Live · Global Threat Intelligence

Global Threat Monitor.

Real cyber-threats unfolding around the world right now — ransomware, phishing, malware, breaches and zero-day exploits. Click any threat to see what happened and exactly how to stay protected.

Last synced: Jun 15, 2026 · 5:24 PM GMT · 45 active advisories · auto-refreshing
45
Active Threats
5
Critical
20
High
20
Medium / Watch
// LIVE THREAT MAP — worldwide activity Critical High Medium STELNEX HQ
N. America · 11 S. America Europe · 5 Africa · 4 Ghana Russia · 6 Middle East · 7 India · 4 China · 8 Japan Australia
Sort:
Critical

Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks

Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-2026…

◉ GlobalBleepingComputer · 1h ago
What happened & how to fix →
High

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three…

◉ GlobalThe Hacker News · 2h ago
What happened & how to fix →
High

Council of Europe investigates ShinyHunters data breach claims

The Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the Sh…

◉ EuropeBleepingComputer · 2h ago
What happened & how to fix →
Medium

FBI: Fraudsters use couriers to steal money in crypto scams

The U.S. Federal Bureau of Investigation (FBI) warned that criminals are using couriers to collect money from victims o…

◉ United StatesBleepingComputer · 3h ago
What happened & how to fix →
Medium

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes

A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files …

◉ GlobalThe Hacker News · 3h ago
What happened & how to fix →
Medium

Vibe coders are gonna vibe code: How CISOs are tackling code sprawl

Employees are increasingly building automations, agents, and apps with AI tools outside traditional security oversight.…

◉ GlobalBleepingComputer · 4h ago
What happened & how to fix →
High

Chinese hackers breach REDCap servers, steal medical research

A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive…

◉ North AmericaBleepingComputer · 4h ago
What happened & how to fix →
Critical

⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feat…

◉ GlobalThe Hacker News · 4h ago
What happened & how to fix →
Critical

New attack turned Microsoft 365 Copilot into 1-click data theft tool

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sen…

◉ GlobalBleepingComputer · 5h ago
What happened & how to fix →
High

Infinite Campus data breach affects 137,000 school staff accounts

The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce…

◉ GlobalBleepingComputer · 6h ago
What happened & how to fix →
High

Webinar: How behavioral AI stops phishing and account takeovers

Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operationa…

◉ GlobalBleepingComputer · 6h ago
What happened & how to fix →
Medium

The Onboarding Password Mistake That Creates Unnecessary Risk

Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords…

◉ GlobalThe Hacker News · 7h ago
What happened & how to fix →
Medium

152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic

Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper …

◉ GlobalThe Hacker News · 7h ago
What happened & how to fix →
High

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustP…

◉ GlobalThe Hacker News · 8h ago
What happened & how to fix →
Medium

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and Nort…

◉ AfricaThe Hacker News · 12h ago
What happened & how to fix →
High

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw

Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability…

◉ GlobalThe Hacker News · 12h ago
What happened & how to fix →
Medium

FBI disrupts massive AI-powered phishing service using a million URLs

In a coordinated effort, the FBI, working with Google and Black Lotus Labs, has dismantled a massive Chinese phishing-a…

◉ ChinaBleepingComputer · 1d ago
What happened & how to fix →
Critical

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited t…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Critical

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active …

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
High

Yarbo Android/iOS Mobile Application and Cloud Infrastructure

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain hard-coded credent…

◉ GlobalCISA Advisories · 4d ago
What happened & how to fix →
High

Naxclow IoT Platform

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to impersonate devices, inte…

◉ GlobalCISA Advisories · 4d ago
What happened & how to fix →
High

Brickcom Cameras

View CSAF Summary Successful exploitation of these vulnerabilities could allow a remote unauthenticated attacker to gai…

◉ GlobalCISA Advisories · 4d ago
What happened & how to fix →
High

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active …

◉ GlobalCISA Advisories · 4d ago
What happened & how to fix →
High

Who Runs the Ransomware Group ‘The Gentlemen?’

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidl…

◉ GlobalKrebs on Security · 5d ago
What happened & how to fix →
Medium

A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and su…

◉ GlobalKrebs on Security · 5d ago
What happened & how to fix →
High

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of act…

◉ GlobalCISA Advisories · 6d ago
What happened & how to fix →
High

Siemens KACO Blueplanet Inverters

View CSAF Summary KACO blueplanet Inverters contain multiple vulnerabilities that could allow an attacker to derive the…

◉ GlobalCISA Advisories · 6d ago
What happened & how to fix →
High

Schneider Electric EcoStruxure Panel Server

View CSAF Summary Schneider Electric is aware of its vulnerability in its EcoStruxure Panel Server offer. The EcoStruxu…

◉ GlobalCISA Advisories · 6d ago
What happened & how to fix →
High

Schneider Electric Modicon Network Managed Switches

View CSAF Summary Schneider Electric is aware of a RADIUS protocol vulnerability affecting its Modicon Network Managed …

◉ GlobalCISA Advisories · 6d ago
What happened & how to fix →
Medium

Argamal: Malware hidden in hentai games

Kaspersky researchers analyze new Argamal RAT distributed via infected hentai games and allowing the attacker to contro…

◉ GlobalSecurelist · Jun 3, 2026
What happened & how to fix →
Medium

Wardriving assessment across Mexico: Preparing for the 2026 World Cup

In the lead-up to the 2026 FIFA World Cup, Kaspersky GReAT experts conducted a wardriving assessment in Mexico City, Mo…

◉ MexicoSecurelist · Jun 2, 2026
What happened & how to fix →
Medium

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly def…

◉ United StatesKrebs on Security · Jun 1, 2026
What happened & how to fix →
Medium

Containers on fire: from container escapes to supply chain attacks

We break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, A…

◉ GlobalSecurelist · Jun 1, 2026
What happened & how to fix →
High

What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant

What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to…

◉ GlobalSecurelist · May 29, 2026
What happened & how to fix →
Medium

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

Our experts continue to track attacks targeting consumers of pirated content, both books and movies. 2026 saw the disco…

◉ GlobalSecurelist · May 28, 2026
What happened & how to fix →
Medium

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT i…

◉ NetherlandsKrebs on Security · May 25, 2026
What happened & how to fix →
Medium

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency…

◉ United StatesKrebs on Security · May 22, 2026
What happened & how to fix →
Medium

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor…

◉ RussiaSecurelist · May 22, 2026
What happened & how to fix →
Medium

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a f…

◉ United StatesKrebs on Security · May 21, 2026
What happened & how to fix →
High

How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)

We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).

◉ GlobalSecurelist · May 20, 2026
What happened & how to fix →
Medium

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public…

◉ GlobalKrebs on Security · May 18, 2026
What happened & how to fix →
Medium

IT threat evolution in Q1 2026. Mobile statistics

This report contains mobile threat statistics for Q1 2026, along with noteworthy discoveries and quarterly trends: new …

◉ GlobalSecurelist · May 18, 2026
What happened & how to fix →
Medium

IT threat evolution in Q1 2026. Non-mobile statistics

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as…

◉ GlobalSecurelist · May 18, 2026
What happened & how to fix →
High

Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are provin…

◉ GlobalKrebs on Security · May 12, 2026
What happened & how to fix →
High

Canvas Breach Disrupts Schools & Colleges Nationwide

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and c…

◉ United StatesKrebs on Security · May 8, 2026
What happened & how to fix →