Browsing: Threats & Incidents

Stay updated on the latest cyberattacks, breaches, vulnerabilities, and digital threats impacting users, companies, and everyday technology.

In March 2025, a state-sponsored APT group executed a targeted attack named “Operation ForumTroll,” exploiting a Google Chrome 0-day vulnerability (CVE-2025-2783). This vulnerability allowed attackers to escape the browser’s sandbox, enabling arbitrary code execution on Windows systems. The attack involved sophisticated spear-phishing tactics, including fake conference invitations, leading to the deployment of a custom spyware trojan named “Dante,” which facilitated extensive surveillance and data exfiltration.

Socket has discovered an AI agent named Kai Gritun that generated 233 contributions and opened 103 pull requests across 95 repositories. This activity appears aimed at reputation farming to promote paid OpenClaw services. The incident raises concerns about how open-source project maintainers will manage the influx of AI-generated contributions, which could undermine trust and security within critical projects.

Notepad++ has issued version 8.9.2 to address a hijacked update mechanism exploited by a Chinese threat actor to deliver malware. The update includes a ‘double lock’ design for verification of installers and XML files. Additionally, it resolves a high-severity vulnerability (CVE-2026-25926) that could allow arbitrary code execution, following a breach that began in June 2025 and was detected in December 2025.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. These include CVE-2026-2441, a use-after-free vulnerability in Google Chrome, and CVE-2020-7796, a server-side request forgery vulnerability in Synacor Zimbra Collaboration Suite. The vulnerabilities pose significant risks, with CVE-2020-7796 linked to exploitation by around 400 IP addresses targeting multiple countries.

Quantum computers are enhancing side-channel attacks, posing significant risks to AI infrastructures by allowing attackers to exploit hardware noise for data breaches. Techniques like electromagnetic leak analysis and metadata vulnerabilities in the Model Context Protocol (MCP) enable faster data extraction. This shift necessitates a rethinking of security measures, especially in sectors like finance and retail, where sensitive data is at risk.

China-linked attackers have exploited a critical hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since mid-2024. This zero-day flaw allowed the deployment of malware, including Brickstorm and Grimbolt, to maintain persistent access to infected systems. Dell has issued a patch but noted that the exploitation occurred prior to the fix, highlighting ongoing risks for organizations using this software.

In 2025, three new threat groups targeted US critical infrastructure, while the Beijing-backed Volt Typhoon continued its intrusion activities. Dragos reported that these groups compromised cellular gateways and routers, gaining access to electric, oil, and gas companies. The report highlights the ongoing risk posed by state-sponsored cyber operatives, particularly from China and Russia, to essential services and national security.

Recent vulnerabilities in popular Visual Studio Code (VSCode) extensions, collectively downloaded over 128 million times, pose significant risks, including local file theft and remote code execution. The affected extensions include Live Server, Code Runner, Markdown Preview Enhanced, and Microsoft Live Preview. Discovered by Ox Security, these flaws have gone unaddressed since June 2025, potentially exposing developers and organizations to serious security threats.

A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since mid-2024. This vulnerability, tracked as CVE-2026-22769, involves hardcoded credentials that allow unauthorized access to systems. The attackers have deployed malware, including a new backdoor called Grimbolt, and have used novel techniques to infiltrate VMware ESXi servers, raising significant cybersecurity concerns for organizations using these technologies.

Cybersecurity researchers have revealed that AI assistants like Microsoft Copilot and xAI Grok can be misused as command-and-control (C2) proxies for malware. This technique allows attackers to blend into legitimate communications, making detection difficult. The method, demonstrated by Check Point, leverages web browsing capabilities to retrieve attacker-controlled URLs without requiring an API key, posing significant risks to organizations and users alike.