Live · Global Threat Intelligence

Global Threat Monitor.

Real cyber-threats unfolding around the world right now — ransomware, phishing, malware, breaches and zero-day exploits. Click any threat to see what happened and exactly how to stay protected.

Last synced: May 31, 2026 · 9:02 PM GMT · 54 active advisories · auto-refreshing
54
Active Threats
3
Critical
23
High
28
Medium / Watch
// LIVE THREAT MAP — worldwide activity Critical High Medium STELNEX HQ
N. America · 11 S. America · 2 Europe · 11 Africa · 4 Ghana Russia · 6 Middle East · 5 India · 6 China · 8 Japan · 1 Australia
Sort:
Medium

Name That Toon Contest

A new security advisory has been reported. Click "Read full advisory" for the complete technical details.

◉ GlobalDark Reading · 1m ago
What happened & how to fix →
High

WP Maps Pro bug exploited to create admin accounts on WordPress sites

Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating …

◉ GlobalBleepingComputer · 6h ago
What happened & how to fix →
Medium

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including compute…

◉ GlobalThe Hacker News · 8h ago
What happened & how to fix →
High

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracke…

◉ GlobalBleepingComputer · 1d ago
What happened & how to fix →
High

New CIFSwitch Linux flaw gives root on multiple distributions

A newly discovered local privilege escalation vulnerability dubbed 'CIFSwitch' in the Linux kernel could allow attacker…

◉ GlobalBleepingComputer · 1d ago
What happened & how to fix →
High

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Acces…

◉ GlobalThe Hacker News · 1d ago
What happened & how to fix →
Medium

Name That Toon: Mark of (Cybersecurity) Progress

As part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures …

◉ GlobalDark Reading · 2d ago
What happened & how to fix →
Medium

ChatGPT share links abused to host fake outage pages to deliver malware

Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to do…

◉ GlobalBleepingComputer · 2d ago
What happened & how to fix →
High

California AG sues 23andMe over 2023 breach exposing health data

California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failu…

◉ GlobalBleepingComputer · 2d ago
What happened & how to fix →
High

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial int…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
High

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions a…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Medium

Asia's Cyber Insurance Market Shows Signs of Life

The cyber insurance industry has made relatively weak inroads into Asia due to a a variety of factors, but that could b…

◉ GlobalDark Reading · 2d ago
What happened & how to fix →
Medium

From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market

DDoS attacks are increasingly being sold like subscription services, complete with pricing tiers, support, and reseller…

◉ GlobalBleepingComputer · 2d ago
What happened & how to fix →
Medium

Dutch govt disrupts malware botnet with 17 million infected devices

Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local…

◉ GlobalBleepingComputer · 2d ago
What happened & how to fix →
High

With Complex Cloud Integrations, Small Errors Lead to Major Compromises

Researchers discover an exploit chain combining over-permissioned roles, secrets discovery, and non-human identities th…

◉ GlobalDark Reading · 2d ago
What happened & how to fix →
High

Google Chrome adds session cookie theft protection for all users

Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolli…

◉ GlobalBleepingComputer · 2d ago
What happened & how to fix →
High

'The Com' Cyberattacks Support Violence & Sexploitation

Your organization's security failures have consequences for everyone else too, since this neo-Nazi-infested criminal ga…

◉ GlobalDark Reading · 2d ago
What happened & how to fix →
High

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active …

◉ GlobalCISA Advisories · 2d ago
What happened & how to fix →
Medium

New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting …

◉ UkraineThe Hacker News · 2d ago
What happened & how to fix →
Medium

Man sent to prison for selling data of 7 millions elderly Americans

A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 milli…

◉ North AmericaBleepingComputer · 2d ago
What happened & how to fix →
Medium

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees b…

◉ GlobalThe Hacker News · 2d ago
What happened & how to fix →
Medium

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit f…

◉ BrazilThe Hacker News · 2d ago
What happened & how to fix →
High

What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant

What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to…

◉ GlobalSecurelist · 2d ago
What happened & how to fix →
Medium

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set…

◉ South KoreaThe Hacker News · 2d ago
What happened & how to fix →
Medium

As Global Powers Explore Humanoid Robots, Cyber-Risk Looms

The future of cybersecurity is germinating, as nation states vie for dominance in the embodied AI market and its supply…

◉ GlobalDark Reading · 2d ago
What happened & how to fix →
Medium

Dutch Raid Fails to Dent Russian Bulletproof Host

Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the hosting provider's core…

◉ RussiaDark Reading · 3d ago
What happened & how to fix →
Critical

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allow…

◉ GlobalThe Hacker News · 3d ago
What happened & how to fix →
Medium

Agentic AI Isn't Risky; the Way Orgs Deploy It Is

AI agents aren't black boxes — they're models interacting with software tools. The risk lies in their overlap.

◉ GlobalDark Reading · 3d ago
What happened & how to fix →
Medium

Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security

In this latest installment of the Reporters' Notebook video series, we discuss how cyber insurance is forcing organizat…

◉ GlobalDark Reading · 3d ago
What happened & how to fix →
High

ABB EIBPORT

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmwar…

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
High

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

View CSAF Summary Successful exploitation of this vulnerability could result in an attacker gaining administrator acces…

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
High

ABB Busch-Welcome 2 Wire Door Opener Actuator

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attack…

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
High

Fourth Frontier Frontier X Mobile Application, Frontier X2

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary han…

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
High

Schnieider Electric EcoStruxure Machine Expert HVAC

View CSAF Summary Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The …

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
High

CP Plus 8 Ch. Network Video Recorder

View CSAF Summary Successful exploitation of this vulnerability allows an attacker's malicious script to execute in the…

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
Medium

Supply Chain Compromises Impact Nx Console and GitHub Repositories

CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ec…

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
High

XCharge C6

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain administrator rights…

◉ GlobalCISA Advisories · 3d ago
What happened & how to fix →
Medium

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

Our experts continue to track attacks targeting consumers of pirated content, both books and movies. 2026 saw the disco…

◉ GlobalSecurelist · 3d ago
What happened & how to fix →
Medium

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT i…

◉ NetherlandsKrebs on Security · 6d ago
What happened & how to fix →
Medium

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency…

◉ United StatesKrebs on Security · May 22, 2026
What happened & how to fix →
Medium

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

Cloud Atlas attacks the public sector and diplomatic structures of Russia and Belarus, using ReverseSocks, SSH, and Tor…

◉ RussiaSecurelist · May 22, 2026
What happened & how to fix →
Medium

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a f…

◉ United StatesKrebs on Security · May 21, 2026
What happened & how to fix →
High

How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)

We explain how a flaw in ExifTool allows attackers to compromise macOS systems via a malicious image (CVE-2026-3102).

◉ GlobalSecurelist · May 20, 2026
What happened & how to fix →
Medium

CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public…

◉ GlobalKrebs on Security · May 18, 2026
What happened & how to fix →
Medium

IT threat evolution in Q1 2026. Mobile statistics

This report contains mobile threat statistics for Q1 2026, along with noteworthy discoveries and quarterly trends: new …

◉ GlobalSecurelist · May 18, 2026
What happened & how to fix →
Medium

IT threat evolution in Q1 2026. Non-mobile statistics

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as…

◉ GlobalSecurelist · May 18, 2026
What happened & how to fix →
Medium

Kimsuky targets organizations with PebbleDash-based tools

Kaspersky researchers analyze a range of new PebbleDash-based tools used in recent Kimsuky campaigns and reveal their c…

◉ GlobalSecurelist · May 14, 2026
What happened & how to fix →
High

Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are provin…

◉ GlobalKrebs on Security · May 12, 2026
What happened & how to fix →
High

State of ransomware in 2026

Kaspersky researchers are sharing insights into the main ransomware trends for 2026: EDR killers on the rise, switching…

◉ GlobalSecurelist · May 12, 2026
What happened & how to fix →
Critical

CVE-2025-68670: discovering an RCE vulnerability in xrdp

During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp serv…

◉ GlobalSecurelist · May 8, 2026
What happened & how to fix →
High

Canvas Breach Disrupts Schools & Colleges Nationwide

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and c…

◉ United StatesKrebs on Security · May 8, 2026
What happened & how to fix →
Medium

Anti-DDoS Firm Heaped Attacks on Brazilian ISPs

A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has bee…

◉ BrazilKrebs on Security · Apr 30, 2026
What happened & how to fix →
Medium

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty

A 24-year-old British national and senior member of the cybercrime group "Scattered Spider" has pleaded guilty to wire …

◉ GlobalKrebs on Security · Apr 21, 2026
What happened & how to fix →
Critical

Patch Tuesday, April 2026 Edition

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating syste…

◉ GlobalKrebs on Security · Apr 14, 2026
What happened & how to fix →