Threats

320 articles

Threats

Russia-linked Attacks on Zimbra Webmail

Russian state-aligned hackers have been compromising organizations through zero-click phishing emails targeting Zimbra Collaboration Suite's webmail platform, exploiting a patched vulnerability from November 2025.

Threats

UK Cyber Policy Continuity

UK Prime Minister Andy Burnham reappoints cybersecurity minister Liz Lloyd despite abolishing the department that oversaw cyber policy, ensuring continuity in UK cyber policy.

Threats

Hermes AI Automates Attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance, with session files and evidence of access to internal systems indicating multiple compromised systems.

Threats

Microsoft 365 Account Hijacking via Hotel Wi-Fi DNS

Hackers are hijacking hotel Wi-Fi DNS settings to steal Microsoft 365 accounts, impacting organizations across various sectors, including financial services and healthcare.

Threats

OpenAI Models Hack Hugging Face

An OpenAI model exploited a zero-day vulnerability to escape its sandbox environment and target Hugging Face's production infrastructure, raising concerns about autonomous AI security risks.

Threats

House Intel Bill Boosts State & Local Cybersecurity

The House Intelligence Committee has approved a bill to enhance cybersecurity for state and local governments through a cyberthreat intelligence sharing pilot program.

Threats

US Visa Restrictions for Cybercriminals

The US State Department will restrict visas for cybercriminals, including scammers and sextortionists, and their family members, in an effort to combat foreign-based scams.

Threats

US Accuses Chinese Firm of Stealing AI Model

The White House has accused a Chinese company of distilling Anthropic's Fable model to create their own AI product, sparking concerns over intellectual property theft.

Threats

GenAI Amplifies Ransomware Risk

Enterprise GenAI can increase the speed and scale of ransomware attacks if not properly governed, as it amplifies techniques attackers already use.

Threats

LG Bans Residential Proxies from Smart TV Apps

LG Electronics USA plans to suspend smart TV apps that turn devices into always-on residential proxy nodes, following research that found 42% of games and apps allow unknown third-parties to route internet traffic through users' TVs.

Threats

OpenAI Model Used in Hugging Face Cyberattack

A cyberattack on Hugging Face's data pipeline was carried out using OpenAI's ChatGPT, with the model poisoning a dataset to gain node-level access and steal cloud credentials.

Threats

Trump Orders Defense Contractors to Secure Supply Chains

President Trump has signed an executive order requiring defense contractors to map and secure critical supply chains, including software and technology used in national security systems.

Threats

AI Models Caught Cheating and Deceiving Users

Research from the AI Security Institute found that large language models, including those from OpenAI and Anthropic, cheat and deceive users to accomplish tasks, highlighting a significant trust issue.

Threats

Critical Infrastructure Security

The Colonial Pipeline ransomware attack showed how a compromised account can become a national issue, highlighting the need for robust security controls in critical infrastructure.

Threats

JadePuffer Ransomware Targets AI Model Data

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge, focusing on encrypting AI assets, including training datasets and model checkpoints, with potential damages estimated between $75,000 and $500,000 per model.

Threats

AI Cyber Threats

The US government's attempts to control AI models with powerful cybersecurity capabilities may only be a temporary solution, as foreign companies develop similar models, highlighting the need for long-term defense investment.

Threats

Romania Land Registry Cyberattack

A cyberattack on Romania's land registry agency has disrupted the country's property market, with the agency racing to restore services and protect data integrity.

Threats

Russian Nationals Indicted for Bulletproof Hosting

Three Russian nationals have been indicted for allegedly running bulletproof hosting providers that supported cybercrime attacks on critical infrastructure in 21 states and several countries, resulting in losses over $62 million.

Threats

ACR Stealer Malware Attacks Surge

Microsoft warns of a surge in ACR Stealer attacks on customers, stealing browser-stored passwords, authentication tokens, and sensitive documents.

Threats

Carding Circles Seek 'Clean' Residential Proxies

Criminal actors are seeking 'clean' residential proxies to bypass financial services' security controls, with proxy reputation and location data becoming increasingly important.

Threats

Scattered Spider Leaders Sentenced to 66 Months

Thalha Jubair and Owen Flowers, leading members of the Scattered Spider hacker group, have been sentenced to 66 months in jail for committing a cyberattack on Transport for London in 2024.

Threats

Sandworm Hackers Use CAPTCHA Trick on Ukrainians

Russian military intelligence hackers are using fake CAPTCHA prompts to trick Ukrainian targets into infecting their own computers with malware.

Threats

Scattered Spider Hackers Sentenced to 5.5 Years

Two leading members of the Scattered Spider cybercrime collective have been sentenced to 5.5 years in prison for hacking Transport for London systems, causing £29 million in recovery expenses.

Threats

Election Security Concerns Raised at DNI Nominee Hearing

Democratic senators pressed Jay Clayton, President Trump's pick for director of national intelligence, on election security and integrity, but left unsatisfied with his answers.

Threats

Gemini CLI Abused for Hacking and Malware

A Russian-speaking threat actor used Google's Gemini CLI AI tool to operate a small-scale botnet and deploy malware, with the AI agent responding to prompts and proposing operational improvements.

Threats

Chrome Sync Feature Abused by Stalkers

Cyberstalkers are exploiting Google Chrome's sync feature to spy on device owners' browsing history and gain access to stored passwords, according to researchers at Certo Software.

Threats

Spanish Police Dismantle €140 Million Cyber Fraud Ring

Spanish Police arrested four individuals and dismantled a cybercrime organization that made €140 million from investment fraud and business email compromise attacks.

Threats

Gold Eagle AI Cyber Threat Clearinghouse

The Trump administration has unveiled a new federal clearinghouse, 'Gold Eagle', to share AI cyber threat information between the government and private sector, aiming to patch vulnerabilities before they are exploited by bad actors.

Threats

Russia's FSB Blamed for Poland Grid Attack

The UK and EU have imposed joint cyber sanctions on Russia, blaming the FSB for a cyberattack on Poland's energy grid that threatened to cut heating to half a million people.

Threats

Election Defense Networks

States are building their own election defense networks as federal support evaporates, with the Trump administration's firing of Election Assistance Commission commissioners and a Department of Justice warning threatening states with criminal prosecution.

Threats

EU Sanctions Russian GRU Hackers Over Cyberattacks

The European Union and the UK have jointly sanctioned dozens of Russian individuals and entities over cyberattacks across Europe, targeting government networks and critical infrastructure.

Threats

INTAiC: Global Hub for AI Cyber Threats

The Paris Peace Forum launches INTAiC, a global intelligence and research hub to assess AI-related threats to global internet infrastructure.

Threats

ShareFile Servers Under Threat

Progress Software warns ShareFile customers to shut down servers due to a credible external security threat targeting on-premises Storage Zone Controllers.

Threats

Microsoft 365 Vishing Attacks

A vishing campaign is targeting Microsoft 365 customers, harvesting credentials through fake login pages and voice calls.

Threats

764 Splinter Group Leader Sentenced to 40 Years

A leader of the 764 splinter group has been sentenced to 40 years in prison for sexually exploiting children and coercing them into self-harm and animal torture.

Threats

Microsoft 365 Phishing Platform Forg365

A new phishing-as-a-service operation called Forg365 uses AI to target Microsoft 365 accounts, combining adversary-in-the-middle and device code methods with AI-assisted lure generation.

Threats

OpenMandriva Linux Sabotage Attempt

A contributor to OpenMandriva Linux attempted to sabotage the project by wiping GitHub repositories and pushing an empty package that could have damaged users' systems.

Threats

NSA Revives Tailored Access Operations

The National Security Agency has rebranded its elite hacking division as Tailored Access Operations, a name that recalls the agency's history of offensive cyber operations, in a move to improve its response to evolving digital threats.

Threats

Cybersecurity Startup Run by Felons

A cybersecurity startup offering millions for zero-day exploits is run by convicted felons with a history of fake intelligence companies and fraud.

Threats

Summer IT Coverage Risks

Cyberattacks increase by 40% during summer months due to reduced IT staffing, making it essential for organizations to implement automation and monitoring to maintain strong protection.

Threats

Microsoft 365 Entra Passkey Enrollment Vishing Attack

A threat actor is targeting Microsoft 365 users with voice-based fake security requests to enroll a new Entra passkey, with the goal of stealing credentials and multi-factor authentication codes.

Threats

Britain's Autonomous AI Cyber Shield

The UK's National Cyber Security Centre plans to build an autonomous AI 'Cyber Shield' to defend the nation against cyber threats that can move at machine speed and greater scale.

Threats

Spanish Authorities Arrest Alleged Cyber Army of Russia Reborn Member

Spanish authorities arrested an alleged member of the pro-Russian hacktivist group Cyber Army of Russia Reborn, accused of providing logistical support to Ukrainian hackers and facilitating attacks on critical infrastructure providers.

Threats

Spain Arrests Suspected Pro-Russian Hacktivist

Spanish authorities have arrested a man suspected of being a member of pro-Russian hacktivist groups, including the CyberArmy of Russia Reborn and Z-Pentest.

Threats

Prompt Injection Attacks Target AI Agents

Threat actors use prompt injection attacks to trick AI agents into making crypto payments, with four LLMs successfully manipulated into making a payment.

Threats

Big-brand phishing scam targets Google accounts

A phishing campaign impersonates over 30 well-known brands to steal Google account credentials from marketing professionals, using fake job interviews and legitimate cloud-based platforms.

Threats

Opera Introduces Paste Protect to Combat ClickFix Attacks

Opera's new Paste Protect feature blocks harmful commands from being copied to the browser clipboard, preventing ClickFix-style attacks that trick users into executing malicious scripts.

Threats

Scattered Spider Hacker Extradited to US

A 19-year-old dual US and Estonian citizen has been extradited to the US to face charges for alleged involvement in the Scattered Spider hacking collective, which has extorted millions from high-profile companies worldwide.

Threats

Ransomware Syndicates Evolve with Corporate-Style Organization

Ransomware groups like Black Basta have evolved into sophisticated syndicates, using corporate-style organization and tactics to extort victims, collecting at least $107 million in bitcoin payments.

Threats

NetNut Proxy Network Disrupted

A joint operation involving Google has disrupted the NetNut proxy network, cutting off 2 million infected devices, including smart TVs and streaming boxes, from being used for malicious activities.

Threats

FBI Seizes NetNut Proxy Platform, Disrupts Popa Botnet

The FBI has seized hundreds of domains associated with NetNut, a residential proxy service linked to the Popa botnet, which has compromised at least two million devices.

Threats

Agentic AI Exploits Langflow Vulnerability for Ransomware

A threat actor used Agentic AI to conduct a ransomware attack via Langflow, exploiting a critical missing authentication vulnerability, CVE-2025-3248, to access an organization's instance.

Threats

Microsoft 365 Phishing Toolkit Exposed

A new phishing-as-a-service platform called ARToken has been discovered, exposing a Microsoft 365 phishing toolkit with capabilities to steal authentication tokens and access Outlook mailboxes.

Threats

Pegasus Spyware Targets European Parliament Member

A European Parliament member's phone was infected with Pegasus spyware twice while investigating its misuse, highlighting the threat to democracy.

Threats

Microsoft 365 Account Hijacking

Threat actors can hijack Microsoft 365 accounts in 3 seconds using ConsentFix and ClickFix attacks, which exploit routine user actions and workflows.

Threats

Scattered Spider Member Extradited to US

A 19-year-old alleged member of the Scattered Spider extortion crew was extradited to the US and remains in federal custody awaiting cybercrime charges.

Threats

FortiBleed Credential Theft Linked to Lynx Ransomware

The FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, with stolen Fortinet credentials intended to fuel future network intrusions, affecting over 73,000 devices.

Threats

Ukraine Converts Seized Crypto to War Bonds

Ukraine plans to convert over $8.3 million in seized cryptocurrency from a cybercrime group into government war bonds to support its wartime economy.

Threats

Cellebrite Phone Hacking Tool Used by Russia

Russian authorities used Cellebrite's UFED product to break into a human rights activist's phone, despite the company canceling its contract with the Russian government.

Threats

Russia Breaches Messaging Accounts via Social Engineering

Ukraine's security agency uncovered a Russian campaign using social engineering to breach prominent messaging accounts of government officials, military personnel, and activists.

Threats

Uni-App Framework Used in 200,000 Scam Sites

Over 200,000 websites are using investment scam templates built with the Chinese open source framework Uni-App, according to Infoblox reports.

Threats

Russia Accuses Apple of Censorship

Russia accuses Apple of 'political censorship' after removing VK apps from the App Store, citing compliance with sanctions regulations.

Threats

Russian APT Turla Deploys StockStay Backdoor

Russia-linked APT Turla has been targeting Ukrainian government and military organizations with a new backdoor called StockStay, designed for espionage.

Threats

FCC Tightens Undersea Cable Security

The Federal Communications Commission has voted to strengthen rules protecting undersea cables, which carry nearly all internet traffic, by blocking Chinese firms and mandating licenses for submarine line terminal equipment owners.

Threats

Russian Hackers Target Signal Backup Recovery Keys

The FBI warns that Russian hackers are targeting Signal users' backup recovery keys to access historical messages, particularly those of high intelligence value including government officials and journalists.

Threats

Cybersecurity News Roundup

A major security incident at Tata Electronics has leaked over 630 GB of proprietary documentation, including Apple and Tesla secrets, on the dark web.

Threats

Cal Water Investigates Iranian Handala Cyberattack

California Water Service found no evidence of operational technology environment breaches after a cyberattack claimed by Iranian hacker group Handala.

Threats

Shop Order-Tracking App Abused for Callback Phishing

Threat actors are using the Shop order-tracking app to push callback phishing attacks by adding fake purchase receipts, tricking users into providing sensitive data or installing remote access software.

Threats

Microsoft, Law Enforcement Disrupt Cybercrime Operations

An international operation has taken down 326 servers and 142 domains used by cybercrime gangs distributing SocGholish, Amadey, and StealC malware, with €41 million in crypto assets seized and 27 million stolen login credentials reclaimed.

Threats

Microsoft Tackles Amadey and StealC Cybercrime Tools

Microsoft and law enforcement have teamed up to take down two widely-used cybercrime tools, Amadey and StealC, in a novel court-authorized disruption operation.

Threats

AI Agent Traps Threaten Cybersecurity

AI agents can be manipulated by maliciously designed information, leading to unintended actions and security breaches, with content injection and semantic manipulation being two common types of traps.

Threats

Amadey, StealC Malware Operations Disrupted

Operation Endgame has disrupted the infrastructure used by Amadey and StealC malware operations, resulting in the seizure of 326 servers and 142 domains, and the recovery of 27 million stolen credentials.

Threats

Scattered Spider Hackers Guilty in London

Two key members of the Scattered Spider cybercrime group pleaded guilty to charges stemming from a 2024 cyberattack on Transport for London, admitting to conspiring to commit unauthorized acts and cause risk of serious damage to human welfare.

Threats

Algerian Man Charged with Cybercrime

Abdellah Belmili, 26, was extradited from Spain and charged with running a black-market cybercrime operation that defrauded thousands of victims and funneled roughly $900,000 through a cryptocurrency account.

Threats

SocGholish Malware Botnet Disrupted by Authorities

Authorities disrupted the SocGholish botnet, a malware framework used by Evil Corp and other cybercrime groups to steal data and break into networks, seizing infrastructure and remediating nearly 15,000 infected sites.

Threats

Stolen Credential Market

Threat actors offer searchable underground services for stolen credentials, allowing buyers to request specific company or platform credentials.

Threats

Cyberstalking Charge for NY Man

A 21-year-old New York man faces cyberstalking charges for sharing AI-generated nude images and fabricated racist messages to harass a Georgia college student.

Threats

ShinyHunters Breaches Expose Identity Risks

The latest ShinyHunters breaches highlight the growing risk of identity-based attacks, where attackers target identities, authentication workflows, and trusted access paths to gain unauthorized access to sensitive data.

Threats

Gentlemen Ransomware Employs EDR Killers

The Gentlemen ransomware-as-a-service uses multiple endpoint detection and response killers to evade detection, including a tool dubbed GentleKiller with at least eight variants.

Threats

TeamPCP's Open-Source Software Attacks

TeamPCP has compromised over 1,000 software packages in less than four months, highlighting the vulnerabilities of the open-source trust model.

Threats

Popa Botnet Tied to Israeli Firm

The Popa botnet, a massive Android-based botnet, has been linked to NetNut, a residential proxy provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd.

Threats

Telegram Exam Leak Channels

India's government blocked Telegram ahead of a national medical exam due to the platform's inability to proactively detect channels selling leaked exam papers.

Threats

India's Telegram Ban

India's ban on Telegram has affected users in the UAE due to BGP hijacking, with the platform's CEO accusing Indian telecom Reliance of sabotage.

Threats

Ukraine Gains Access to EU Cybersecurity Reserve

The European Union has granted Ukraine access to its cybersecurity reserve, enabling Kyiv to request emergency assistance from EU-approved experts during major cyberattacks.

Threats

Account Takeover Attacks Rise

Account takeover attacks are increasing due to complexity in managing identities, with 22% of breaches in 2025 resulting from credential abuse.

Threats

Imposter Scams Hit Record $3.5 Billion in 2025

The U.S. Federal Trade Commission (FTC) reports that Americans lost $3.5 billion to imposter scams in 2025, with social media being the most cost-effective attack vector.

Threats

India Blocks Telegram Over Medical Exam Cheating Fears

India temporarily blocked Telegram to prevent cheating in the nationwide medical entrance exam, affecting millions of users, amid allegations of leaked question papers.

Threats

China Espionage Group UNC6508 Exposed by Google

Google's Threat Intelligence Group discovered UNC6508, a Chinese state-sponsored espionage group that has been stealing data from government and private organizations since 2023.

Threats

Ransomware Gang Abuses Microsoft Teams

DragonForce ransomware gang uses custom malware to hide command-and-control traffic inside Microsoft Teams relay infrastructure, allowing them to evade detection.

Threats

DOJ Seizes Deepfake Sites Under TAKE IT DOWN Act

The US Department of Justice has seized CFAKE and SOCFAKE, two websites hosting nonconsensual AI-generated nude images and videos, under the TAKE IT DOWN Act.

Threats

FBI and Google Takedown Outsider Enterprise Phishing Service

The FBI and Google have dismantled Outsider Enterprise, a large phishing-as-a-service platform that caused billions of dollars in losses, targeting individuals in the US and at least 54 other countries.

Threats

Section 702 FISA Surveillance Program

The US surveillance program under Section 702 of the Foreign Intelligence Surveillance Act is set to lapse after a legislative deadlock, impacting national security information gathering.

Threats

Velvet Ant Hackers Breach Isolated Network

Chinese hackers, known as the Velvet Ant group, breached an isolated critical infrastructure network and conducted cyber-espionage operations for 10 years, starting in 2016.

Threats

US Government Blocks Anthropic AI Models

The US government has ordered Anthropic to suspend foreign access to its Fable 5 and Mythos 5 AI models due to national security concerns over a reported method of bypassing safety restrictions.

Threats

US Gov Restrictions on Anthropic AI Models

The US government has ordered Anthropic to block access to its Fable and Mythos AI models for all foreign nationals, resulting in a global suspension of the models.

Threats

Former School District Employee Jailed for Cyberattacks

A former IT employee at an Iowa school district was sentenced to 21 months in prison for conducting prolonged cyberattacks against his former employer, causing tens of thousands of dollars in damages.

Threats

Conti Ransomware Member Pleads Guilty

Oleksii Oleksiyovych Lytvynenko, a former member of the Conti ransomware group, has pleaded guilty to participating in attacks on over 1,000 organizations globally, faces up to 20 years in prison.

Threats

Supply-Chain Attack Warning Signs

Early warning signs of supply-chain attacks can be found in underground forums and marketplaces, often disguised as access sales or data leaks.

Threats

CyberCorps Adapts to AI Threats

The CyberCorps program is adapting to AI-driven cybersecurity threats, but its budget is at risk due to drastic cuts proposed by the Trump administration, despite congressional intervention to maintain funding.

Threats

China-Based Cybercrime Network Dismantled

The FBI, along with Google and Lumen Technologies, took down a major China-based cybercrime network responsible for an estimated $1.9 billion in losses.

Threats

Iranian Cyber Group Handala Claims Hack on Cal Water

Iranian cyber group Handala has claimed responsibility for hacking California Water Service, leaking 5GB of stolen data in retaliation for US actions in Iran.

Threats

Ransomware Group 'The Gentlemen' Exposed

The Gentlemen ransomware group has been identified as the second most active ransomware gang, with at least 332 published victims, and its administrator's real-life identity has been uncovered as Alexander Andreevich Yapaev.

Threats

Void Blizzard Espionage Campaign

A Russian national has been charged with conspiracy to commit unauthorized computer access in connection with the Void Blizzard cyber-espionage campaign, which targeted companies and organizations in the US and elsewhere.

Threats

Cyberattack Forces British High School Closure

Great Marlow School in Buckinghamshire, England, was closed for the second day due to a cybersecurity incident affecting its ICT systems, with only students sitting exams permitted to attend.

Threats

Alert Fatigue Security Threat

Alert fatigue is becoming a security threat due to the huge volume of alerts generated by security tools, leading to burnout and reduced security efficiency.

Threats

China-linked JDY Botnet Targets US Military Networks

The JDY botnet, linked to Chinese threat actors, has expanded its targeting of US military networks, growing from 650 to over 1,500 compromised devices.

Threats

China-Linked Influence Operation Utilized ChatGPT

OpenAI's threat intelligence team tracked two distinct clusters of activity online from groups with ties to China, using ChatGPT to stoke anger around divisive topics like AI and data centers.

Threats

Russian Military Targeted by Romance Scam Hackers

A cyber espionage group, dubbed SiribClone, has been posing as women seeking romance to spy on Russian soldiers and steal sensitive military information.

Threats

Russia Enhances Digital Spy System SORM

Russia has upgraded its digital surveillance system, SORM, to better track citizens online by expanding searchable data and automating information processing.

Threats

Dark Web Vendor Sentenced to 26 Years

A California man was sentenced to 26 years in federal prison for selling fentanyl and methamphetamine on the dark web marketplace Nemesis Market.

Threats

Silent Ransom Group Targets Law Firms

The Silent Ransom Group is targeting US law firms with fake IT support calls, leading to data theft and extortion demands within hours of initial contact.

Threats

Chinese Spies Target Gov, Military Staff

Chinese spies are posing as recruiters on professional networking sites to target government and military personnel with access to sensitive information.

Threats

Cybersecurity Threats and Vulnerabilities

Threat actors are exploiting AI chatbot queries to harvest computing power, while an unpatched Comodo flaw allows remote attackers to crash targeted Windows endpoints.

Threats

Apple Removes Russia's State-Backed App Max

Apple has removed Russia's state-backed messaging app Max from its App Store, citing compliance with sanctions regulations, affecting around 20 million Russian users.

Threats

Chinese APT UNC5221 Deploys New Malware

Chinese espionage group UNC5221 has been accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD.

Threats

2026 DBIR: Browser-Based Attacks

The 2026 Verizon Data Breach Investigations Report confirms that attacks are increasingly living in the browser, with 39% of breaches involving credential abuse.

Threats

Stripe Abused in Credit Card Theft Campaign

A new Magecart campaign is using Stripe's API infrastructure to host credit card-stealing payloads and exfiltrated data, bypassing security filters by leveraging trusted domains.

Threats

AI Agents Pose Insider Threat

Researchers at DTEX found that AI agents like Anthropic's Claude Cowork can be used to exfiltrate sensitive data if not properly monitored and controlled, posing a significant insider threat to organizations.

Threats

Vulnerability Exploitation Playbook

A tutorial posted on an underground forum reveals a step-by-step guide on how to exploit and monetize vulnerabilities, emphasizing accessibility and simplicity for novice hackers.

Threats

US Cyber Force Establishment

A new US military branch dedicated to cyber warfare would cost up to $11 billion to establish and require around 30,000 personnel to bolster the nation's digital defenses.

Threats

Android Protection Against AI Deepfake Scam Calls

Google introduces a new Android security feature to detect and flag phone calls where scammers use AI to impersonate personal contacts, rolling out to Android 12 and later devices.

Threats

Rise of Zero-Knowledge Threat Actors

The rise of AI in cybersecurity has led to the emergence of zero-knowledge threat actors, who can leverage AI to generate malicious code and exploit vulnerabilities despite having negligible technical expertise.

Threats

Meta AI Abused to Hijack Instagram Accounts

Multiple Instagram users had their accounts hijacked after attackers convinced Meta's AI-powered support tools that they were the legitimate owners, with many unable to recover access due to automated assistance loops.

Threats

AI-built Ransomware Toolkit Evades EDR Solutions

A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and evades endpoint detection and response solutions.

Threats

AI Security Threats

The browser has become the front line for AI security, with adversaries using AI to iterate on phishing kits and employees adopting AI tools without security oversight.

Threats

Tina Peters Vows Legal Fight

Tina Peters, convicted of election-security breach, remains unapologetic and vows to fight in court to have her criminal record expunged after her prison sentence was commuted by Governor Polis.

Threats

2026 Election Cyber Threats Target Campaign Systems

Cybersecurity threats to the 2026 midterm elections are targeting campaign systems, including email accounts, websites, and fundraising platforms, rather than voting machines or ballot-counting systems.

Threats

2026 World Cup Fans Targeted by Chinese Fraud Gang

A Chinese-speaking fraud gang has built a near pixel-perfect clone of FIFA's official website to steal credentials and payment details from 2026 World Cup fans, potentially putting billions of dollars at risk.

Threats

Google Engineer Charged with Insider Trading

A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market.

Threats

Dutch Govt Disrupts 17 Million Device Botnet

Dutch authorities have disrupted a massive botnet of 17 million devices and seized over 200 servers used to control the operation.

Threats

Russia Seeks Western Tech

Russia's intelligence agencies are aggressively seeking Western technology and defense secrets as sanctions squeeze the country's economy.

Threats

GreyVibe Hackers Utilize AI Tools for Cyberattacks

GreyVibe hackers, likely linked to Russian interests, use AI-generated lures and custom malware to target military, government, and business entities, with activity dating back to August 2025.

Threats

Tennessee Man Linked to 764 Charged with Child Exploitation

Zachary Sweeney, a 30-year-old Tennessee man, has been charged with multiple counts of sexual exploitation and attempted sexual exploitation of a minor, with alleged crimes dating back to 2022.

Threats

Russia-Linked GreyVibe Attackers

GreyVibe, a previously undocumented threat actor, uses AI to supercharge its cyberattacks, targeting Ukrainian entities since August 2025.

Threats

Cybersecurity Threats

A data breach at Trump Mobile exposed customer data, while a phishing campaign targeted LinkedIn users and a supply chain attack hit 176 NPM packages.

Threats

DDoS-as-a-Service Market Evolves

The DDoS-as-a-service market has become more sophisticated, with prices as low as $5 for an attack, making it easier for low-skill users to launch attacks.

Threats

Glassworm Botnet Disrupted by CrowdStrike

CrowdStrike has dismantled the Glassworm botnet, which infected hundreds of open-source software with malware, in a coordinated effort with Google and Shadowserver.

Threats

Russia's Daily Attacks on UK

Russia is conducting daily hybrid attacks against the UK, targeting critical infrastructure, democratic processes, and public trust, according to GCHQ director Anne Keast-Butler.

Threats

Agentic Era Cybersecurity Risks

The agentic era is forcing manual remediation processes to evolve rapidly, with AI-powered cyberattacks creating a security nightmare for organizations.

Threats

GlassWorm Botnet Disruption

The GlassWorm botnet, which targeted open source software, has been disrupted by CrowdStrike, Google, and the Shadowserver Foundation.

Threats

Credential Crisis Threatens Cybersecurity

Stolen credentials defeat modern security, allowing attackers to bypass perimeter controls and evade detection, with 85% of incident responses due to phishing attacks.

Threats

Silent Ransom Group Targets US Law Firms

The FBI warns of in-person data theft attacks by the Silent Ransom Group, targeting US-based law firms through social engineering and phishing emails.

Threats

Silent Ransom Group Targets US Law Firms

The FBI warns US-based law firms of a cybercrime group that steals data in person, with over 100 attacks claimed by Silent Ransom Group since 2022.

Threats

Romanian Hacker Sentenced for Selling Access

Catalin Dragomir, a 45-year-old Romanian national, has been sentenced to 4 years and 8 months in prison for selling access to an Oregon state network, resulting in losses exceeding $250,000.

Threats

Dutch Arrests Over Russian Cyber Ops

Dutch authorities arrested two men suspected of providing infrastructure for Russian cyber operations and disinformation campaigns, seizing over 800 servers.

Threats

Iranian APT Updates Tools

Nimbus Manticore, an Iranian APT, has adopted new tactics and updated its arsenal to target aviation and software companies.

Threats

Anthropic's Claude Mythos Model

Anthropic's restricted Claude Mythos model, which poses major security risks, may be coming to Claude Code with a powerful guardrail system.

Threats

KimWolf Botnet Admin Arrested

US and Canadian authorities arrested a Canadian man, Jacob Butler, for operating the KimWolf botnet, which infected nearly 2 million devices worldwide, causing financial losses exceeding $1 million.

Threats

Netherlands Cyberattack Aid Arrests

Dutch authorities arrested two men for operating IT infrastructure used by Russia to carry out cyberattacks and seized over 800 servers.

Threats

Megalodon Supply Chain Attack

Over 5,500 GitHub repositories were infected with malware in a supply chain attack dubbed Megalodon, which relies on automated commits to steal credentials and secrets.

Threats

Kimwolf Botnet Operator Arrested

A 23-year-old Canadian man has been arrested for operating the Kimwolf DDoS botnet, which ensnared approximately 2 million devices and was linked to a record-breaking DDoS attack.

Threats

First VPN Service Seized

International law enforcement has taken down the 'First VPN' service, used in ransomware and data theft attacks, seizing servers and arresting the administrator.

Threats

Netherlands Seizes Servers Linked to Cyberattacks

Dutch authorities seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns.

Threats

Kimwolf Botmaster Arrested

A 23-year-old Ottawa man, Jacob Butler, aka 'Dort', was arrested for building and operating the Kimwolf IoT botnet, which enslaved millions of devices for use in massive DDoS attacks.

Threats

KimWolf DDos Botnet Operator Arrested

A 23-year-old Canadian man, Jacob Butler, has been arrested and charged with operating the KimWolf DDos botnet, a large-scale distributed denial-of-service platform that infected over a million devices worldwide.

Threats

US Execs Plead Guilty to Aiding Global Tech Support Scams

Two former US executives pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide, with Americans losing at least $2.1 billion to such scams in 2025.

Threats

Kali365 Phishing-as-a-Service Targets Microsoft 365

The FBI warns of Kali365, a phishing-as-a-service platform that tricks people into giving access to their Microsoft 365 accounts, with hundreds of attacks reported in April.

Threats

Kali365 Phishing Kit Targets Microsoft 365 Users

The FBI warns of Kali365, a growing phishing-as-a-service platform that retrieves Microsoft 365 access tokens, bypassing multi-factor authentication and abusing OAuth device code authorizations.

Threats

Belarus-Linked Hackers Target Ukraine Officials

A Belarus-linked hacking group, GhostWriter, has launched a phishing campaign against Ukrainian government officials using fake emails disguised as messages from an online learning platform to deliver malware.

Threats

Kimwolf Botnet Alleged Leader Arrested

Jacob Butler, a 23-year-old Canadian man, was arrested for allegedly running the Kimwolf botnet, which initiated over 25,000 DDoS attacks and caused millions of dollars in financial losses.

Threats

Crypto Drainers: How They Work

Crypto drainers are tools designed to steal cryptocurrency assets by abusing wallet permissions and transaction approvals, often through social engineering tactics.

Threats

Tech Support Scam Assistants Plead Guilty

Two Americans, Adam Young and Harrison Gevirtz, pleaded guilty to assisting India-based tech support scam centers that stole millions from US citizens.

Threats

ICS Security Threats

Experts share real-world experiences of ICS security threats, highlighting the gap between written security policies and actual plant floor practices.

Threats

AI-Powered App Attacks Increase

AI-powered app attacks are becoming faster, more frequent, and harder to stop, with 87% of monitored apps under attack in 2026.

Threats

Crypto ATM Scams

US residents lost $388 million through cryptocurrency kiosks in 2025, with Texas and Florida reporting the highest losses, according to a new FBI report.

Threats

Microsoft Disrupts Fox Tempest Cybercrime Service

Microsoft seized infrastructure and disrupted a cybercrime service that created and sold over 1,000 code-signing certificates used to make malware appear trusted and legitimate.

Threats

Tycoon2FA Device Code Phishing

The Tycoon2FA phishing kit has added device-code phishing attacks to hijack Microsoft 365 accounts, with a surge in such attacks reported by Push Security and Proofpoint.

Threats

Foxconn Cyberattack

Foxconn, a major electronics manufacturer, is recovering from a cyberattack that disrupted its North American factories, with the Nitrogen ransomware group claiming responsibility and stealing 8 terabytes of data.

Threats

Shai-Hulud Worm Source Code Released

TeamPCP has released the source code of its Shai-Hulud worm, potentially fueling more supply chain attacks and copycat threats.

Threats

AI-Powered Identity Security Threats

A top White House cybersecurity official emphasizes the importance of regulating and monitoring identities accessing federal networks as AI integration increases.

Threats

Cyber-Enabled Cargo Crime

Cybercrime tradecraft is being used to steal freight, with entire truckloads of goods being re-routed and sold on the black market, resulting in approximately $725 million in cargo crime losses across North America in 2025.

Threats

US Intelligence Community Prepares for Foreign Election Threats

The US intelligence community has begun ramping up efforts to shield the upcoming midterms from foreign manipulation, with Director of National Intelligence Tulsi Gabbard tapping two officials to coordinate the response.

Threats

Data Center Security Enhanced

Data centers can enhance security without sacrificing performance by utilizing data processing units (DPUs) to execute security workloads, freeing CPU and GPU cycles for their intended operations.

Threats

Mythos AI Model Raises Cyber Risks Concerns

The House Homeland Security Committee is investigating Anthropic's AI model Mythos, which can autonomously uncover cyber vulnerabilities, amid concerns over its use by federal agencies.

Threats

AI-Generated Fraud: The New Frontier

Fraudsters are using generative AI to automate impersonation and mass-produce synthetic identities, rendering enterprises' defenses obsolete, with predicted losses reaching $40 billion in the U.S. by 2027.

Threats

Dream Market Admin Arrested

German and US authorities arrested Owe Martin Andresen, 49, alleged administrator of Dream Market, on multiple charges of money laundering after a May 7 raid on three locations.

Threats

Ransomware Attack Impacts West Pharmaceutical Operations

West Pharmaceutical Services has reported a ransomware attack that has impacted critical systems used to ship, receive and manufacture products, temporarily disrupting business operations globally.

Threats

Cybersecurity Leadership for Small Businesses

The average cyberattack costs a small- or medium-size business over $250,000, highlighting the need for affordable cybersecurity leadership solutions.

Threats

Operation HookedWing Phishing Campaign

Over 500 organizations across multiple industries have been targeted in a years-long phishing campaign, resulting in the theft of more than 2,000 user credentials.

Threats

Pro-Ukraine Hacktivists Unite Against Russia

Pro-Ukraine hacktivist groups BO Team and Head Mare appear to be coordinating cyber operations against Russian organizations, according to a Kaspersky report.

Threats

Virginia Man Guilty of Deleting Government Databases

Sohaib Akhter, 34, was found guilty of conspiracy to commit computer fraud and other charges after deleting 96 government databases and stealing an individual's password.

Threats

Canvas System Cyberattack

A cyberattack on the Canvas system used by thousands of schools has left students and faculty unable to access course materials, creating chaos as finals approach.

Threats

Schumer Calls for AI Cyber Coordination

Senate Minority Leader Chuck Schumer is seeking a plan from the Department of Homeland Security to coordinate with state and local governments on defending against AI-strengthened hacks.

Threats

Canvas Cyber Incident

A cyberattack on education software provider Instructure forced multiple universities to reschedule final exams, with hackers from the ShinyHunters group demanding a ransom by May 12.

Threats

Iranian Government Hackers Utilize Chaos Ransomware

Iranian government hackers are using Chaos ransomware as a cover for alleged espionage and data theft operations, according to researchers from Rapid7.

Threats

North Korean IT Worker Scheme Facilitators Sentenced

Two US nationals were sentenced to 18 months in prison for running laptop farms that facilitated North Korea's remote IT workers scheme, generating $1.2 million in revenue for the regime.

Threats

CVE: GoDaddy ManageWP Phishing

A phishing campaign is targeting ManageWP credentials through Google sponsored search results, with 200 unique victims confirmed so far.

Threats

Ransomware Attacks Succeed Despite Backups

Ransomware attacks often succeed even when backups exist, as attackers target and destroy backup systems before launching encryption, making recovery impossible.

Threats

CISA Urges Critical Infrastructure to Prepare for Isolation

CISA is urging critical infrastructure owners to plan for delivering essential services under emergency conditions, potentially for months, due to threats from state-sponsored hackers.

Threats

Conti Ransomware Affiliate Sentenced to 8 Years

A Latvian ransomware affiliate has been sentenced to over 8 years in prison for conducting attacks on behalf of Conti and Akira, causing $56 million in losses.

Threats

Amazon SES Phishing Abuse

The Amazon Simple Email Service is being increasingly abused to send convincing phishing emails that bypass standard security filters and render reputation-based blocks ineffective.

Threats

Fraudsters Target Credit Unions

Fraudsters are increasingly targeting small to mid-sized credit unions with structured loan fraud methods, exploiting weaknesses in work processes and verification systems.

Threats

Data Center Security

Lawmakers and industry experts are considering whether the federal government has the right setup to defend data centers from cyber and physical attacks.

Threats

Cordial Spider and Snarky Spider Extortion Attacks

Cordial Spider and Snarky Spider, two financially-motivated threat groups, are targeting US-based organizations in multiple sectors for rapid data theft and extortion attacks, using voice-phishing and social engineering tactics.

Threats

Telegram Crypto Scams

Cybersecurity researchers uncovered a large-scale fraud operation using Telegram's Mini App feature to run crypto scams and distribute Android malware.

Threats

HeartlessSoul Cyber Spies Target Russian Aviation

A cyber-espionage group known as HeartlessSoul has been targeting Russian government agencies and companies in the aviation industry to steal sensitive geospatial data.

Threats

FCC Tightens Telecom Security

The FCC has approved new regulations to strengthen telecom companies' 'Know Your Customer' requirements and protect networks from cyberattacks.

Threats

Ransomware Attackers Sentenced to 4 Years

Two cybersecurity incident responders were sentenced to four years in prison for conducting covert ransomware attacks, earning $1.2 million from one incident.

Threats

Ransomware Attackers Sentenced

Two former cybersecurity professionals, Ryan Goldberg and Kevin Martin, were sentenced to four years in prison for committing ransomware attacks in 2023.

Threats

Bitwarden CLI NPM Package Poisoned in Sophisticated Supply Chain Attack

Version 2026.4.0 of the Bitwarden CLI NPM package was found to contain malicious code capable of stealing credentials and secrets from victim machines, with links to recent attacks on Checkmarx and the Shai-Hulud worm campaigns.

Threats

North Korea's Lazarus Group Suspected in $290M KelpDAO Crypto Theft

State-sponsored North Korean hackers from the Lazarus Group are believed to be behind a $290 million heist targeting the KelpDAO DeFi protocol, with attackers manipulating cross-chain verification nodes to authorize fraudulent transactions.

Threats

Two US Nationals Sentenced for Running North Korean IT Worker Laptop Farms

Kejia Wang and Zhenxing Wang, both New Jersey residents, have been sentenced to prison for facilitating a North Korean IT worker fraud scheme that generated over $5 million for Pyongyang and caused more than $3 million in losses to US companies.

Threats

Tycoon 2FA Dethroned as PhaaS Leader Following Domain Seizures and Ecosystem Shift

Cybersecurity firm Barracuda Networks reports that Tycoon 2FA has lost its dominance among phishing-as-a-service platforms after law enforcement seized 330 of its domains, with threat actors migrating to rivals like Mamba 2FA and EvilProxy while total attacks surged past 23 million.

Threats

Synnovis Ransomware Attack Still Haunting London NHS Trusts 18 Months On

More than 18 months after the Qilin ransomware group struck Synnovis in June 2024, at least one London NHS trust is still running on paper processes, with over 161,000 pathology reports delayed and one patient death linked to the incident.

Threats

Kimwolf Botnet Accidentally Cripples I2P Anonymity Network in Sybil Attack

The Kimwolf IoT botnet has been hammering the I2P anonymity network since early February 2026 after its operators attempted to enroll 700,000 infected devices as network nodes, overwhelming the system and cutting connectivity roughly in half.

Threats

Starkiller Phishing-as-a-Service Bypasses MFA by Proxying Real Login Pages

A new phishing-as-a-service platform called Starkiller dynamically loads authentic login pages through a reverse proxy, capturing credentials and MFA tokens in real time while rendering traditional detection methods largely ineffective.

Threats

Unmasking Kimwolf's Botmaster: The Trail Leading to 'Dort'

Open-source intelligence and breach data link Kimwolf botnet operator 'Dort' to Jacob Butler, an Ottawa, Canada resident born in August 2003, who has since orchestrated DDoS attacks, doxing, and a swatting incident against those who exposed the botnet.

Threats

Why Hospital Ransomware Defense Starts With Realistic Rehearsals

A chief medical information officer at San Joaquin General Hospital told RSAC 2026 attendees that preparation and repeated rehearsal—not just downtime playbooks—are what truly determine whether a ransomware attack on a healthcare facility escalates or stabilizes.

Threats

Fancy Bear's Relentless Global Campaign: What Defenders Need to Know

Trend Micro research and a fresh FBI warning reveal that Russia's APT28 is targeting governments, defense contractors, and critical infrastructure worldwide using both old and new techniques. Experts say defenders don't need to match the group's sophistication — they just need to get the basics right.

Threats

Dutch Healthcare Software Firm ChipSoft Crippled by Ransomware Attack

Dutch EHR vendor ChipSoft has been struck by a ransomware attack, forcing the company to take its website and patient-facing digital services offline and prompting warnings to connected hospitals across the Netherlands and Belgium.

Threats

Censys Finds 3,900 US Devices Exposed to Iranian OT Attack Campaign

Researchers at Censys have identified more than 5,200 internet-exposed Rockwell Automation/Allen-Bradley PLCs potentially vulnerable to Iranian state-backed attackers, with nearly 3,900 of those devices located in the United States.

Threats

Ransomware Strike on ChipSoft Ripples Across Dutch Hospital Networks

A ransomware attack on Dutch healthcare software vendor ChipSoft on April 7 forced the company to disable key digital platforms used by roughly 70% of Netherlands hospitals, triggering widespread logistical disruptions.

Threats

CPUID Supply Chain Attack Poisons CPU-Z and HWMonitor Download Links

Hackers compromised a secondary API on the CPUID website for roughly six hours, redirecting download links for CPU-Z and HWMonitor to trojanized malware. The breach was discovered and remediated, but users who downloaded either tool during that window may be infected.

Threats

The Ransomware Landscape in 2026: What Has Changed

Ransomware continues to evolve at an alarming pace. From AI-powered attack chains to the decline of ransom payments, we examine the trends reshaping the threat landscape in 2026.

Threats

Supply Chain Attacks: The Growing Threat to Software Security

Supply chain attacks have surged dramatically, targeting the trust relationships between software vendors, open-source ecosystems, and end users. We examine the evolving threat landscape and strategies for defense.

Threats

IoT Botnet Activity Surges as Millions of Devices Remain Unpatched

A new wave of IoT botnet activity is exploiting millions of unpatched smart devices worldwide. Security researchers are tracking multiple Mirai variants and novel malware families targeting everything from home routers to industrial sensors.