Live · Global Threat Intelligence

Global Threat Monitor.

Real cyber-threats unfolding around the world right now — ransomware, phishing, malware, breaches and zero-day exploits. Click any threat to see what happened and exactly how to stay protected.

Last synced: Aug 14, 2026 · 5:06 PM GMT · 54 active advisories · auto-refreshing
54
Active Threats
9
Critical
20
High
25
Medium / Watch
// LIVE THREAT MAP — worldwide activity Critical High Medium STELNEX HQ
N. America · 4 S. America · 1 Europe · 5 Africa · 9 Ghana Russia · 7 Middle East · 11 India · 7 China · 9 Japan · 1 Australia
Sort:
High

Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office

One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as we…

◉ GlobalDark Reading · 1h ago
What happened & how to fix →
Critical

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authenti…

◉ NetherlandsBleepingComputer · 2h ago
What happened & how to fix →
Medium

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Dr…

◉ GlobalBleepingComputer · 3h ago
What happened & how to fix →
Medium

What Boards Need to Know About Tech Risk

Why do so many boards underestimate technology risk until it becomes a crisis?

◉ GlobalDark Reading · 3h ago
What happened & how to fix →
High

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targe…

◉ GlobalBleepingComputer · 3h ago
What happened & how to fix →
Medium

Cyera's Oasis Security Buy Is All About AI Agent Control

The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged…

◉ GlobalDark Reading · 4h ago
What happened & how to fix →
High

Shell investigates 'potential incident' after Clop data theft claims

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed …

◉ GlobalBleepingComputer · 5h ago
What happened & how to fix →
Medium

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data fr…

◉ GlobalKrebs on Security · 5h ago
What happened & how to fix →
High

RingCentral data breach exposed info of 1.6 million accounts

The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the com…

◉ GlobalBleepingComputer · 6h ago
What happened & how to fix →
High

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious process…

◉ GlobalSecurelist · 8h ago
What happened & how to fix →
Medium

Data analyst sent to prison for stealing data, extorting employer

A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his empl…

◉ GlobalBleepingComputer · 8h ago
What happened & how to fix →
Medium

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

You're not alone if you just received an "Apple Threat Notification" saying it detected a "mercenary spyware attack tar…

◉ GlobalBleepingComputer · 15h ago
What happened & how to fix →
Medium

Ukraine shuts down 94 fraudulent call centers, seize millions in cash

Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams …

◉ UkraineBleepingComputer · 19h ago
What happened & how to fix →
High

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by re…

◉ GlobalBleepingComputer · 20h ago
What happened & how to fix →
Critical

Global Threat Campaign Hits Critical VMware vCenter Flaw

Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully…

◉ GlobalDark Reading · 20h ago
What happened & how to fix →
High

Siemens Parasolid

View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the applica…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

Siemens License Server (SLS)

View CSAF Summary Siemens License Server is affected by multiple vulnerabilities which could allow an attacker to eleva…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

Siemens Desigo DXR and PXC Controllers

View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

Johnson Controls Inc. Airwall

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, b…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

Johnson Controls Metasys

View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject …

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

Siemens Siveillance Video

View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Executio…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

Flow Neuroscience FL-100

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker within Bluetooth range to manip…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

Siemens LOGO! Soft Comfort

View CSAF Summary Siemens LOGO! Soft Comfort contains multiple vulnerabilities in its project-file encryption and passw…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
High

ANDRITZ HIPASE-250 and 250 SCALA

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read data from the device…

◉ GlobalCISA Advisories · 1d ago
What happened & how to fix →
Medium

'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft

Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web p…

◉ GlobalDark Reading · 1d ago
What happened & how to fix →
Medium

Armored Likho expands its cyber-espionage toolkit

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still …

◉ GlobalSecurelist · 1d ago
What happened & how to fix →
Critical

Belgium's eID Authentication Opens Citizen Accounts to RCE

The trust framework underlying Belgium's electronic ID system was fully compromised by severe vulnerabilities in a key …

◉ GlobalDark Reading · 1d ago
What happened & how to fix →
High

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a pro…

◉ GlobalThe Hacker News · 1d ago
What happened & how to fix →
Medium

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sect…

◉ GlobalDark Reading · 1d ago
What happened & how to fix →
Critical

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patche…

◉ South KoreaThe Hacker News · 1d ago
What happened & how to fix →
Medium

Walmart Takes a 'Trusted Agent' Approach to Purple Teaming

Walmart colocates red and blue teams to build trust and improve security through collaborative purple teaming exercises

◉ GlobalDark Reading · 2d ago
What happened & how to fix →
Medium

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking acce…

◉ RussiaThe Hacker News · 2d ago
What happened & how to fix →
Critical

Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the …

◉ North AmericaDark Reading · 2d ago
What happened & how to fix →
Medium

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let resea…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Medium

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making …

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Critical

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Cam…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Critical

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, acco…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Medium

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of h…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
High

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that c…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Critical

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and s…

◉ GlobalKrebs on Security · 2d ago
What happened & how to fix →
High

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference par…

Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver …

◉ GlobalSecurelist · 3d ago
What happened & how to fix →
Medium

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework…

◉ IsraelSecurelist · 3d ago
What happened & how to fix →
Medium

IT threat evolution in Q2 2026. Non-mobile statistics

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as…

◉ GlobalSecurelist · 4d ago
What happened & how to fix →
Medium

IT threat evolution in Q2 2026. Mobile statistics

This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the …

◉ GlobalSecurelist · 4d ago
What happened & how to fix →
Medium

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded…

◉ GlobalKrebs on Security · Aug 6, 2026
What happened & how to fix →
High

How legitimate cloud platforms enable phishers to bypass MFA

We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing h…

◉ GlobalSecurelist · Aug 4, 2026
What happened & how to fix →
Medium

An analysis of incidents at Brazilian educational institutions

Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Braz…

◉ BrazilSecurelist · Aug 3, 2026
What happened & how to fix →
Medium

Network Anomaly Detection in KATA

An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoastin…

◉ GlobalSecurelist · Jul 31, 2026
What happened & how to fix →
Medium

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimite…

◉ GlobalKrebs on Security · Jul 30, 2026
What happened & how to fix →
Medium

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that tu…

◉ GlobalKrebs on Security · Jul 22, 2026
What happened & how to fix →
High

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems an…

◉ GlobalKrebs on Security · Jul 14, 2026
What happened & how to fix →
Medium

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contracto…

◉ GlobalKrebs on Security · Jul 13, 2026
What happened & how to fix →
Critical

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software i…

◉ GlobalKrebs on Security · Jul 8, 2026
What happened & how to fix →
Medium

FBI Seizes NetNut Proxy Platform, Popa Botnet

The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains asso…

◉ IsraelKrebs on Security · Jul 2, 2026
What happened & how to fix →