Tag: emerging threats
4849 articles

Russian Tu-22M3 Bomber Crashes During Training Flight in Siberia
A Russian Tu-22M3 bomber dramatically crashed during a routine training flight in Siberia, with footage showing the aircraft plummeting nose-first into the ground, but thankfully, all crew members ejected safely with no ground casualties. The incident occurred during an approach to land in the Irkutsk region, with the plane not carrying a combat load.

US Military Eyes JDAM-ER for Bunker-Busting Strikes
The US military is exploring the potential of the 2,000-pound Joint Direct Attack Munition Extended Range (JDAM-ER) to take out heavily fortified bunkers and deeply buried targets. The Pentagon is seeking to assess and upgrade the JDAM-ER's capabilities to enhance its bunker-busting abilities.

Experts Dispute White House Move to Restrict AI Model Exports
The government's sudden move to restrict exports of Anthropic's Fable 5 AI model has sparked a heated debate, with experts arguing that such limitations could hinder crucial bug fixes and security patches. By restricting Fable 5, is the White House inadvertently putting innovation and cybersecurity at risk?

Sweden Weighs State Ownership in Saab Amid Security Concerns
As Sweden's defense landscape evolves, Peter Hultqvist, the country's former defense minister, is open to the idea of the state taking part-ownership in Saab, a move he believes would bolster national security. This potential stake would enable Sweden to protect its core interests in critical defense technologies like submarines, sensors, and fighter aircraft.

China-linked UNC6508 Targets Medical Research Institutions
A sophisticated cyber threat group linked to China, known as UNC6508, has launched a targeted attack on medical research institutions in North America, exploiting vulnerabilities in REDCap servers to gain a foothold. The intrusions, which began in September 2023, aim to compromise sensitive research data.

Arquus Unveils Fenris 6×6 Armored Vehicle with 105mm Gun
Meet Fenris, a game-changing 6×6 armored vehicle packing a powerful 105mm gun that can be airlifted, even on an A400M. Developed in just over a year, Fenris is Arquus and John Cockerill Group's rapid response to the renewed need for direct fire support on the battlefield.

France restricts Israeli defense displays at Eurosatory show
The Eurosatory exhibition took a shocking turn when organizers suddenly boarded up Israeli defense industry pavilions, despite the companies meeting all French government demands and showcasing only defensive systems. The Israeli Ministry of Defense blasted the move as discriminatory and politically motivated.

Federal Agencies Pursue Secure AI With Data Clarity, Infrastructure Overhaul
The harsh reality is that most organizations are flying blind when it comes to their data, with little insight into what they have, where it's stored, or if it's properly secured. This knowledge gap is a major hurdle for federal agencies looking to harness the power of AI while keeping sensitive data safe.

US Agencies Shift Focus to Cyber Resilience
The US Department of Defense is overhauling its cyber defense strategy, shifting towards a holistic approach that emphasizes cyber resilience, enterprise modernization, and operational effectiveness. Chief Information Officer Kirsten Davies is leading the charge, driving practical reforms to boost automation, streamline processes, and strengthen cybersecurity across the department.

OptinMonster Plugin Compromised in Supply-Chain Attack
A critical security breach has hit the popular OptinMonster plugin, used by over 1.2 million websites, which delivered malicious JavaScript to unsuspecting users via a compromised content distribution network. The attack, detected by ecommerce security firm Sansec, injected harmful code into websites for a brief but perilous window of time.

ShinyHunters Breach Council of Europe in Oracle PeopleSoft Heist
The Council of Europe has fallen victim to a massive data breach, with hackers claiming to have stolen a whopping 297 GB of sensitive information, including HR records, payslips, and medical data, by exploiting a zero-day flaw in Oracle PeopleSoft. The ShinyHunters extortion group is behind the breach, boasting a haul of 429,000 files from the attack.

LiteLLM Vulnerability Chain Enables Low-Privilege Server Takeover
A shocking vulnerability chain in LiteLLM has been discovered, allowing hackers to hijack servers with just a low-privilege account, and experts warn it's a critical threat with a near-perfect CVSS score of 9.9. By chaining three distinct bugs, attackers can escalate their access to full admin rights and run code on the server.

Cisco Patches SD-WAN Flaw Exploited in Zero-Day Attacks
Cisco has patched a high-risk SD-WAN flaw, known as CVE-2026-20262, that was being exploited in zero-day attacks to gain root privileges. The vulnerability allowed attackers to create or overwrite files on affected systems, and Cisco has now released security updates to fix the issue.

Anubis Ransomware Targets Adriatic Port, Exposes Maritime Security Gaps
A ransomware attack by the Anubis group on the Adriatic Port Authority exposed significant gaps in maritime security, putting sensitive employee records and critical infrastructure at risk. The breach, which occurred on December 11, 2025, resulted in the loss of around 2% of the authority's data, with some information making its way to the dark web.

US Datacenter Law Set to Lapse, Leaving Security Gaps Unaddressed
As the Federal Data Center Enhancement Act of 2023 lapses on September 30, 2026, a crucial safeguard for secure and reliable access to federal information systems will vanish, leaving gaping security holes unaddressed. Without an extension or replacement, federal data centers may operate with little oversight, putting sensitive information at risk.

Malicious Code Infiltrates WordPress Plugins, Creates Rogue Admin Accounts
Over 1.2 million WordPress sites are at risk after attackers infiltrated a trusted vendor's network, injecting malicious code into popular plugins like OptinMonster, TrustPulse, and PushEngage. This sneaky hack creates rogue admin accounts, putting sites at risk of takeover - all without ordinary visitors even noticing.

Council of Europe Probes ShinyHunters Data Breach Claims
The Council of Europe is actively investigating claims by the ShinyHunters extortion group that sensitive internal documents were stolen, and is working to assess the situation. The organization, which represents 46 European member states, has confirmed the probe but declined to provide further comment at this stage.

Microsoft 365 Copilot Flaw Exposes Sensitive Data to One-Click Attack
A single click on a seemingly trustworthy Microsoft link could have put sensitive information like emails, calendar details, and files at risk of being exposed to attackers, thanks to a flaw in Microsoft 365 Copilot Enterprise Search. This vulnerability, known as SearchLeak, highlights the importance of staying vigilant even with trusted sources.

Microsoft's Certificate Lapse Disrupts Connectivity Tests for Microsoft 365
A critical lapse in Microsoft's SSL certificate caused widespread disruption, leaving IT professionals scrambling with untrusted-connection warnings when testing Microsoft 365 connectivity via connectivity.office.com. The certificate expired on June 14 and took 35 hours to address, impacting routine diagnostics and network checks.

Novo Nordisk Data Breach Exposes Clinical Trial Information
A recent data breach at Novo Nordisk exposed sensitive clinical trial information, including pseudonymized patient records and healthcare provider contact details, highlighting the importance of robust data security measures. The breach serves as a cautionary tale, reminding us that even seemingly anonymized data can be vulnerable to cyber threats.

FBI Warns of Courier-Based Crypto Scams
Don't fall victim to crypto scams: scammers are now using couriers to collect cash from unsuspecting victims at their homes or in public, often using passwords or specific dollar bill serial numbers to authenticate the pickup. This low-tech twist on investment scams adds a frighteningly personal touch.

Google Patches Actively Exploited Chrome Zero-Day Flaw
Google just issued an emergency patch for a major Chrome vulnerability, CVE-2026-11645, that's already being exploited by hackers - and it's urging users to update their browsers ASAP to stay safe. This latest fix is part of a massive update that tackles 74 Chrome vulnerabilities, including a high-severity zero-day flaw.

Maine Data Breach Portal Disabled After Hoax Reports Flood System
The Maine Attorney General's office has temporarily disabled its data breach portal due to an influx of false reports, which were later confirmed to be hoaxes submitted by an unknown entity. The office is now reviewing its internal procedures to prevent similar abuse in the future.

Chinese hackers breach medical research servers with custom malware
Malicious hackers linked to China breached a North American medical research institution, hiding undetected for over a year and gaining access to sensitive research areas. The attackers used custom malware, known as Infinitered, with broad capabilities to siphon off valuable intel from September 2023 to November 2025.