Skip to main content

Tag: emerging threats

4860 articles

Law firm's reception desk with phone, notepad, and pen, and blurred office workers or files in the background.

Silent Ransom Group Exploits Law Firms with Fake IT Support Scams

Law firms are being targeted by the Silent Ransom Group through clever fake IT support scams, putting sensitive client information at risk. This sophisticated attack starts with innocent-looking invoice emails that trick victims into calling a phone number, initiating a chain of events that can lead to devastating consequences.

Analyst 207
Cluttered router configuration room with networking equipment and devices scattered across shelves and tables.

C0XMO Botnet Exploits DD-WRT Flaw to Spread, Disrupts Rival Malware

Meet C0XMO, a highly sophisticated botnet malware that's disrupting the status quo with its advanced architecture and modular design, allowing it to spread rapidly by exploiting flaws like the DD-WRT vulnerability CVE-2021-27137. Its operators can easily update and adapt the malware to launch devastating DDoS attacks.

Analyst 207
KJ-700 airborne warning and control aircraft in flight with prominent radar arrays against a clear blue sky.

China Expands AWAC Fleet with Advanced KJ-700 Radar Platform

China's latest KJ-700 Radar platform is a game-changer, boasting not two, but four side-looking airborne radars that supercharge its airborne warning and control capabilities. This upgraded variant has been spotted with two AESA panels behind each wing and two additional panels ahead, marking a significant leap forward.

Analyst 207
Person working on laptop in minimalist office with blurred screen, focused expression.

OpenAI Bolsters ChatGPT with Lockdown Mode to Curb Data Exfiltration Risks

OpenAI is stepping up ChatGPT's security game with Lockdown Mode, a powerful setting that limits connections to the web and external services to prevent data exfiltration - a game-changer for those handling sensitive information. This advanced feature is now rolling out to eligible accounts, offering stricter protection guarantees.

Analyst 207
A WordPress dashboard screen with a cracked laptop keyboard in the foreground, symbolizing site vulnerability.

Hackers Exploit Everest Forms Pro Flaw to Hijack WordPress Sites

More than 29,300 attempted hacks have been blocked by Wordfence, revealing a surge in automated attacks exploiting a critical flaw in the Everest Forms Pro plugin, tracked as CVE-2026-3300. This alarming number highlights the urgent need for WordPress site owners to safeguard against this vulnerability.

Analyst 207
Armored vehicles maneuver across a vast, open plain in a military exercise.

Armor Tactics Evolve as FPV Drones Redefine Battlefield Dynamics

The online debate rages on: could a US Armored Division take down a PLA combined-arms brigade in a showdown on open plains? But the truth is, geography and logistics play a much bigger role in battle strategy than fantasy matchups.

Analyst 207
Networked server equipment and cabling in a brightly-lit data center with a blurred background.

CISA Flags SolarWinds Serv-U Flaw as Actively Exploited

A critical flaw in SolarWinds Serv-U is being actively exploited, allowing attackers to crash the service with a specially crafted POST request - no authentication required. This denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered by a simple HTTP POST request with a malicious Content-Encoding header.

Analyst 207
Smart TV on a media console in a living room with subtle hints of a vast network connection in the background.

Free Apps Turn Smart TVs Into AI Web-Scraping Proxies

Free apps can secretly turn your smart TV into a powerful tool for web scraping, unknowingly contributing to a massive residential proxy network of over 400 million IPs. This startling reality raises questions about consumer data and the hidden use of their devices.

Analyst 207
GitHub repository page on laptop screen with error message and blurred software development workspace background.

Miasma Worm Targets Microsoft GitHub Repositories in Supply Chain Attack

GitHub has taken swift action, disabling access to 73 Microsoft repositories across four organizations after a sneaky supply chain attack by the Miasma Worm compromised code on the platform. The disruption was triggered when the malware targeted Microsoft's GitHub repositories, prompting site-wide warnings and restricted access.

Analyst 207
Laptop screen displays code editor with blurred background of software development facility.

AI Agent Exposes 21 Zero-Days in Widely Used FFmpeg Library

In a single, remarkable run, an AI-powered security agent uncovered 21 zero-day vulnerabilities in the widely-used FFmpeg library, a feat that cost just $1,000 and showcases the incredible potential of autonomous security testing. The agent scanned 1.5 million lines of code to produce these groundbreaking findings.

Analyst 207
University career services area with students and laptop.

Oxford Uni Student Data Breached Through Career Platform

Oxford University student data has been breached once again, this time through a career platform compromise, leaving records exposed. The incident is a separate attack from a break-in that occurred just last month.

Analyst 207
Network equipment and router on a rack with technician checking a laptop in the background.

Cisco SD-WAN Manager Flaw Actively Exploited

Cisco is warning of a high-severity vulnerability in its Catalyst SD-WAN Manager that allows attackers to execute commands as root, and it's already being exploited by hackers. This flaw, rated 7.8 on the CVSS scale, could give attackers control over your system if they're able to upload a malicious file.

Analyst 207
Factory-new MQ-9 Reaper drone centered on a neutral background in soft daylight.

USAF Scrambles to Buy Scarce MQ-9 Reapers After Heavy Losses

The US Air Force is on a mission to replenish its fleet of MQ-9 Reapers, and it's turning to General Atomics for help, with plans to buy several unused MQ-9A Block 5 aircraft. The scramble comes as General Atomics reveals an alarmingly small inventory of just a handful of new MQ-9As available worldwide.

Analyst 207
Military personnel holds small attack drone with blurred base background.

Pentagon Accelerates Small Drone Procurement Amid Modern Battlefield Push

The Pentagon is fast-tracking the acquisition of small, one-way attack drones to equip every squad with a powerful new weapon, aiming to achieve this goal later this year. This push comes after Defense Secretary Pete Hegseth vowed to cut through red tape and unleash the full potential of the US drone industrial base.

Analyst 207
Aircraft with double arrowhead fuselage flies low over desert landscape at dusk.

Stealth Fighter Concept Resurfaces in Area 51 Mystery Aircraft Leak

A decades-old stealth fighter concept has resurfaced in discussions after a viral sighting near Area 51, sparking fresh interest in a mysterious aircraft that was once deemed too unstable for serious consideration. The unusual plane's distinctive double arrowhead design was caught on thermal footage near Groom Lake, leaving many to wonder about its true purpose.

Analyst 207
US naval vessel underway in Strait of Hormuz with clear view of surrounding waters and distant coastline.

US Forces Intercept Iranian Drones Over Strait of Hormuz

US forces have intercepted and shot down four Iranian drones heading towards the Strait of Hormuz, swiftly responding to an immediate threat to regional maritime traffic. The bold move also included targeted strikes on Iranian coastal radar sites to prevent further attacks.

Analyst 207
Researchers in lab coats work in a modern laboratory with a mix of old and new architecture.

US Research Security Landscape Evolves Amid Foreign Exploitation Fears

Join a live webinar on June 24, 2026, to explore how the Pentagon's new emphasis on research security is transforming the way universities, government agencies, and institutions protect against foreign exploitation. Earn 1 CPE credit while learning how to bolster defenses for basic and applied research in a rapidly evolving security landscape.

Analyst 207
Security researcher at laptop workstation with blurred screen, conveying tension.

Microsoft Revives Vulnerability Disclosure Debate with Researcher Crackdown

Microsoft is stirring up controversy in the vulnerability disclosure debate, clashing with a security researcher over the responsible handling of zero-day vulnerabilities. The tech giant's strong response, including threats of legal action, has sparked heated discussion on coordinated disclosure.

Analyst 207
Formal podium in conference room with cityscape visible through tall windows.

US Defense Chief Misses Chance to Bolster Taiwan Support

US Secretary of Defense Pete Hegseth's recent speech at the Shangri-La Dialogue in Singapore left many wondering why he didn't seize the opportunity to reaffirm US support for Taiwan, a crucial moment to make a strong statement in the region. By choosing not to directly address Taiwan, Hegseth missed a chance to show strength and clarity in the face of growing uncertainty.

Analyst 207
Network device with cables on a rack in a well-lit technology room.

Palo Alto Networks Warns of Active PAN-OS Vulnerability Exploitation

Palo Alto Networks has sounded the alarm on a critical PAN-OS vulnerability, CVE-2026-0257, that's being actively exploited by threat actors to bypass authentication and gain unauthorized access to VPN connections. This security gap could allow attackers to circumvent controls and initiate their own VPN sessions, putting your network at risk.

Analyst 207
Blurred computer workstation and file cabinet in a brightly-lit office interior, with a cityscape visible through the window.

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics

Beware of UNC3753, a notorious group that's been stealing sensitive data from US law firms and other professional services, using clever vishing tactics and lightning-fast intrusions to extort their victims. In some cases, they can go from initial contact to data theft in under an hour.

Analyst 207
Person in a corporate office hallway holds a small device, looking concerned.

Extortion Gang Exploits Corporate Networks with In-Person Visits

Meet UNC3753, a notorious extortion gang that's taking corporate hacking to a whole new level - from deceitful phone calls to in-person visits, where they show up at companies' doorsteps with thumb drives, targeting dozens of US banks, law firms, and professional services firms in just a few short months. Their tactics have evolved from fake emails to help-desk calls and now, brazen doorstep drop-offs.

Analyst 207
Laptop screen displays rogue login prompt with generic logo and username field.

Polyfill Compromise Targets Major Websites with Rogue Login Prompts

Major websites, including Toshiba and Muji, have been compromised by a rogue login prompt scam through polyfill.io, tricking visitors into entering sensitive information. If you encountered the fake sign-in screen, be sure to cancel and change your password to protect your account.

Analyst 207
Server room with networked equipment and a single server in the foreground.

Hackers Actively Exploit SolarWinds Serv-U Flaw to Crash Servers

SolarWinds has issued an emergency hotfix to address a critical flaw in its Serv-U file transfer product, which hackers are actively exploiting to crash servers with specially crafted POST requests. A denial-of-service vulnerability, tracked as CVE-2026-28318, can be triggered without authentication, posing a significant threat to users.

Analyst 207