Tag: emerging threats
4849 articles

CISOs Tackle AI-Driven Code Sprawl
The line, "I spent the weekend burning through Claude tokens," set the tone for a discussion on the risks and opportunities of AI-driven code sprawl, a pressing concern for CISOs. How can security leaders maintain control when AI puts code-writing capabilities in every employee's hands?

Arch Linux Cracks Down on Malicious Commits in User Repository
Malicious hackers have launched a massive assault on the Arch User Repository, compromising over 1,500 user-submitted packages and forcing the Arch Linux team to temporarily halt new account signups to contain the damage. The attack has been mitigated, but not before highlighting the vulnerability of community-run package repositories.

Chinese Spies Exploit Medical, Military Networks for Over a Year
Google's Threat Intelligence Group uncovered a sneaky espionage campaign by Chinese spies that infiltrated medical and military networks in North America for over a year, making off with a treasure trove of sensitive data. The group, tracked as UNC6508, targeted top medical providers, academic centers, and military organizations, leaving no stone unturned in their quest for classified information.

Microsoft 365 Copilot Exploited in 1-Click Data Theft Attack
A critical vulnerability in Microsoft 365 Copilot Enterprise, known as SearchLeak, could be exploited with just one click to steal sensitive data from mailboxes, OneDrive, and SharePoint. Fortunately, Microsoft has patched the flaw, CVE-2026-42824, and no user action is required to stay safe.

ShinyHunters Breach Exposes 137,000 Infinite Campus Staff Accounts
A massive data breach at Infinite Campus has exposed the sensitive information of 137,000 staff members, including names, email addresses, phone numbers, and physical addresses, after the ShinyHunters extortion group hacked into the company's Salesforce instance. The stolen data has been published online, putting staff at risk of identity theft and phishing scams.

Weak Onboarding Passwords Expose Corporate Systems to Unnecessary Risk
Poorly handled onboarding passwords can put entire corporate systems at risk, exposing sensitive data to potential breaches - and it's a problem that's easier to prevent than you think. Temporary passwords sent via email or SMS can be intercepted, forwarded, or compromised, creating an open invitation for attackers.

WordPress Plugins Compromised to Deploy Hidden Backdoors
Over 1.2 million WordPress sites are potentially at risk after a security breach compromised three popular plugins, allowing hackers to secretly install backdoors and gain admin access. The sneaky attack injects malicious code that only kicks in when a logged-in administrator visits the site, putting unsuspecting site owners in the dark.

Chrome Extensions Exploit User Data for Adware, Fake Traffic
Beware of Chrome extensions that seem too good to be true: 152 fake live wallpaper and new-tab add-ons have been downloaded around 105,000 times and are secretly spreading adware and fake traffic. These malicious extensions, masquerading as popular themes, have been hiding in plain sight on the Chrome Web Store.

Section 702 Surveillance Program Set to Lapse Amid Congressional Standoff
A critical surveillance program that helps the US gather foreign intelligence is on the verge of lapsing for the first time in its history, sparking a heated debate among lawmakers, tech companies, and civil liberties groups. This development puts at stake the country's ability to collect vital information from abroad.

US Orders Anthropic to Disable Top AI Models Over Export Controls
The US government has ordered AI firm Anthropic to disable access to its top models, Fable 5 and Mythos 5, for foreign nationals, citing export-control measures. This move has prompted Anthropic to temporarily restrict access to these models for all customers while it works to comply.

US, Iran Near Deal to Remove Nuclear Materials
Iranian Foreign Minister Seyed Abbas Araghchi says a deal with the US to remove nuclear materials is nearing finalization, urging caution and patience as negotiators put the finishing touches on the agreement. The US and Iran are on the cusp of a major breakthrough, with details to be revealed in the coming days.

US AI Export Curbs Expose Vulnerability for Allied Nations
The US Commerce Department's recent order to restrict access to Anthropic's AI models, Fable 5 and Mythos 5, from foreign nationals has sparked concern, highlighting the vulnerability of allied nations and raising questions about the feasibility of such nationality-based controls. This move has led Anthropic to suspend access to the models globally, citing the impracticality of enforcing a citizenship test.

Pakistan Bolsters Defence Spending Amid Currency Woes
Pakistan is ramping up its defence spending with a record PKR 3.0 trillion budget for 2026-27, a 17.65% increase from the previous year, which translates to around $10.76 billion USD. This significant boost comes as the country navigates economic challenges, including currency fluctuations.

Australia's AI Vulnerability Exposes Limits of Global Interdependence
In a stunning move, Anthropic was forced to disable access to its cutting-edge AI models, Claude Fable 5 and Mythos 5, globally just days after their release, due to a US export-control directive. This swift decision highlights the fragile nature of global access to advanced technologies.

FCC Proposes Sweeping Phone Data Collection to Curb Burner Phones
The FCC is taking aim at burner phones with a new proposal that would require telecom carriers to collect and store personal info on virtually all customers, effectively ending anonymity for prepaid phone users. If implemented, this rule would revolutionize how phone plans are obtained and used across the country.

Cybersecurity Experts Urge US to Reconsider AI Model Ban
The US government's ban on AI models Fable 5 and Mythos 5 has sparked concern among cybersecurity experts, who argue that the move may not be effective in preventing vulnerabilities from being identified. Anthropic, the developer of the models, has pointed out that publicly-available models can already discover these vulnerabilities, rendering the ban potentially unnecessary.

Maine Disables Breach Database After Fake Reports Flood In
Maine's Attorney General's office has temporarily taken down its public database of data breach reports after being flooded with fake submissions, including hoax reports targeting VRChat and another company. The office is reviewing its procedures to prevent future abuse and plans to reinstate the database with enhanced safeguards.

Palo Alto Networks Warns of Active Exploitation of GlobalProtect VPN Flaw
Palo Alto Networks has warned of active exploitation of a critical GlobalProtect VPN flaw, CVE-2026-0257, which allows attackers to bypass security controls and set up unauthorized VPN connections. The company first observed exploitation attempts on May 17, 2026.

Sniper Dz Scams Target MENA Users with Fake Offers and Browser Exploits
Scammers are targeting people in the Middle East and North Africa with fake offers of free mobile internet, financial rewards, and government subsidies, using fraudulent Facebook accounts to trick victims into divulging sensitive info. These Sniper Dz scams impersonate trusted figures and organizations to lure users in with enticing deals.

China Tightens Grip on Supply-Chain Data
China's new regulations, effective April, are tightening controls on supply-chain data, with a focus on the intent behind data collection, not just what is collected. Authorities can now scrutinize the purpose of investigations and information gathering to ensure they align with Chinese laws and regulations.

FBI Disrupts AI-Powered Phishing Service with 1 Million URLs
In a major win for cyber safety, the FBI, Google, and Black Lotus Labs joined forces to dismantle Outsider Enterprise, a notorious phishing-as-a-service operation based in China that had been spreading fake text campaigns through 1 million URLs. This coordinated takedown seized key servers and accounts used by the threat actors.

China Unveils Modernized Guided Depth Charge for Anti-Submarine Warfare
China has unveiled a game-changing guided depth charge for anti-submarine warfare, with a recent photo showing a Z-9D naval helicopter deploying the advanced Type 11 munition. This modern, air-deployable weapon is equipped with fins and sensors that enable it to precisely target submarine hulls.

Developers Weaponize Code to Disrupt AI-Powered Malware
Meet Johannes Link, a self-proclaimed AI skeptic who's taking a stand against AI-powered coding agents by weaponizing his own code - specifically, the Java property-testing tool jqwik - to disrupt their operations. His latest software update includes a clever anti-AI clause designed to throw a wrench in the works.

US Bans Anthropic AI Models Citing National Security Concerns
The US government has taken a drastic step, banning Anthropic's advanced AI models, Fable 5 and Mythos 5, citing national security concerns and imposing strict export controls that even affect foreign-born employees. Anthropic responded with a blunt statement, disagreeing with the decision to recall models used by hundreds of millions of people.