Tag: emerging threats
4848 articles

Nation-States Drive 75% of UK Critical Infrastructure Cyber-Attacks, NCSC Warns
The UK's National Cyber Security Centre has warned that a staggering 75% of critical infrastructure cyber-attacks in the UK are driven by nation-states, with 200 incidents reported in the past year alone. This alarming trend highlights the growing threat of state-sponsored cybercrime, with countries like Russia, China, and Iran linked to many of these attacks.

Cybercrime Exploits APAC's Rapid Digitalization
Cybercrime is rapidly overtaking traditional crime in APAC, with nearly a third of crime in over half the region's countries now online, according to Interpol's latest report. The alarming trend highlights the urgent need for stronger cross-border collaboration to combat the evolving threat.

China Expands Security Footprint Across Indo-Pacific
China's military presence in the Indo-Pacific has undergone a significant transformation, evolving from a regional focus to a broader security footprint across the region. From peacekeeping to counter-piracy missions, China's defence diplomacy has become a central tool of statecraft under Xi Jinping's leadership.

AUKUS Bolsters Australia's Maritime Defense Strategy
Australia's nuclear-powered submarines will play a critical role in defending its maritime borders, with a key focus on detecting and countering threats from Chinese submarines. The vessels will be essential in finding, tracking, and neutralizing enemy subs to safeguard national security.

Congress Probes Pentagon's Ability to Supply Ukraine with Patriot Interceptors
The Senate Armed Services Committee is pressing the Pentagon for answers on whether it can ramp up deliveries of crucial Patriot interceptors to Ukraine, following concerning cutbacks in supplies. Ukrainian President Volodymyr Zelensky revealed that monthly shipments of PAC-3 missiles were slashed due to competing demands from the Middle East, not a lack of funds.

Cybercrime Surges Across Asia and South Pacific, Hits 30% of All Crime
Cybercrime is surging across Asia and the South Pacific, now accounting for over 30% of all recorded crime, with organised networks leveraging AI, ransomware, and social engineering on a massive scale. The rapid rise is driven by rapid digital adoption and new technologies.

Microsoft Tackles RoguePlanet Defender Flaw with Imminent Patch
Microsoft is working on a patch to fix a serious security flaw in Microsoft Defender, known as RoguePlanet, which could allow hackers to gain elevated privileges on affected systems. A high-quality security update is imminent to address this vulnerability and protect users.

Malware Campaign Exploits Fake Reviews to Spread Crypto Clipper
A single threat actor cleverly mimicked legitimate brands to spread Crypto Clipper Malware, using fake reviews, tutorial videos, and promotions on trusted platforms to manufacture credibility for a malicious crypto tool. They created a convincing illusion of a trusted product, complete with inflated download counts and coordinated five-star reviews.

US Army Tests Robots in Breach Exercises to Spare Soldiers
In a bold move to protect its soldiers, the US Army recently tested robots in high-risk breach exercises, sending uncrewed systems forward to tackle heavily defended obstacles instead of troops. This game-changing tactic could revolutionize the way the military approaches combat, keeping soldiers safer in the process.

USAF Faces Senate Scrutiny Over E-11 BACN Jet Retirement Plan
The US Air Force's plan to retire its fleet of seven E-11A Battlefield Airborne Communications Node (BACN) jets by 2028 has raised red flags with the Senate Armed Services Committee, which is demanding answers on how the capability gap will be filled. The committee wants a briefing by March 31, 2027, on the Air Force's plan to mitigate the operational risk of losing this critical communication capability.

Iran's Hackers Persist Despite Peace Deal Efforts
Despite a diplomatic breakthrough between the US and Iran, cyber conflict remains a persistent threat, with US officials skeptical that a peace deal will bring an end to Iran's hacking activities. The fragile agreement leaves major disputes unresolved, including cyber, fueling concerns about Iran's continued digital aggression.

Aselsan Secures $900M Deal for Turkey's Steel Dome Air Defense Project
Turkey is bolstering its air defense capabilities with the Steel Dome project, a critical modernization effort driven by lessons learned from global conflicts, and Aselsan is leading the charge with a $900 million contract to supply cutting-edge technologies. The deal, valued at €780 million, will see deliveries of key components between 2028 and 2032.

Pakistan Defence Budget Targets Modernization with $10.76 Billion Outlay
Pakistan is set to bolster its defence capabilities with a record $10.76 billion budget for FY2026-27, but experts say the impressive figure hides underlying complexities when factoring in the rupee's decline and spending trends. The allocation breaks down into PKR 967 billion for personnel, PKR 743 billion for operations, and a 39% surge in "physical assets" to PKR 925 billion.

Attackers Exploit Critical Fortinet Vulnerabilities Disclosed in April
Security researchers have confirmed that hackers are actively exploiting critical vulnerabilities in Fortinet's FortiSandbox product, first patched in April, with multiple independent groups jumping on the bandwagon. The exploitation attempts, observed as early as June 9, involve OS-command injection and path-traversal flaws.

Ukraine Bolsters Europe's Long-Range Strike Capabilities with Cruise Missile Tech
Ukraine's groundbreaking cruise missile tech is set to supercharge Europe's defense capabilities, with German defense firm Diehl Defense partnering with Ukrainian manufacturer Fire Point to produce the game-changing FP-5 "Flamingo" missile. This powerful collaboration is a win for both nations, marking a major leap forward in their joint defense innovation.

Kodak Breach Exposes 2.2M Records to ShinyHunters Threat Group
Kodak has confirmed a major data breach, with the ShinyHunters threat group claiming to have stolen 2.2 million records, including sensitive customer information. The company is working closely with law enforcement and cybersecurity experts to address the breach.

Fortinet Firewalls Compromised in Massive Password-Stealing Attack
A massive password-stealing attack has compromised around 75,000 Fortinet firewall devices, putting credentials of major corporations across 194 countries at risk and leaving a trail of full network compromises in its wake. The breach, dubbed FortiBleed, has created a verified database of working credentials for some of the world's largest enterprises, threatening nearly every sector of the global economy.

Hackers Exploit Tailscale for Persistent Access After C2 Takedown
Meet Poisson, a French-speaking hacker who left a digital trail of 339 commands over 33 days, revealing a clever exploit that allowed them to maintain persistent access to a small French automotive business even after a C2 takedown. The intruder's step-by-step playbook was surprisingly left in an open storage bucket, giving Cato Networks researchers a glimpse into their tactics.

Europe's Digital Sovereignty Drive Needs New Operating Model
Europe's reliance on just a few major cloud providers is sparking concerns about digital sovereignty, with policymakers worried that over-dependency on foreign technology can compromise national resilience. This concentrated market - where just 3 providers hold around 70% of the market - is driving the urgent need for a new operating model that prioritizes European control and flexibility.

North Korean Hiring Scam Exposed with AI, US Laptop Farms
Meet the ingenious AI-powered sting operation that busted a North Korean hiring scam, exposing a massive laptop farm churning out fake remote IT workers. A suspicious resume sparked the investigation, leading to a shocking discovery of a closet full of machines impersonating candidates for Western companies.

FortiBleed Exposes 73,000 Fortinet VPN Credentials Worldwide
A massive security breach has exposed a whopping 73,000 Fortinet VPN credentials worldwide, putting tens of thousands of firewall endpoints at risk, including those of major companies like Chevron, Samsung, and Mercedes-Benz. The alarming leak, discovered by security researcher Bob Diachenko, contains sensitive information like usernames, email addresses, and plaintext passwords.

Cisco Expands SD-WAN Warning on Max-Severity Bug
Cisco has urgently warned organizations using its Catalyst SD-WAN products to investigate their exposure to network compromise and hunt for malicious activity following a maximum-severity bug. This critical alert was issued after Cisco expanded its advisory to include the Cisco Catalyst SD-WAN Validator, which is vulnerable to a 10.0 improper-authentication exploit.

GitHub Phishing Kit Targets Mexican Banks via Cloud Services
A sneaky GitHub phishing kit called "GitBait" has been targeting customers of 12 Mexican banks for three years, cleverly using cloud services like GitHub Pages and Google Sheets to stay under the radar. This cunning operation relied on over 100 GitHub-hosted domains to steal credentials, making it a challenging case for investigators.

Account Takeovers Rise as Complexity Exposes Identity Vulnerabilities
As attackers increasingly target identities rather than infrastructure, account takeovers are on the rise - and with 22% of breaches involving credential abuse, it's clear that traditional username-and-password security just isn't cutting it. The explosion of identities across cloud services, SaaS apps, and remote environments has created a perfect storm of vulnerability.