Tag: emerging threats
4849 articles

Breach Notice Error Fuels Patient Skepticism
A simple mistake on breach notices sent by third-party vendor Xsolis sparked skepticism among patients when the letters misnamed Rochester Regional Health as "Rochester Regional Medical Center", leading many to dismiss them as scams. This misstep undermined trust and raised questions about the effectiveness of the breach notification process.

B-52 Crash Disrupts Radar Modernization Efforts
A devastating crash of a B-52 aircraft during takeoff at Edwards Air Force Base in California has dealt a significant blow to the Radar Modernization Program, with the incident deemed unsurvivable. The mishap has prompted an immediate suspension of flight operations at the base.

Experts Push for Standardized AI Model Inventories to Mitigate Cyber Risk
Experts warn that without standardized AI model inventories, we risk a chaotic "fire, ready, aim" approach, where multiple incompatible solutions create more cyber threats than they mitigate. A new policy paper proposes an AI bill of materials (AIBOM) as a crucial step towards reducing cyber risk and improving transparency.

NATO Overhauls Modernization Approach Amid Rising Threats
NATO's modernization approach has undergone a significant transformation in recent years, driven by the need for faster learning, greater experimentation, and interoperable systems in the face of rising threats. This shift, sparked by Russia's invasion of Ukraine, is revolutionizing how the alliance approaches force design and innovation.

Trump Bolsters Military, Intelligence Cybersecurity with New National Security Memo
President Trump just took a major step to fortify America's defenses in the digital age, signing a National Security Presidential Memorandum to boost cybersecurity and modernize governance for our nation's most sensitive computer systems. This move aims to improve accountability and coordination among agencies, protecting the systems that support military and intelligence operations.

Cal Water Probes Alleged Hacking by Iran-Linked Group
Cal Water is taking swift and decisive action to investigate allegations of a cybersecurity incident, swiftly activating its response plan and working around the clock to get to the bottom of the claim. The utility confirms that its probe, launched after learning of the alleged hacking by an Iran-linked group on June 11, 2026, is ongoing with no known operational disruptions reported so far.

Ransomware Gang Exploits Microsoft Teams for C2 Traffic
Meet the sneaky ransomware gang that hijacked Microsoft Teams to secretly control its victims' systems for two whole months, using sophisticated cyber tradecraft to stay under the radar. They pulled off this impressive heist with a custom backdoor and some clever C2 traffic disguises.

UK Plans Facial Scans, ID Checks for Social Media Users
The UK government plans to revolutionize online safety by introducing facial scans and ID checks for social media users, starting with a ban on social media for under-16s. This move aims to give kids their childhood back and protect them from the potential harms of online platforms.

Rokarolla Malware Targets Android Banking Apps with 137 Commands
Meet Rokarolla, a sneaky Android banking trojan that's taking aim at 217 banking and cryptocurrency apps with an arsenal of 137 remote commands, giving attackers alarming control over infected phones. This malicious malware is designed to outsmart even Google's Play Protect defenses, putting your financial security at risk.

China-Linked Backdoor Expands to Windows with Kernel Stealth
A China-linked espionage group has unleashed a stealthy backdoor that infiltrates Windows systems, targeting government bodies in Honduras, Taiwan, Thailand, and Pakistan. The malware, known as SprySOCKS, boasts advanced espionage features and kernel-level stealth, making it a formidable threat.

Windows Junctions Expose Hidden Malware Paths
Malware creators have found a sneaky way to evade detection by using NTFS junctions, a feature that's normally used to connect directories, to create hidden paths that can bypass security defenses like Microsoft Defender. By exploiting this vulnerability, attackers can cleverly disguise their malware's true location, making it harder to detect.

FTC Warns of $3.5 Billion Losses to Imposter Scams
The Federal Trade Commission is sounding the alarm on imposter scams, which have led to a staggering $3.5 billion in losses - nearly triple the amount reported in 2020. This pervasive form of fraud has become the most reported category, accounting for almost a third of all fraud reports filed with the FTC.

Rokarolla Trojan Enables Unseen Banking Fraud via Device Takeover
Meet Rokarolla, a sneaky Android banking trojan that's taking device takeover to a whole new level, allowing scammers to isolate and exploit victims like never before. This malicious malware doesn't just steal credentials - it gives attackers total control over your phone.

Cardiac Monitor Maker's Data Breach Exposes Security Gaps
A recent report has exposed a shocking security gap in a leading cardiac monitor manufacturer's system, leaving sensitive clinical monitoring data vulnerable to data thieves. This alarming breach highlights the urgent need for enhanced medical-device security and protection of patient information.

Cybersecurity Pros Face Mounting Challenges
Cybersecurity professionals are facing a harsh reality: 68% say their job has become significantly harder in just two years, with many also being shut out of key technology decisions that impact their work. This alarming trend is backed by eight years of data, highlighting a growing crisis in the industry.

Anonymized Infrastructure Exposes Reactive Security Gaps
Despite having access to a flood of IP data, security teams are struggling to turn it into actionable insights, with a staggering 94% of security incidents involving anonymized infrastructure that exposes reactive security gaps. The sheer volume of data is creating a clarity crisis, with analysts overwhelmed by signals but lacking the context needed to respond effectively.

Chainguard Launches Athena to Fortify Open Source Against AI Threats
Meet Athena, a groundbreaking coalition and platform that helps safeguard open-source software from AI-driven threats by streamlining vulnerability detection, private remediation, and coordinated disclosure. By joining forces, Athena members can proactively protect the entire open-source ecosystem from emerging risks.

DragonForce Ransomware Exploits Microsoft Teams to Facilitate Months-Long Breach
Meet Backdoor.Turn, a sneaky new threat that uses Microsoft Teams to hide its tracks and wreak havoc on your network for months on end - and it's surprisingly sophisticated. This Go-based RAT masquerades as legit traffic by exploiting Teams' TURN relay servers.

CISA Warns of Actively Exploited cPanel Plugin Flaw
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical cPanel plugin flaw, CVE-2026-54420, that's being actively exploited by hackers, posing a significant risk to all user-end plugin versions prior to 2.4.8. This vulnerability allows attackers to escalate privileges to root, putting your online security at risk.

China-Linked SprySOCKS Backdoor Targets Windows with Driver-Based Stealth
ESET has uncovered a Windows variant of the SprySOCKS backdoor, previously thought to only affect Linux, marking a significant expansion of its capabilities. This new variant, version 1.8, uses driver-based stealth and can communicate through TCP, UDP, and WebSocket channels.

Fortinet FortiSandbox Flaws Targeted by Attackers in Wide-Ranging Exploits
Cyber attackers are actively exploiting three high-severity Fortinet FortiSandbox vulnerabilities, CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, which were patched just last month and carry a near-critical CVSS score of 9.1. These flaws have been targeted in wide-ranging exploits over the past 24 hours, according to threat intelligence firm Defused Cyber.

Ransomware Gang Exploits Microsoft Teams to Conceal Malicious Traffic
Meet Backdoor.Turn, a sneaky new malware that's abusing Microsoft Teams to hide its malicious activities - and it's a game-changer for cyber threats. This clever RAT uses Teams' own infrastructure against us, making it harder to spot its secret communications.

Fortinet Flaws Exposed to Active Exploitation
Critical vulnerabilities in Fortinet's FortiSandbox platform are under active attack, with multiple flaws, including CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, being exploited by hackers just 24 hours after security updates were issued.

Earth Lusca Expands Arsenal with Windows SprySOCKS Malware
Chinese threat actor Earth Lusca has upgraded its malware arsenal with Windows SprySOCKS, a sneaky tool that lets hackers secretly send commands to compromised devices, allowing them to fly under the radar. This latest move has been linked to a string of high-profile attacks on government organizations worldwide.