to be a formatting trick but have become the model's de facto security architecture. This role confusion is the surprising reason why LLMs are susceptible to these types of attacks.

Analyst 207
Smartphone on a plain surface in a Russian government building with a blurred historic background and forensic tools nearby.

Cellebrite Tool Exploited by Russia to Infiltrate Activist's Phone

Russian authorities exploited a loophole in Cellebrite's UFED tool, using it to extract data from activist Andrey Pivovarov's phone, even after the device was no longer receiving updates. This security gap allowed the authorities to access the phone's data as far back as June 2021.

Analyst 207
Frank Kendall sits contemplatively in a formal setting, looking down.

Kendall Warns of Lethal Autonomy Control Challenges

The challenge with lethal autonomy control is that it's incredibly hard to define - and therefore regulate - because its core capabilities exist on a spectrum with no clear boundaries. This makes it nearly impossible to draw a line between acceptable and banned systems, leaving us with a daunting question: how can we create an effective arms control regime?

Analyst 207
Judge Strikes Down Trump's Election-Focused Executive Order

Judge Strikes Down Trump's Election-Focused Executive Order

In a major blow to Trump's agenda, a federal judge has ruled that the President has no constitutional power over elections, striking down key sections of an executive order aimed at reshaping ballot and voter list management. The decision declares that presidential actions are not above review, and that the administration cannot dictate how states manage their elections.

Analyst 207
Army Tests AI Limits in Tactical Planning, Finds Mixed Results

Army Tests AI Limits in Tactical Planning, Finds Mixed Results

The US Army's 3rd Mobile Brigade Combat Team experimented with AI in tactical planning for a year, with Col. Ryan Bell revealing that while AI showed promise, it had limitations - particularly with large language models struggling to grasp three-dimensional space. By training AI on military doctrine, the team aimed to speed up planning and response times.

Analyst 207
US Defense Base Exposes Strategic Vulnerability

US Defense Base Exposes Strategic Vulnerability

With US President Donald Trump invoking the Defense Production Act, the Department of Defense can now collaborate with private providers to speed up supply chains and address critical bottlenecks. This move comes as global alliances shift, with North Korea's recent endorsement of China's "One China" principle raising questions about the region's future dynamics.

Analyst 207
macOS computer screen with error message box on a cluttered desktop surrounded by icons and folders on a clean desk.

macOS Malware Embeds Fake Errors to Evade AI Analysis

Meet macOS.Gaslight, a sneaky new malware family from a North Korean-linked threat actor that's got a clever trick up its sleeve - embedding 38 fake system messages to throw off AI analysis tools. This tiny 3.5 KB payload is packed with deception, making it a formidable foe for cybersecurity experts.

Analyst 207
Hospital corridor with healthcare professionals, laptop on workstation, and patient room door in background.

Healthcare Sector Braces for Looming Cyberattack Threats

With AI now a staple in 93% of healthcare practices, the stage is set for a new wave of technological advancements - but also for looming cyberattack threats that have 61% of organizations bracing for a potentially fatal impact within the next five years.

Analyst 207
Water utility company's outdoor infrastructure with personnel and subtle computer systems.

Iranian Hackers Exploit Credentials in Cal Water Breach

Cal Water swiftly sprang into action when an Iranian-linked group, Handala, claimed to have hacked their system, activating their cybersecurity response plan and launching a thorough investigation. Thankfully, experts from Mandiant found that the breach was limited to third-party accounts, containing no evidence of a larger-scale attack.

Analyst 207
Law enforcement officials gather around a large screen displaying a world map during a briefing on a global sports piracy…

Authorities Disrupt PirloTV Sports Piracy Network, Seize 44 Domains

In a major blow to sports piracy, authorities have shut down PirloTV, a notorious network that illegally streamed live sports to over 950 million visitors worldwide each year. The operation, involving UEFA, UC3, and Mexican authorities, seized 44 domains used to distribute unauthorized streams.

Analyst 207
Laptop on a table in a brightly-lit public area, suggesting internet access.

Bluekit Phishing Kit Enhances Login Theft with Browser-in-the-Middle Tactics

Bluekit's phishing kit just got a sinister upgrade, now using browser-in-the-middle tactics to steal logins in real-time. This move has led to a massive expansion of its infrastructure, with nearly 70 new hostnames appearing in just one week.

Analyst 207
Technicians work in a brightly-lit network operations room with a Cisco device on a rack surrounded by generic networking…

Google Warns of Cisco Vulnerability Exploited as Zero-Day Months Before Disclosure

Google sounded the alarm on a Cisco vulnerability that was exploited as a zero-day months before its disclosure, putting users of Cisco Catalyst SD-WAN products on high alert. This critical flaw, tracked as CVE-2026-20245, allows authenticated local attackers to wreak havoc due to insufficient validation of user input in the command-line interface.

Analyst 207
Google Chrome browser window on laptop with YouTube open, surrounded by home office setting.

Popular Chrome Ad Blocker Exposes Script Injection Risk

A popular Chrome ad blocker with over 10 million installs, Adblock for YouTube, has been found to have a shocking vulnerability that could allow hackers to inject malicious JavaScript into any website, all with just a single server-side tweak. This means users could be exposed to serious security risks without even realizing anything has changed.

Analyst 207
Multi-layered city infrastructure with payment terminal in foreground.

Fraud Prevention Strategies Target Multiple Elevation Levels

Fraudsters are constantly evolving, and a single-layer defense just won't cut it - that's why IPQS advocates for a layered approach to fraud prevention, because what may seem like a secure transaction to you might be just the tip of the iceberg to a sophisticated scammer. By monitoring at multiple levels, you can stay one step ahead of even the most cunning attackers.

Analyst 207
Smart TV on an entertainment center in a living room with ambient daylight and low-utility apps on the screen.

Smart TVs Compromised by Proxyware Vulnerabilities Plague 24-Year-Old Curl AI Emerges in Cybercrime Forums Hackers Exploit Microsoft Teams Legacy Credentials Fuel Data Breaches

Over a third of smart TV apps, including clocks, screensavers, and games, contain residential proxy software, putting your device at risk. Researchers found that 42.5% of LG webOS and 26.9% of Samsung Tizen apps harbour these vulnerabilities.

Analyst 207