Tag: emerging threats
4857 articles

SoFi Hong Kong Breach Exposes Customer Data at Third-Party Vendor
SoFi Hong Kong recently discovered a data breach at a third-party vendor that exposed customer information, with unauthorized access detected on April 30, 2026. The company's investigation is ongoing, but it confirmed the breach originated from a vendor, not its internal systems.

Android Malware NFCShare Targets Europe Banks via GitHub Updates
Malicious actors are using GitHub to spread new variants of the NFCShare Android malware, disguising them as banking app updates to target customers of European banks. Victims are first lured into downloading the malware through phishing sites that mimic real banks, where they're prompted to install a fake update.

Israel, Iran Engage in Strikes, Then De-escalate Tensions
In a shocking escalation, Israel and Iran exchanged strikes, but quickly stepped back from the brink, with both sides now pushing for an immediate ceasefire and final peace negotiations. President Donald Trump publicly urged calm, calling for both nations to stop fighting and hinting at a potential breakthrough.

FCAS Fighter Program Implodes Amid Industrial Dispute
The €100 billion FCAS Fighter Program, a joint effort between France, Germany, and Spain to develop a next-generation fighter jet, has reportedly collapsed due to irreconcilable differences between industry giants Dassault and Airbus. The program's demise comes after failed mediation efforts and a final decision by the German government to pull the plug.

Trump Memo Targets AI Contractors With New Security Rules
The US is set to supercharge its AI capabilities in intelligence and warfighting domains, with a new presidential memo directing the federal government to accelerate AI adoption while prioritizing speed, security, and responsible innovation. The move aims to harness AI's potential in line with American values, with rigorous oversight to ensure safe and effective deployment.

Defense Teams Face AI-Driven Data Protection Challenges
The explosive growth of AI in the Department of Defense - a 1,775% surge in just one year - is putting intense pressure on defense teams to safeguard sensitive mission data. As AI empowers warfighters to make faster, more precise decisions, the challenge of protecting data at rest has never been more urgent.

Franco-German Fighter Program Collapses Amid Industrial Impasse
France and Germany have reportedly pulled the plug on their ambitious joint fighter jet project, the New Generation Fighter, after failing to iron out industrial differences. The decision comes after extensive discussions between the two leaders, who concluded that the program was no longer viable.

China's Demand-Chain Strategy Upends Australia's Mineral Market Leverage
Can Australia's rich mineral resources still guarantee its economic clout, or will China's demand-chain strategy shake up the global market and redefine who holds the power? The answer lies in whether owning the resources or controlling the demand will ultimately capture the most value.

Meta Alleges NSO Group Breaches Spyware Injunction
Meta just took a bold stand against NSO Group, the notorious spyware maker, by ramping up legal action after thwarting a sneaky phishing campaign aimed at WhatsApp users. The tech giant successfully blocked NSO-linked attempts to trick people into clicking malicious links, despite a US court injunction already in place.

Defense Industry Converges on Berlin Air Show Amid Budget Surge
The 2026 ILA Berlin Air Show is set to make a splash as the defense industry converges on Berlin, fueled by Germany's dramatic surge in defense budgets. This pivotal event will put the spotlight on how increased national spending will drive procurement and program decisions, making it a must-attend for military and aerospace suppliers.

Apple Unveils AI-Powered Tool to Automatically Secure Compromised Passwords
Say goodbye to password anxiety with Apple's latest innovation - an AI-powered tool that automatically secures compromised passwords, giving you peace of mind with just a few clicks. This game-changing feature, part of Apple Intelligence, uses AI to update weak and vulnerable credentials to strong, unguessable passwords.

Shai-Hulud Malware Targets Python Packages, Exposes Developer Secrets
Hundreds of thousands of downloads of 19 popular Python packages were compromised in a massive supply-chain attack that stole developer secrets, courtesy of the Shai-Hulud malware. The malicious packages, disguised as useful bioinformatics and science tools, were actually designed to expose sensitive information.

IBM, AT&T Face Allegations of Concealing Data Breaches
A shocking lawsuit alleges that tech giants IBM and AT&T may have concealed massive data breaches, with Chinese hackers reportedly infiltrating IBM's network over 56,000 times between 2013 and 2016. The allegations, made by a former IBM vice president, claim the company knowingly kept the breaches under wraps.

Handala's Israeli Radar Claim Sparks Skepticism
Can a mysterious Iranian-linked hacker group really take down Israel's radar systems? Handala claims it did on the same day Israel and Iran exchanged missile fire, but experts are raising an eyebrow.

WhatsApp Disrupts NSO Group's Spyware Phishing Campaigns
Meta's WhatsApp team swiftly sprang into action, disrupting a sophisticated spyware phishing campaign linked to the NSO Group after investigating user reports of targeted social-engineering attacks. They successfully stopped the attackers' attempts to trick people into clicking malicious links that could have put their data at risk.

China Exploits Job Sites for Spying on Five Eyes Targets
Be cautious on job sites - Chinese spies are posing as recruiters on LinkedIn, Indeed, and Upwork to trick Five Eyes targets into divulging sensitive information. They're using clever social engineering tactics to make their scams seem all too believable.

Check Point Discloses Zero-Day Flaw Exploited by Ransomware Groups
Check Point has uncovered a zero-day flaw, CVE-2026-50751, that allowed ransomware groups to exploit a critical authentication bypass in Remote Access and Mobile Access deployments, prompting an emergency fix. The vulnerability enabled attackers to establish a remote access VPN connection without proper authentication.

Meta Disrupts NSO Group's WhatsApp Phishing Campaign
Meta detected and blocked a sneaky WhatsApp phishing campaign linked to NSO Group, where attackers tried to trick people into clicking malicious links that led to external websites. The company also filed a contempt order against NSO for allegedly violating a court injunction by targeting WhatsApp users.

Gogs Fixes Zero-Day Flaw Enabling Remote Code Execution
A critical vulnerability in Gogs allows attackers to execute remote code, putting Internet-facing instances at risk of full compromise - and it's easily exploitable by anyone who can create an account. This flaw enables attackers to wreak havoc without needing admin privileges, making swift action a must.

UniFi OS Bug Lets Hackers Gain Root Without Authentication
A critical bug in UniFi OS can be exploited by hackers to gain root access without any login credentials, user interaction, or prior access, putting your system at risk. Three vulnerabilities, now patched, can be chained together to allow remote code execution with root privileges.

Ransomware Disrupts Illinois High School, Wales Education Sector
A ransomware attack has forced Evanston Township High School in Illinois to shut down until at least Wednesday, canceling summer school, sports camps, and on-campus activities. The school has activated its incident response procedures and is working with cyber experts to investigate and recover from the breach.

North Korean Hackers Exploit Coding Lures to Steal Crypto Credentials
In a sneaky move, North Korean hackers sent over 250 emails with innocent-looking coding tasks to nearly 100 US-based organizations, tricking them into handing over cryptocurrency credentials. The clever phishing scam, tracked as UNK_DeadDrop, targeted tech, education, and finance firms, with a special focus on cryptocurrency companies.

Check Point VPN Flaw Exposed, Bypasses Passwords in IKEv1 Setups
A critical flaw in Check Point VPN setups has been exposed, allowing attackers to bypass passwords and establish a VPN session without proper authentication in certain configurations. This vulnerability, tracked as CVE-2026-50751, impacts Remote Access VPN and Mobile Access deployments using the outdated IKEv1 protocol.

Miasma Worm Exposes GitHub Repositories in Supply Chain Attack
A sneaky Miasma worm has infiltrated 73 Microsoft GitHub repositories, putting countless projects at risk in a self-replicating supply chain attack. This malicious campaign is a stark reminder of the rapidly evolving threats lurking in the shadows of our digital supply chains.