Skip to main content

Tag: emerging threats

4837 articles

A coach sits at a table with an open laptop displaying heart rate and sleep data.

Wearables Expose Athletes to Data Abuse Risks

Imagine a coach scrutinizing an athlete's sleep and heart-rate logs to gauge their off-field behavior - a chilling invasion of privacy that's not as far-fetched as it sounds. As wearables become ubiquitous, athletes face growing risks of data abuse, from compromised privacy to unfair advantages in high-stakes competitions.

Analyst 207
Modern software development setting with a laptop displaying a graphical interface on a neutral surface.

Microsoft Fixes AutoGen Studio Flaw That Enabled Code Execution

Microsoft swiftly squashed a potential code execution flaw in AutoGen Studio, ensuring the vulnerable code never made it to users via a PyPI release. The fix addressed a sneaky three-part vulnerability chain, dubbed AutoJack, that could have been exploited to run malicious code.

Analyst 207
Unmanned ground vehicles on display at a defense trade show exhibition hall.

Unmanned Ground Vehicles Proliferate at Eurosatory Amid Ukraine War Lessons

At Eurosatory 2026, the spotlight shone bright on unmanned ground vehicles, with over 50 makers showcasing their war robots, including Ukraine's largest-ever contingent of 40-plus manufacturers, who brought battle-tested innovations to the table. Ukraine's three years of real-world battlefield experience have catapulted it to the forefront of UGV development.

Analyst 207
Workers in a brightly-lit manufacturing facility assemble defense equipment.

Trump Invokes Defense Production Act to Boost Weapons Production

President Donald Trump has taken a crucial step to ramp up US weapons production by invoking the Defense Production Act, a move aimed at bolstering the country's defense capabilities. This executive decision enables a surge in production to meet growing demands.

Analyst 207
Modern conference room with laptop and sleek table overlooking brightly-lit facility.

Intel Agencies Warn of AI-Driven Cybersecurity Overhaul

Get ready for a seismic shift in cybersecurity: AI-driven threats are on the horizon, and intelligence agencies warn that the clock is ticking, with advanced AI models expected to become publicly available within months, not years. The Five Eyes agencies are sounding the alarm, urging a proactive overhaul of cybersecurity defenses to counter the impending storm.

Analyst 207
Australian farm with crates of fresh produce, some slightly disorganized, bathed in natural light from an open door.

Australia's Food Security Prepares for Stress Test

A year of global turmoil has put Australia's food security to the test, proving that ensuring a steady food supply is crucial to national resilience. Recent events, from the Iran-Israel missile exchange to Strait of Hormuz pressures, have highlighted the need for governments to address vulnerabilities in the country's food system before it's too late.

Analyst 207
Smartphone on cluttered desk with WhatsApp conversation on screen, surrounded by papers and office supplies, with cityscape…

WhatsApp VBScript Campaign Targets Global Users with RMM Software

Malicious actors are targeting WhatsApp users worldwide with a sneaky VBScript campaign, compromising accounts to spread harmful files through direct messages. In a shocking concentration of attacks, 80% of victims were in Malaysia, highlighting the need for users to stay vigilant.

Analyst 207
A generic drone with visible sensors and cameras sits on a laboratory bench with a blurred background.

Autonomy Shapes Future of Battlefield Drones

As battlefield drones become more prevalent, the line between automation and autonomy is drawing a lot of attention, with experts like Palladyne AI's Ben Wolff insisting that true autonomy requires artificial intelligence that can respond in real-time without human intervention. Automation may be just table stakes, but autonomy is what will truly shape the future of these drones.

Analyst 207
Professional surrounded by technology and learning materials in a bright room.

Cybersecurity Readiness Revolution Gains Momentum

The traditional cybersecurity certification approach is no longer enough - we need a culture of lifelong learning where professionals continually upskill and reskill to stay ahead of evolving threats. Dan Magnotta, Senior Federal Business Development Manager at Hack The Box, is leading the charge towards an active-readiness revolution.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center or server room.

Dify Vulnerabilities Expose AI Chats Across Tenants

Researchers have uncovered four critical vulnerabilities in Dify, a popular AI platform with over 146,000 GitHub stars, that could allow attackers to read sensitive AI conversations across different customer applications without needing authentication. These flaws, collectively known as DifyTap, expose a broad attack surface due to Dify's default multi-tenant setup.

Analyst 207
Technicians work in a dimly lit server room with rows of racked equipment.

Squid Proxy Bug Exposes Cleartext HTTP Requests

A newly discovered bug, dubbed Squidbleed, has been found in the popular Squid web proxy, allowing attackers to intercept sensitive HTTP requests and steal valuable credentials. This 20-year-old vulnerability, traced back to a 1997 FTP-parsing change, still affects Squid's default configuration.

Analyst 207
Medical equipment and a computer terminal sit on a cluttered counter in a hospital setting.

Ransomware Gang Disables Security Software with GentleKiller Framework

Meet GentleKiller, a sneaky framework that helps ransomware gangs disable security software by targeting over 400 processes across 48 security products at the kernel level, allowing them to run unchecked. This sinister tool uses a "bring your own vulnerable driver" technique to terminate protections and clear the way for ransomware attacks.

Analyst 207
Concerned customers and staff in a utility company's office with scattered papers and a blurred computer screen.

London Hydro Data Breach Exposes Customer Information

London Hydro recently suffered a data breach that may have compromised personal info for over 160,000 of its customers in and around London, Ontario, leaving many with unanswered questions about the security of their data. The utility company has started notifying affected customers and is investigating the incident.

Analyst 207
Cramped, dimly lit room with cluttered desk, laptop, and scattered papers, surrounded by old computer equipment.

Threat Actors Monetize Stolen Credentials with Searchable Underground Services

Cybercriminals are cashing in on stolen credentials with a new breed of underground services that allow buyers to search and purchase specific, verified login details. This emerging market acts as a middleman between hackers who steal sensitive info and those who want to use it to take over accounts.

Analyst 207
Smartphone on a neutral surface with blurred screen, set against a cityscape background.

Google Tightens Android App Verification Rules Ahead of Sept. 30 Deadline

Get ready for a safer app experience on Android! As of September 30, 2026, Google will start enforcing developer verification, blocking installs of unverified apps on certified phones in Brazil, Indonesia, Singapore, and Thailand.

Analyst 207
Close-up of a circuit board with a USB controller chip on a lab bench.

Unpatchable Apple BootROM Flaw Targets A12, A13 Chips

A newly discovered Apple BootROM flaw affecting A12 and A13 chips poses a lifelong security risk to affected devices, as the issue is embedded in unchangeable code that can't be fixed with a simple software update. This vulnerability, known as usbliter8, is a complex combination of hardware and firmware flaws that creates a pathway to compromise the boot chain on impacted Apple systems.

Analyst 207
Laptop screen shows fake Node.js download page on Google Ads against blurred cityscape.

Malicious Google Ads Deliver CastleStealer via New OXLOADER Malware

Beware of malicious Google ads that can deliver CastleStealer via the new OXLOADER malware, which has shown impressive engineering skills and is worth keeping an eye on. Victims are tricked into downloading fake Node.js versions through ads masquerading as legitimate sources.

Analyst 207
Network operations center with exposed cables and equipment near a large window.

FortiBleed Campaign Exposes 80K Targets Worldwide

A massive cybersecurity threat, dubbed FortiBleed, has exposed over 80,000 Fortinet FortiGate devices worldwide, with alarming ease, by exploiting weak passwords and reused credentials. The US Cybersecurity agency is urging affected customers to secure their appliances immediately to prevent a potential breach.

Analyst 207
Dimly lit server room with outdated equipment and exposed cables.

Legacy Infrastructure Exposes AI Agents to Hijacking Risks

Legacy infrastructure can put your AI agents at risk of hijacking, as seen with CVE-2025-24813, a remote code execution flaw that lets attackers turn a routine server compromise into a full takeover. An unpatched Internet-facing Apache Tomcat server is all it takes to expose your enterprise to this threat.

Analyst 207
Emergency alert system interface on a computer monitor in a government office setting.

Brazil Probes Hack of Emergency Alert System After Rogue Alert

A bogus emergency alert sent shockwaves across Brazil, pinging mobile devices in multiple states with a mysterious message reading "Alerta extremo - Defesa Civil:misantropi4". The authorities are now scrambling to investigate the hack, with SEDEC and Federal Police on the case.

Analyst 207
Cluttered tech workspace with laptop and papers, background blurred.

Microsoft Links North Korea to Mastra AI Supply Chain Compromise

Microsoft has uncovered a massive supply chain attack on the npm registry, where over 140 packages were compromised, and has linked the operation with high confidence to Sapphire Sleet, a notorious North Korean state actor known for targeting the financial sector. This large-scale attack highlights the growing threat of North Korean hacking groups.

Analyst 207
Cloud-based software integration hub with OAuth token authorization prompt on laptop screen.

Klue Breach Exposes Cybersecurity Firms to OAuth Token Abuse

A single compromised credential led to a massive security breach at Klue, allowing an unauthorized actor to exploit OAuth tokens and gain access to sensitive customer data on third-party platforms like Salesforce. This incident highlights the growing threat of OAuth token abuse and the need for robust cybersecurity measures.

Analyst 207
CSIS agent surrounded by technology equipment in a neutral setting.

Canada's Spy Agency Neutralizes Foreign Botnets with Landmark Warrant

In a groundbreaking move, Canada's spy agency, CSIS, has successfully neutralized two foreign-run botnets operating on Canadian soil, thanks to a landmark warrant that allowed them to access and shut down infected devices. This pioneering threat-reduction tactic marks a major win in the fight against botnet threats.

Analyst 207
Cautious hand approaches laptop with blurred screen in neutral workspace.

Gizmodo Readers Targeted by ClickFix Malware After Account Compromise

If your Gizmodo account was compromised, be aware that you may have been targeted by the ClickFix malware, which showed up as suspicious prompts after the breach. Stay vigilant and take immediate action to protect your online security!

Analyst 207