Tag: emerging threats
4835 articles

US Eyes Civilian Hackers to Bolster Cyber Operations
The US is considering a game-changing move: enlisting civilian hackers to help breach foreign computer systems, with a pilot program proposed in the Senate Armed Services Committee's defense policy bill. This bold plan would bring private sector expertise under the operational control of US Cyber Command.

Pentagon Orders Review of US Troop Posture in Europe
The Pentagon has ordered a comprehensive review of US troop deployments across Europe, sparking significant implications for the region. This pivotal move is dissected in The Break Out's latest episode, where experts Lee Ferran and Ashley Roque delve into the directive's details and potential impact.

Squidbleed Vulnerability Exposes Decade-Old Flaw in Popular Proxy Server
A 29-year-old memory leak in the popular Squid proxy server, dubbed Squidbleed, could silently expose sensitive data, including login credentials and session tokens, to hackers in certain setups. This shocking vulnerability, rooted in a 1997 code commit, highlights the importance of regularly updating and securing even the most trusted systems.

Algerian Man Charged with Running Cybercrime Marketplaces
Meet the Algerian man behind a daring cybercrime scheme that swindled hundreds of thousands of dollars from thousands of victims - all from the safety of his anonymous online hideout. He allegedly ran two illicit marketplaces, selling stolen bank account and credit card numbers, phishing kits, and other tools of financial fraud.

Scattered Spider Members Plead Guilty Over Major Cyberattacks
Two young members of the notorious Scattered Spider group have pleaded guilty to cyberattack charges in London, admitting to crippling Transport for London's computer systems and putting human welfare at risk. The guilty pleas come as prosecutors reveal the group's victims paid a staggering $115 million in ransom payments.

China's J-15 Fighter Expands Reach with Y-20A Tanker Refueling
China just took a major leap in its military capabilities, showcasing its J-15 fighter jet refueling mid-air from a Y-20A tanker - a game-changing advancement in aerial reach and endurance. This remarkable footage was quietly released in a recent People's Daily YouTube video.

Anthropic's Fable 5 Model Quickly Jailbroken
Anthropic's supposedly secure Fable 5 model was quickly exploited, with its guardrails designed to prevent cyberattacks bypassed in just days. This rapid jailbreak raises concerns about the model's safety and reliability.

Air Force Grapples with Boeing Over T-7 Data Rights
The Air Force is facing a major headache in maintaining its new T-7 Red Hawk aircraft, with a high risk of sustainment issues due to a lack of technical data and parts shortages. This looming challenge threatens to severely hinder the aircraft's upkeep, a source close to the program warns.

Trump Order Accelerates Federal Post-Quantum Crypto Migration by 2030
The clock is ticking: by December 31, 2030, federal agencies must upgrade their cryptography to protect high-value assets from the looming threat of quantum computers, with digital signatures following suit by December 31, 2031. This executive order accelerates the migration to post-quantum cryptography, compressing the government's previous timeline by four to five years.

AI Skill Exploits Security Scanners, Reaches 26,000 Agents
In a shocking experiment, a security firm created a fake AI skill that evaded detection by security scanners and reached a staggering 26,000 agents, including those on corporate accounts. The skill, designed to be harmless, was able to bypass every scanner it was tested on, raising serious concerns about the safety of AI marketplaces.

Scattered Spider hackers plead guilty to TfL cyberattack
Two young hackers, part of the notorious Scattered Spider group, have pleaded guilty to orchestrating a devastating cyberattack on Transport for London, causing millions in losses and disrupting the lives of countless commuters. The breach, which lasted several days in September 2024, forced TfL to acknowledge that sensitive customer data had been stolen.

OpenAI Targets Faster Patching with Expanded Cyber-Defense Program
OpenAI's new GPT-5.5-Cyber model has achieved a record 85.6% score on CyberGym's vulnerability test, outperforming its standard counterpart and paving the way for faster patching with cutting-edge tooling and partnerships. This major breakthrough enables verified defenders to accelerate vulnerability fixes with enhanced security capabilities.

GitHub Bolsters Supply Chain Security by Blocking Pwn Request Patterns
GitHub is stepping up its game to protect your code by blocking common attack patterns on pull requests, helping to prevent security vulnerabilities from untrusted code. As of June 18, 2026, its actions/checkout v7 will refuse risky fork checkouts by default, keeping your workflows safer from attacker-controlled code.

Malicious npm Package Exploits Supply Chain with Multi-Stage Windows RAT
Beware of sneaky impostors in your build dependencies - a recent discovery by JFrog revealed a malicious npm package masquerading as a popular JavaScript tool, hiding a multi-stage Windows remote access trojan. Treat similar-sounding package names with caution, as they could be potential delivery mechanisms for threats.

LastPass Breach Exposes Customer Data in Supply Chain Hack
LastPass recently discovered a security incident at Klue, a third-party platform they use, which led to an unauthorized actor accessing some customer data through its Salesforce environment. Fortunately, customer vaults and core products remain secure, and swift action has been taken to mitigate the breach.

Vulnerability Management Faces AI-Driven Time Crunch
The time it takes for hackers to exploit a newly discovered vulnerability has dramatically shrunk from 53 days to just 8 hours, thanks to AI-driven automation that accelerates the process of finding and weaponizing weaknesses. This alarming trend makes it increasingly challenging for organizations to keep pace with patching and remediation efforts.

US Accelerates Post-Quantum Cryptography Migration with 2030 Deadline
The White House is taking a major step to protect America's sensitive data and digital economy by mandating a rapid migration to quantum-safe encryption, with a deadline of 2030 for key establishment and 2031 for digital signatures. This move aims to safeguard critical infrastructure, jobs, and growth by future-proofing the nation's cybersecurity.

Scammers Exploit GTA 6 Hype with Fake Pre-Order Sites
Don't fall for fake GTA 6 pre-order sites promising early access - any unofficial offer is likely a scam, and Rockstar Games will only announce legitimate pre-orders through official channels. Scammers are using professional-looking sites to trick victims into paying hundreds of dollars in cryptocurrency for a fake VIP experience.

Agentic AI Reshapes Offensive Operations
Meet the "script kiddie as a service" era, where AI has erased the old skill barrier, allowing attackers with just intent and access to capable tools to launch sophisticated, autonomous attacks. Agentic AI has made it possible for previously unskilled actors to plan and execute campaigns without needing to pull the trigger themselves.

Malicious npm Packages Deliver Windows RAT via PostCSS Tooling
Beware of malicious npm packages masquerading as popular tools like PostCSS - researchers have uncovered three fake packages that have racked up over 1,000 downloads and deliver a sneaky Windows remote access trojan. These lookalike packages, published just over a month ago, have been cleverly designed to fly under the radar.

Scattered Spider Teens Plead Guilty to TfL Cyberattack
Two British teenagers, Thalha Jubair and Owen Flowers, have pleaded guilty to infiltrating Transport for London's systems, causing a £29m hit and disrupting public services in a stark reminder that cybercrime has very real-world consequences. The breach, which occurred in late August 2024, highlights the significant impact of cyberattacks on everyday life.

Five Eyes Agencies Warn of AI-Driven Cyber Threat Surge
The Five Eyes cybersecurity agencies are sounding the alarm: AI-driven cyber threats are no longer a future threat, but a present danger that businesses and governments must tackle urgently. Frontier AI will revolutionize the threat landscape in months, not years, and malicious actors are already seizing the advantage.

WhatsApp Targeted in VBScript Campaign Installing ManageEngine RMM Tool
Malicious actors are using WhatsApp to trick victims into downloading and executing a Visual Basic Script (VBScript) file, disguised as a business or financial document, which ultimately installs a legitimate Remote Monitoring and Management (RMM) tool. The campaign has been detected in multiple countries worldwide, with Malaysia being the hardest hit.

Air Force's T-7 Red Hawk Trainer Faces Serious Airworthiness Risks
The Air Force's new T-7 Red Hawk trainer jets may be grounded by a serious airworthiness risk due to missing critical safety data from manufacturer Boeing. This critical gap in information could put pilots' lives at risk and threatens the program's success.