What are the latest cyber threats I should know about?
"Latest" is usually the wrong question: the vulnerabilities exploited at scale are frequently months or years old and already patched. The durable categories are ransomware with data extortion, exploitation of internet-facing edge devices, identity attacks driven by infostealers, supply chain compromise, and social engineering. Track CISA’s Known Exploited Vulnerabilities catalog for what is genuinely being used now.
Threat lists date badly, which is why this page does not name a current campaign. Any specific group, malware family or incident named here would be stale within weeks and would then be quoted while wrong. The categories below have recurred for years and are what actually shows up in incident response, and the method for finding what is current matters more than any snapshot of it.
Ransomware has largely converged on stealing data as well as encrypting it, so that refusing to pay still carries a disclosure threat; some crews now skip encryption entirely. Internet-facing edge devices — VPN concentrators, firewalls, file transfer appliances, remote access gateways — are a favoured entry point precisely because they are exposed, hard to patch quickly and often poorly monitored. Identity attacks have displaced a great deal of exploitation: infostealer malware harvests session tokens and credentials that are sold on to access brokers, which is why multi-factor authentication that can be phished or fatigued is no longer sufficient. Supply chain compromise, through a dependency, a build system or a managed service provider, gives one intrusion many victims. Social engineering underpins most of the above, and remains effective without any novelty.
The counterintuitive part is that novelty is rarely the risk. A substantial share of entries added to the Known Exploited Vulnerabilities catalog in recent years carry identifiers from earlier years, meaning attackers are exploiting flaws that had patches available well before the attack. An organisation fully patched against everything in that catalog would be defended against most of what is actually used, and no threat-of-the-week list would have improved on it.
For what is genuinely current, prefer sources with the sourcing intact over sources with the most headlines. CISA’s Known Exploited Vulnerabilities catalog is the highest-signal feed available and is free. Vendor research blogs publish most significant findings first, with the caveat that each is marketing for its author. Original reporting — Krebs on Security, The Record, Risky Bulletin — carries the provenance that lets you judge a claim. Read a digest to decide what to open, then judge the original.