Skip to main content

Tag: emerging threats

3126 articles

Secure facility with workstations and laptop showing code on screen.

AI-Powered Vulnerability Discovery Outpaces Remediation

The AI-powered Mythos model discovered a staggering number of vulnerabilities, including a 27-year-old bug in OpenBSD and a four-bug exploit chain that bypassed browser and OS defenses, with fewer than 1% of these vulnerabilities patched. This led Anthropic to delay a public release and share the findings with tech giants like Apple and Microsoft to prioritize patching.

Analyst 207
Laptop screen displays Alibaba webpage amidst medical items and papers.

Biobank Data Breach Exposes 500k Volunteers on Alibaba

A major data breach at UK-based Biobank has exposed the medical records of around 500,000 volunteers on the Chinese e-commerce site Alibaba, putting sensitive information at risk of being misused. The compromised dataset, described as one of the world's most comprehensive biomedical datasets, was listed for sale, sparking urgent concerns about data security.

Analyst 207
Sleek technology lab setting with futuristic devices and laptop on minimalist workbench.

Google Unveils AI Agent Identity Platform to Tackle New Identity Risks

Google is stepping up its game in AI security with a new platform that gives autonomous software agents their own unique identities, ensuring that every action is verified, recorded, and accountable. This move towards zero-trust verification means organizations can trust their AI agents to act with integrity and transparency.

Analyst 207
Interconnected devices in a dimly lit server room with daylight visible through tall windows.

UK Warns of Chinese Hackers' Proxy Network Tactics to Evade Detection

The UK's National Cyber Security Centre has warned that Chinese hacking groups are using a sophisticated network of proxies to evade detection, with multiple covert networks constantly being updated and used by multiple threat actors. This alarming shift in tactics has prompted a coordinated warning from the NCSC-UK and nine international partners.

Analyst 207
Modern office setting with subtle digital communication hints.

China-Linked APT Group Exploits Legitimate Services for Covert Ops

ESET researchers have uncovered a treasure trove of clues, analyzing 6,044 Slack messages and 3,005 Discord messages that reveal the covert operations of a China-linked APT group, dubbed GopherWhisper, which has been active since at least 2023. The recovered logs provide a rare glimpse into the group's tactics, thanks to hardcoded credentials in Go-based backdoors that gave investigators access to the group's command and control channels.

Analyst 207
A small gadget, roughly the size of a dongle, sits beside a modern display device on a neutral-colored surface.

UK Cyber Agency Unveils Anti-Malware Gadget for Display Devices

Meet SilentGlass, a game-changing anti-malware device from the UK's National Cyber Security Centre that shields your display screens and monitors from cyber threats with unprecedented ease. This innovative gadget is now available for commercial use, protecting vulnerable IT infrastructure like never before.

Analyst 207
Brightly-lit federal IT operations room with Windows-based computer systems.

CISA Mandates Patching of Exploited BlueHammer Flaw in Federal Systems

Don't let your federal systems become an easy target: CISA is mandating the patching of the exploited BlueHammer flaw to prevent malicious cyber actors from gaining a foothold. A high-severity vulnerability in Microsoft Defender can allow low-privileged users to gain SYSTEM permissions - but a patch is available.

Analyst 207
Students and faculty in a university library with laptops and tablets on tables.

Education Sector Grapples with 63% Surge in Cyber-Attacks

The education sector is facing a daunting reality: a 63% surge in cyber-attacks is putting institutions at risk, threatening the very openness and collaboration that define higher education. Can schools and universities keep pace with the growing threat?

Analyst 207
Person holds smartphone with blurred city or office background, emphasizing digital security.

NCSC Endorses Passkeys as Default Login Method

The UK's National Cyber Security Centre now recommends passkeys as the default login method, marking a significant shift away from passwords. This endorsement comes after a year of collaboration with industry and notable improvements in passkey technology.

Analyst 207
Breach scene in a brightly-lit tech office with a computer workstation in the foreground.

Vercel Breach Exposes Additional Customer Accounts

A recent Vercel breach exposed additional customer accounts after a malicious chain of events began with a compromised employee account at Context.ai, which was likely triggered by a simple online search for Roblox scripts. The breach highlights the risks of malware distribution and token theft, with threat intel pointing to a sophisticated attack targeting valuable keys and account credentials.

Analyst 207
Government agency office interior with subtle computer equipment hints.

Eset Exposes Chinese Hackers' Careless Backdoor Tactics

Chinese hackers have been caught off guard by their own carelessness, leaving behind a digital trail that exposed their previously undetected backdoor tactics. Researchers uncovered over 9,000 messages revealing the attackers' testing systems and habits, leading to the identification of a Chinese nation-state actor dubbed GopherWhisper.

Analyst 207
Government office interior with computers and a large window, featuring a subtle network diagram in the background.

China-Linked GopherWhisper Targets Mongolian Government Systems with Go Backdoors

A China-linked cyber group, dubbed GopherWhisper, has been targeting Mongolian government systems with a suite of Go-based backdoors, infecting at least 12 systems and potentially dozens more. The attackers used clever tactics, routing command-and-control traffic through compromised Discord and Slack servers.

Analyst 207
Laptop screen shows Slack channel with plain-text password pinned amidst cluttered workspace.

Weak Passwords Expose Firms to Data Loss Risk

One careless decision - using the same easily-guessable password across multiple environments - left a client vulnerable to disaster, despite a hefty investment in security tools. A simple password like "admin123" pinned in a shared Slack channel created a single point of failure that put the entire system at risk.

Analyst 207
Cluttered office workspace with computer and browser on desk, cityscape outside window.

Researchers Expose AI Agents to Malicious Prompt Injection Payloads

Imagine a browser AI that can summarize web pages, but with a hidden vulnerability that allows malicious instructions to be embedded and executed - a newly discovered threat that security researchers are warning deserves our attention. Forcepoint researchers have uncovered 10 real-world examples of indirect prompt injection payloads designed to subvert AI agents and wreak havoc.

Analyst 207
Person holding smartphone in modern conference room setting with technical diagrams.

NCSC Endorses Passkeys Over Passwords in New Guidance

Say goodbye to password headaches! The UK's National Cyber Security Centre now recommends passkeys as a user-friendly alternative that provides stronger resilience, making it easier to log in securely.

Analyst 207
Smartphone screen shows notification panel with one deleted alert still visible.

Apple Fixes iOS Flaw That Preserved Deleted Signal Notifications

Apple has fixed a frustrating iOS flaw that was causing deleted Signal notifications to stick around, and you can get the solution by updating your iPhone or iPad to the latest software version. The update addresses a logging issue that allowed deleted notifications to be retained on the device.

Analyst 207
Naval shipbuilding facility with podium in foreground.

Vought Targets Shipbuilders with OMB Rebuke at Sea Air Space

In a stunning move, Office of Management and Budget chief Russel Vought took aim at the shipbuilding industry during the Navy League's Sea Air Space conference, delivering a sharp rebuke that made headlines. His bold intervention marked a dramatic close to the annual gathering.

Analyst 207
US Navy ship in a bustling port with industrial buildings and workers.

US Navy Faces Sustained Strain as Industrial Base Lags

The US Navy is buckling under the weight of soaring demands with a dwindling workforce, sparking concerns about its ability to keep pace. With its fleet aging and the defense industrial base struggling to keep up, the pressure is on to find a solution.

Analyst 207
Modern cruise missile on pedestal, lit by soft daylight, with blurred crowd in background.

CoAspire Unveils Extended-Range Cruise Missile with Tomahawk-Like Capabilities

CoAspire has just unveiled the RAACM-ER, an extended-range cruise missile boasting a range of over 1,000 nautical miles and game-changing capabilities that rival the renowned Tomahawk missile. This cutting-edge weapon was introduced at Sea-Air-Space 2026, showcasing CoAspire's innovative approach to modern missile technology.

Analyst 207
Formal Pentagon setting with podium and subtle Navy presence in background.

Navy Secretary Phelan Departs Pentagon Amid Iran Blockade

In a sudden move, Navy Secretary John C. Phelan is leaving his post, effective immediately, as the Navy maintains a historic blockade of Iranian ports. Undersecretary Hung Cao steps in as acting secretary, following Phelan's swift departure from the Pentagon.

Analyst 207
The Supreme Court building exterior with people on the steps and a flag in the foreground.

Supreme Court Weighs Limits on Geofence Warrants

The Supreme Court is set to tackle a pressing question: do geofence warrants, a relatively new law enforcement tool, overstep constitutional boundaries? This high-stakes case, Chatrie v. The United States, could have far-reaching implications for digital privacy and police power.

Analyst 207
Container ship with bridge damage in Strait of Hormuz, with patrol boat in background.

Iran Escalates Ship Attacks in Strait of Hormuz

A container ship narrowly escaped disaster in the Strait of Hormuz after an Iranian gunboat fired on it, causing significant damage to the bridge, but thankfully no injuries or environmental harm. The alarming incident is the latest escalation in a series of attacks in the region, heightening tensions in this critical waterway.

Analyst 207
Government official stands in front of high-tech control room with multiple blank screens.

Trump Names Execs to Lead Space Force Acquisition, NRO

President Trump has nominated two top defense executives, Erich Hernandez-Baquero and Roger Mason, to lead major US space acquisition and reconnaissance organizations. This move comes as the Space Force is set to receive a massive 342% funding boost to $19.1 billion for procurement in fiscal 2027.

Analyst 207
Empty congressional hearing room with vacant chair and podium.

CISA Nominee Plankey Withdraws Amid Senate Gridlock

Sean Plankey, the nominee to lead the Cybersecurity and Infrastructure Security Agency, has withdrawn his nomination, citing Senate gridlock that had stalled his confirmation for 13 months. In a letter, he asked President Trump to remove his nomination, expressing support for the department's leadership.

Analyst 207