Tag: emerging threats
4849 articles

AI Coding Agents Exposed to 'Agentjacking' Attacks
Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

Microsoft Resolves BitLocker Recovery Bug in Windows Server 2025 Update
Microsoft has fixed a frustrating bug in the April 2026 security update for Windows Server 2025 that could have forced devices into BitLocker recovery mode, and the solution is now available in two cumulative updates, KB5094125 and KB5093998. This fix ensures a smoother experience for users by preventing unexpected BitLocker recovery key prompts.

ShinyHunters Breach Exposes 454,600 University of Nottingham Records
The University of Nottingham has confirmed a major data breach, with a notorious cybercriminal group gaining access to a massive 454,600 student records, affecting both current students and alumni. The university is working closely with authorities and experts to investigate the incident and mitigate its impact.

CEO's Password Practice Exposes Firm to Breach Risk
A CEO's outdated password policy left his 2,000-strong company vulnerable to a potential data breach, after he stored all employee usernames and passwords in a single Excel spreadsheet on his desktop. This alarming security risk was only resolved after months of persistence, when the IT team proved they could manage messages centrally without needing everyone's login details.

GitHub Disrupts Supply Chain Attacks by Blocking npm Install Scripts
GitHub is taking a bold step to safeguard the npm ecosystem by blocking install scripts from running by default, tackling the single largest code-execution surface in the ecosystem. This move, part of npm 12's release, aims to prevent supply chain attacks by requiring explicit permission for scripts to run.

Ivanti Sentry vulnerability exploited in attacks
Within 24 hours of Ivanti releasing a patch for a high-severity vulnerability in its Sentry software, attackers began exploiting it in real-world attacks, with a large number of exploitation attempts detected. The flaw, tracked as CVE-2026-10520, allows hackers to execute code with root privileges on vulnerable mobile gateways.

China Exposes Botnet Resurgence, AI Influence Ops Targeting US
A botnet once dismantled by US law enforcement has made a stunning comeback, with over 1,500 compromised routers and IoT devices now under the control of China-nexus actors, who are using it to fuel influence campaigns and recruitment scams. This resurgence poses a significant threat, with the same group of actors still active and causing chaos.

Boeing, Rheinmetall unveil drone for German air force CCA race
Boeing Australia and Rheinmetall have just unveiled their game-changing MQ-28 Ghost Bat drone at the Berlin Air Show, a cutting-edge collaborative combat aircraft already proven in flight. The innovative drone is being pitched to the German air force as a top contender in the CCA race.

US-Iran Ceasefire Fractures Amid Overnight Strikes
US-Iran tensions have flared up again after a series of overnight strikes have left a fragile ceasefire hanging by a thread. President Donald Trump vowed to continue the military pressure, saying "We hit 'em hard yesterday, and we're going to hit 'em again hard today."

LeoLabs Deploys Mobile Radar to Track Space Objects
LeoLabs has successfully deployed its innovative mobile radar system, Scout Hawaii, which became operational in June 2026, marking a major milestone in tracking space objects. This transportable radar, fitting neatly into a standard container, is already providing valuable data to the company's space monitoring network.

CISA Overhauls Vulnerability Patching with Smarter Prioritization Directive
The Cybersecurity and Infrastructure Security Agency (CISA) has rolled out a game-changing directive that revolutionizes vulnerability patching with a smarter approach to prioritization, empowering federal agencies to tackle fixes more efficiently. By introducing clear guidelines and timelines, CISA is helping agencies focus on the most critical patches first, based on criteria like exposure, exploitability, and real-world threat activity.

Germany Weighs Drone Options Amid FCAS Fallout
As Germany ramps up its military capabilities in an era of rapid change, all eyes are on which drone wingman will be chosen to support its bold new plans. The question hung over the Berlin Air Show, where vendors showcased their top picks for the role.

Nations Scramble to Build Critical Mineral Supply Chain Resilience
The conversation about critical minerals is no longer about "if" but "how" - and the Darwin Dialogue 2026 brought together global leaders to shift the focus from diagnosis to delivery. The big question now is why democratic economies struggle to build resilient supply chains at scale and speed.

OpenAI Exposes Chinese Influence Operation Using ChatGPT
OpenAI has uncovered a sneaky Chinese influence operation that used ChatGPT to spread disinformation, posing as American voices to manipulate online debates. The operation, tracked by OpenAI's threat intelligence team, appears to be a classic case of foreign meddling.

Attackers Exploit Langflow Path Traversal Flaw in Active Attacks
A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, a popular AI development platform, allowing attackers to write arbitrary files to its filesystem. This is made possible by a path traversal vulnerability, CVE-2026-5027, which can be easily triggered due to Langflow's default unauthenticated auto-login feature.

Miasma Worm Source Code Leaked, Threatens Open-Source Ecosystem
The Miasma worm's source code leak is a game-changer, putting the entire open-source ecosystem at risk after already infiltrating 73 Microsoft repositories on GitHub. This credential-stealing attack framework operates autonomously, spreading rapidly by infecting developer machines and compromising legitimate repositories.

GitHub Bolsters npm Security to Thwart Supply-Chain Attacks
GitHub's upcoming npm v12 update is a game-changer for supply-chain security, as it will require explicit approval for automated actions like install scripts and dependency resolution that are often exploited by attackers. This move aims to shut down common code-execution paths and give developers, CI/CD pipelines, and security teams greater control over their code.

ShinyHunters Targets Oracle PeopleSoft Servers in Widespread Data Theft Attacks
ShinyHunters, a notorious extortion group, has launched a massive data theft campaign targeting Oracle PeopleSoft servers, compromising over 300 instances across 100+ organizations, with a significant impact on the education sector. The attackers have brazenly claimed responsibility, boasting of their exploits in a chilling conversation with BleepingComputer.

Disgruntled Bug Hunter Exposes New Windows 0-Day Vulnerability
A disgruntled bug hunter, known as Nightmare Eclipse, has revealed a new zero-day vulnerability called RoguePlanet, which can give attackers SYSTEM-level control over fully patched Windows 10 and 11 systems. The exploit, fueled by a grudge against Microsoft, targets a weakness in Windows Defender.

Cybercriminals Exploit AI Hype in Social Engineering Attacks
Cybercriminals are cleverly exploiting our curiosity about AI to launch sophisticated social engineering attacks, using trusted AI names and urgent lures to trick victims into divulging sensitive info or downloading malware. By tapping into our desire to stay ahead of the curve, attackers are able to bypass our usual caution and catch us off guard.

China-Linked JDY Botnet Surges to 1,500 Devices for Cyber Reconnaissance
A covert network of over 1,500 devices, linked to China, has been uncovered, feeding sensitive data to nation-state actors in a massive cyber reconnaissance operation. This JDY botnet has rapidly expanded, scanning and mapping vulnerable infrastructure on a massive scale.

TikTok Tutorials Spread Vidar Stealer via Fake Software Lures
Cybercriminals are using TikTok and Instagram Reels to spread the Vidar infostealer by disguising it as free software tutorials, tricking viewers into downloading malware. By reporting these accounts, users can help take them down and slow down the attackers' momentum.

CISA Flags Cisco, Chrome, Arista Flaws as Actively Exploited
Stay safe online: CISA has flagged serious vulnerabilities in Cisco, Chrome, and Arista that are being actively exploited by hackers, so take action now to protect your systems. These flaws could let attackers gain unauthorized access, making it crucial to update your software ASAP.

Browser-Based Phishing Attacks Evade Detection by Cybersecurity Software
Most cybersecurity tools are doing their job - but that's exactly the problem, as they're not designed to catch attacks that occur at the browser session layer, where attackers are now hiding. One in five phishing attacks on enterprise browsers slip through undetected, according to Menlo Security's latest report.