Skip to main content

Tag: emerging threats

4865 articles

IT staff members in a server room look at a laptop with urgency, surrounded by rows of servers and racks near a large window.

India's CERT-In Mandates Swift Patching for Exposed Flaws

CERT-In is urging organizations to act fast to contain cyber threats, setting a tight 12-hour deadline to patch known vulnerabilities in critical, internet-facing systems. This swift response aims to combat the accelerating threat of AI-driven cyber-attacks.

Analyst 207
Concerned office worker examines laptop with blurred screen amidst office supplies and city view.

Iranian Hackers Deploy AI-Backed MiniFast Backdoor via Phishing and SEO Poisoning

Iranian hackers have escalated their cyber attacks, leveraging AI-powered tools to craft malware and targeting key sectors like aviation, defense, and telecommunications across the US, Europe, and the Middle East. Their sophisticated tactics, including phishing and SEO poisoning, have allowed them to spy on organizations with alarming speed and efficiency.

Analyst 207
US airport terminal with check-in counter and departure board, laptops and phone on counter.

Iran-Linked Hackers Target US Aviation with Sophisticated Phishing and SEO Poisoning

Meet Nimbus Manticore, an Iran-linked hacking group that's back with a vengeance, using clever phishing and SEO poisoning tactics to target the US aviation industry in a series of sophisticated attacks. Their latest campaign, which ran from February to April 2026, marked a significant expansion into aviation, defense, and telecommunications.

Analyst 207
Large, empty government building interior with podium and blurred seal on wall.

CISA Mandates Patching of Exploited Drupal Vulnerability

The US Cybersecurity and Infrastructure Security Agency has issued a directive requiring federal agencies to patch a critical Drupal vulnerability, known as CVE-2026-9082, by May 27 to prevent devastating SQL injection attacks. This highly critical flaw allows hackers to exploit PostgreSQL-powered Drupal sites and gain unauthorized access to sensitive information.

Analyst 207
Rack-mounted servers in a server room with one server prominently displayed.

Microsoft Warns of Domain Controller Lookup Failures on Windows Server 2016

If you've installed the KB5087537 update on your Windows Server 2016 system, be aware that domain controller lookup may fail if your server hostname is exactly 15 characters long. This issue affects only those with 15-character hostnames, so check yours to see if you're impacted.

Analyst 207
7-Eleven store interior with disorganized papers near employee.

7-Eleven Data Breach Compromises 185,000 People's Personal Info

A recent 7-Eleven data breach has put the personal info of 185,000 people at risk, exposing sensitive details like names, addresses, birthdays, and phone numbers. The breach, which occurred on April 8, 2026, is still shrouded in mystery, with 7-Eleven only confirming that certain systems storing franchisee documents were compromised.

Analyst 207
Laptop on student desk shows login screen in bright campus library setting.

KnowledgeDeliver LMS Flaw Exploited to Deploy Malware

A security flaw in the KnowledgeDeliver LMS, known as CVE-2026-5426, was exploited by a threat actor to inject malicious code and infect users visiting the site. This vulnerability was caused by a predictable secret in the system's web.config file, allowing attackers to execute remote code.

Analyst 207
US military personnel handles portable counter-drone system outdoors.

Pentagon Taps Perennial Autonomy for $500M Counter-Drone Contract

The Pentagon has taken a major stand against the growing threat of drones, awarding a $500 million contract to Perennial Autonomy for cutting-edge, AI-powered counter-drone systems. This game-changing deal is part of the US military's broader Drone Dominance initiative to stay ahead of the curve in modern warfare.

Analyst 207
Military drone on desert terrain, angled for deployment, with abstract operation details in foreground.

USAF Deploys Upgraded ULTRA Surveillance Drones to Middle East

The US Air Force has taken a major leap forward with its ULTRA Surveillance Drones, successfully completing a 60-hour flight at 25,000 feet and 100 knots - now, a turbocharged variant is set for operational testing in the Middle East. This next phase will see the drone put through its paces in a real-world setting within US Central Command's area of responsibility.

Analyst 207
Large aircraft or naval vessel with four turboprop engines sits on a Chinese coastal pier.

China's 'Bohai Sea Monster' Emerges with Apparent Combat Capabilities

Newly surfaced images of China's mysterious Bohai Sea Monster reveal a surprising detail: four turboprop engines, each driving a three-bladed propeller, hinting at a more complex role and extended range than initially thought. This game-changing feature has analysts reevaluating the capabilities of this enigmatic craft.

Analyst 207
Drone flies over a power plant or industrial area, highlighting security risks.

Europe's Drone Defense Gap Exposes Critical Infrastructure Risks

Europe's critical infrastructure is left vulnerable due to a lack of clear governance and rules of engagement, despite having the technology to defend against drone threats. The absence of ownership and jurisdictional clarity hinders the deployment of drone defense systems where they're needed most.

Analyst 207
Law enforcement officers seize servers and equipment in a brightly-lit data center.

Dutch Authorities Disrupt Russian Cyber Operations, Seize 800 Servers

In a major blow to Russian cybercrime, Dutch authorities seized over 800 servers and arrested two individuals in a daring raid that cracked down on illicit online operations. The suspects, a 57-year-old Amsterdam resident and a 39-year-old from The Hague, were charged with violating sanctions law by aiding EU-sanctioned entities.

Analyst 207
Damaged KC-135 aircraft with shrapnel repairs and missing refueling boom on RAF Mildenhall airbase.

Damaged KC-135 Tanker Spotted at RAF Mildenhall Amid Post-War Repairs

A KC-135 tanker, bearing scars of a intense battle, has been spotted at RAF Mildenhall, its damaged airframe a testament to the high stakes of war, with makeshift repairs and a missing refueling boom telling a story of their own. Aviation photographer Andrew McKelvey captured striking images of the battered jet, revealing a patchwork of temporary fixes and shrapnel damage.

Analyst 207
Sleek modern military engineering setting featuring the GBP113A Rigid-Flexible Combination Bangalore Torpedo on a clean…

PLA Unveils Upgraded Bangalore Torpedo

Meet the GBP113A, a game-changing upgrade to the century-old Bangalore torpedo, now with a rigid-flexible combination design that lets it curve, snake, and blast its way into previously hard-to-reach areas. This innovative device delivers the same powerful punch as its predecessor, but with added maneuverability and flexibility.

Analyst 207
University computer lab workstation with laptop and papers, soft natural light from a nearby window.

SaaS Providers Face Trust Crisis After Canvas Breach

A massive breach of the Canvas learning management system has left 275 million users reeling, compromising student records and disrupting learning at over 8,800 institutions worldwide. The shocking incident has sparked a trust crisis for SaaS providers, raising urgent questions about security and data protection.

Analyst 207
Laboratory workbench with laptop and technical instruments in a bright, clean setting.

Anthropic Readies Restricted AI Model for Public Rollout

Anthropic is on the cusp of unveiling its game-changing Mythos model, a frontier AI that's poised to revolutionize code reasoning and autonomy with capabilities that far surpass its predecessors. This powerful tool could redefine the cyber landscape, giving a significant edge to those who harness its potential.

Analyst 207
People of diverse ages and backgrounds walk through a crowded Australian cityscape, some looking at smartphones, amidst…

Australia's Defence Strategy Lags in Information War Arena

Australia is losing ground in a different kind of battle – one of perception and understanding – where adversaries are manipulating what people believe to be true, eroding public trust and turning domestic audiences into a vulnerability in times of crisis. By shaping perceptions through information, our nation risks being left behind in the information war arena.

Analyst 207
Cluttered developer workstation with laptop, monitor, and notes, VS Code on screen.

Linux Flaws Expose Critical Infrastructure to Root Command Execution

GitHub confirmed that a compromised employee device, infected by a poisoned Nx Console VS Code extension, led to the theft of around 3,800 internal repositories, sparking swift action to contain the breach and protect sensitive data. The incident highlights the vulnerability of even the most secure systems to supply chain attacks.

Analyst 207
Laptop on office desk with papers and supplies, subtle hint of phishing attempt nearby.

FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Accounts

Beware of Kali365, a sneaky phishing service that's hijacking Microsoft 365 accounts by exploiting a legitimate authentication flow - and it's happening fast, with the platform emerging as recently as April 2026. This clever trick uses a short code to trick victims into handing over control of their accounts.

Analyst 207
Network operations center interior with daylight streaming in through a large window and analysts at console stations…

Agentic AI Tames Network Detection's Alert Firehose

Imagine sifting through 847 network anomalies daily - that's like trying to find a needle in a haystack! With agentic AI triage, that overwhelming number is dramatically reduced to just 4 prioritized detections, complete with the evidence and suggested actions analysts need to take swift and effective action.

Analyst 207
Laptop screen displays a blurred CMS interface with a cityscape background.

Ghost CMS Flaw Exploited to Hijack Over 700 Sites in ClickFix Attacks

Over 700 websites were hijacked in a massive campaign that exploited a critical Ghost CMS vulnerability, turning legitimate pages into gateways for Windows malware. This alarming attack was made possible by CVE-2026-26980, an SQL injection flaw with a near-perfect CVSS score of 9.4.

Analyst 207
Brightly-lit financial sector setting with computer workstation in background.

Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks

The notorious Lazarus Group has unleashed a sneaky new attack tool, a memory-only Remote Access Trojan (RAT), targeting the financial sector with cunning precision. This stealthy malware, known as RemotePE, is just the latest weapon in the group's arsenal, and it's being used to infiltrate and manipulate its victims.

Analyst 207
Modern office setting with laptop and smartphone on a tidy desk, hinting at a cyber threat.

FBI Warns of Kali365 Phishing Kit's OAuth Token Heist

The FBI has sounded the alarm on Kali365, a phishing-as-a-service platform that's making it easy for even novice hackers to steal Microsoft 365 login credentials and bypass security measures like multifactor authentication. This subscription-based service, mainly spread through Telegram, provides attackers with AI-generated phishing lures, campaign templates, and real-time tracking tools to target individuals and organizations.

Analyst 207
Formula 1 fan with smartphone displaying suspicious live stream amidst crowd and counterfeit merchandise.

Fraudsters Target F1 Fans with Fake Streams, Counterfeit Merch Scams

When it comes to motorsports, speed is a double-edged sword - while the action is fast-paced and thrilling, it also creates opportunities for scammers to strike, as noted by Bogdan Botezatu, senior director of threat research at Bitdefender. Cybercriminals are now targeting F1 fans with fake streams and counterfeit merch scams, making it essential for fans to stay vigilant.

Analyst 207