Tag: emerging threats
4849 articles

Langflow Vulnerability Exploited for Unauthenticated Remote Code Execution
A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, allowing attackers to execute remote code without needing any login credentials. This vulnerability, tracked as CVE-2026-5027, enables malicious actors to write files to any location on a host filesystem.

Fortinet, Ivanti, SAP Patch Critical Vulnerabilities
This week, Fortinet, Ivanti, and SAP issued urgent patch rollouts to fix critical vulnerabilities that could allow hackers to execute remote code or gain unauthorized access to sensitive systems. The flaws, affecting sandboxing infrastructure, mobile gateway software, and core enterprise apps, carry high severity scores and demand immediate attention.

SilabRAT Trojan Targets Crypto Wallets with Session Hijacking
Meet SilabRAT, a sneaky Trojan that's been sold as a malware-as-a-service on dark web forums since late 2025, allowing cybercrooks to hijack crypto wallet sessions and swipe funds. For just $5,000 a month, attackers can get their hands on this powerful tool and start targeting unsuspecting crypto wallet users.

China-linked JDY botnet targets US military networks with expanded reconnaissance.
The JDY botnet, linked to China, has more than doubled its malicious reach since January 2024, growing from 650 to over 1,500 compromised devices, with a significant focus on infiltrating US military networks and associated targets. This expanding reconnaissance capability poses a concerning threat to US cybersecurity.

Credential Theft Spurs Demand for Secure Identity Verification
Credential theft skyrocketed 160% in 2025, fueling a critical need for secure identity verification solutions that can outsmart AI-driven attacks. To stay ahead, robust multi-factor authentication is a must-have, combining unique factors like something you know, have, and are to fortify defenses.

Microsoft Fixes Zero-Day Flaw in Exchange Server Exploited in Attacks
Microsoft has patched a high-severity flaw in Exchange Server, known as CVE-2026-42897, which allowed hackers to execute malicious JavaScript in victims' browsers simply by sending a specially crafted email. This zero-day vulnerability was actively exploited in attacks, putting Outlook Web Access users at risk.

GitHub Overhauls npm Defaults to Thwart Script-Based Attacks
GitHub is taking a major step to boost npm security by changing its default settings to block automatic execution of install-time lifecycle scripts, a common vulnerability exploited in script-based attacks. Starting with npm 12, these scripts will require explicit permission to run, unless explicitly allowed via a new allowlist mechanism.

Microsoft Warns of Windows Update Failures After 11 Upgrades
Beware: if you've upgraded to the latest Windows 11 versions, you might be at risk of update failures, with error codes 0x80073712 or 0x800f0993 popping up when trying to install crucial security patches. Microsoft warns that a small percentage of devices are affected, so it's essential to check your update history and logs to catch any issues.

Anthropic Unveils Mythos-Class LLM with Enhanced Cybersecurity Capabilities
Meet Claude Mythos 5 and Claude Fable 5, Anthropic's latest game-changing AI models, boasting the strongest cybersecurity capabilities on the planet. With Mythos 5 leading the charge, these cutting-edge tools are revolutionizing the fight against cyber threats.

Ivanti Warns of Critical Bugs in Sentry Software, Urges Immediate Patching
Ivanti is urging Sentry customers to patch immediately due to critical bugs affecting versions 10.0 and 9.9, and it's crucial to act now to avoid potential security risks. Don't delay - apply the necessary patches to keep your system secure.

Microsoft Patch Tuesday Disrupts 206 Vulnerabilities, Including Zero-Days
Microsoft just dropped a massive Patch Tuesday update, fixing a record 206 security vulnerabilities in its software - including three already publicly known flaws - to keep your digital world safe and secure. This critical update tackles a wide range of threats, from remote code execution and privilege escalation to spoofing and more.

Identity Crime Incidents Multiply for Victims, ITRC Data Reveals
The alarming rise in identity crime incidents is not just about the numbers, but also the disturbing pattern of recurrence, with nearly 26% of victims experiencing multiple concurrent incidents, according to the Identity Theft Resource Center's 2026 Trends in Identity Report. This growing multi-layered crisis sees single compromises snowballing into additional incidents across accounts and institutions.

Microsoft Fixes Zero-Days in June Patch Tuesday Update
Microsoft just dropped some critical patches in its June update, fixing three zero-day vulnerabilities that left Windows systems open to attacks - and one security researcher isn't happy about the delayed fix. The update squashes bugs that allowed hackers to escalate privileges or bypass disk encryption.

CISA Directive Overhauls Cyber Risk Prioritization Across Agencies
The Cybersecurity and Infrastructure Security Agency is shaking up its approach to cyber risk with a new directive that prioritizes impact over raw vulnerability counts, helping agencies focus on protecting what matters most. Acting director Nick Andersen urges a pragmatic approach, acknowledging that some systems are more critical than others.

Anthropic's Vulnerability Tool Yields Mixed Results
Anthropic's Project Glasswing, launched in April, aimed to empower companies to detect and fix software vulnerabilities using its innovative Mythos model, but the results have been mixed. The initiative has generated significant buzz, with many outlets picking up Anthropic's messaging, but the actual impact remains to be seen.

China Warns Australia on Critical Minerals Push
China is hitting back at Australia's critical minerals push, slamming Treasurer Jim Chalmers' decision to force China-linked investors to sell their stakes in rare earths developer Northern Minerals as "irrational de-sinicisation". This move has significant implications for Australia's defence, manufacturing, and renewable energy sectors.

Space Force Awards $437.7 Million for Anti-Jam Satellites
The US Space Force has awarded $437.7 million to Viasat and Intelsat to develop anti-jam satellites, a crucial component of its resilient communication architecture that will enable tactical warfighters to stay connected in denied environments. This move is a significant step towards countering emerging threats and ensuring secure communication.

Microsoft Unveils Record 200 Patches, Warns of Rising AI-Driven Flaws
Microsoft just dropped a record 200 security patches to fix critical flaws in Windows and supported software, with nearly three dozen vulnerabilities rated as critical and at least three already being exploited by hackers. This massive update signals a new normal in vulnerability disclosure, with AI-driven flaws on the rise.

Military GPS Broadcasts Conceal Encryption Keys
For nearly two decades, the US military has been secretly broadcasting encryption codes through public GPS signals, turning satellites into hidden messengers that beam mysterious information to any device that uses GPS. This covert operation was uncovered by researchers, led by Steven Murdoch, who stumbled upon a digital trail that revealed the surprising truth.

Attackers Target Cloud Logging Services for Defense Evasion and Continuous Visibility
Cloud logging services, like AWS CloudTrail and Google Cloud Logging, are a treasure trove of insights into your cloud environment - but they're also a prime target for attackers looking to erase their tracks or gain continuous visibility into your operations. By manipulating these services, adversaries can create persistent blind spots that leave you vulnerable.

AI-Fueled Attacks Prompt Enterprises to Overhaul Security Architecture
Enterprises in APAC are scrambling to revamp their security architecture as AI-fueled attacks exploit new vulnerabilities at lightning-fast speed, making rapid containment more crucial than ever. Automation is now a vital defense against these accelerated threats.

Lockheed Martin Offers HIMARS to France with Accelerated Timeline
Lockheed Martin is offering France a game-changing deal: get the advanced HIMARS system within just 18 months if a contract is signed, with a significant portion of launchers set to arrive by 2028.

US Pressures Oman, Risks Eroding Key Gulf Mediator Role
President Donald Trump's reported threat to blow up Oman has raised concerns that the US may be jeopardizing a crucial diplomatic channel with Iran, one that has helped prevent escalation for decades. By pressuring Oman to cut ties with Tehran, the US risks eroding its role as a trusted mediator in the Gulf.

Microsoft Patch Tuesday Disrupts 200 Vulnerabilities, Zero-Day Exploits
Microsoft's June Patch Tuesday update is a doozy, tackling a whopping 200 vulnerabilities, including three zero-day exploits and 33 critical flaws that could lead to remote code execution. This crucial update aims to prevent a range of issues, from denial-of-service attacks to elevation of privilege and information disclosure.