Threats Affecting Canada
View all threats affecting or targeting Canada. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Canada
Click on any threat for detailed analysis and mitigation recommendations
Fake CAPTCHA, Real Business: Traffic Distribution for Hire 0 A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines. MediumMalware Join the discussion | AlienVault OTX General | 08/05/2026, 14:36:07 UTC Added: 08/06/2026, 08:56:14 UTC |
Phishing service spoofs RingCentral to steal Microsoft 365 accounts 0 The Greatness phishing-as-a-service (PhaaS) platform targets Microsoft 365 accounts using advanced phishing techniques including adversary-in-the-middle and device-code phishing. It spoofs RingCentral emails to bypass email security filters by exploiting whitelisting and safe-sender list trust. Post-compromise, attackers access Microsoft 365 data and services via stolen authentication tokens. The platform is sold to cybercriminals and has been active since at least mid-2022, targeting users in multiple countries. Researchers recommend auditing safe-sender lists and monitoring suspicious MFA-approved sign-ins. Join the discussion | Bleeping Computer | 08/04/2026, 21:45:36 UTC Added: 08/04/2026, 22:02:01 UTC |
ZDI-26-523: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution VulnerabilityCVE-2026-15679 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-15679. Join the discussion | Zero Day Initiative | 07/30/2026, 05:00:00 UTC Added: 07/31/2026, 01:36:50 UTC |
Microsoft Teams vishing attacks lead to Chaos ransomware attacks 0 Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...] Join the discussion | Bleeping Computer | 07/30/2026, 15:56:33 UTC Added: 07/30/2026, 17:22:18 UTC |
Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security 0 Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance. Key takeaways: Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Querying for isolated, hard-to-reach process-control systems, enables operators to establish a required security baseline. Predictive Vulnerability Priority Rating (VPR) scoring helps you prioritize and focus limited resources on the critical flaws that actually threaten physical safety and uptime. Advanced multi-detection engines and seamless IT workflow integrations accelerate mean-time-to-respond (MTTR) to help both security teams and operators align with a strict 72-hour reporting requirement. With the enactment of Canada’s Critical Cyber Systems Protection Act (CCSPA), commonly known as Bill C-8, the Canadian federal government is laying down a clear framework to protect the cyber-physical systems that are vital to national critical infrastructure security. For designated operators in telecommunications, energy, transportation, and banking, the mandate is clear: Establish formalized cybersecurity programs, mitigate supply chain risks, and — most critically — report cyber incidents to authorities within 72 hours. Failure to comply carries heavy consequences, including penalties that can reach up to $15 million Canadian dollars (CAD). But beyond the threat of fines, Bill C-8 highlights a fundamental operational challenge that many industrial organizations are still struggling to solve: How can you detect, investigate, and report a breach in 72 hours when you lack unified visibility across your converged IT and OT environments? Requirements for meeting Bill C-8's 72-hour incident reporting mandate In modern industrial operations and critical infrastructure, the line between IT and OT continues to blur. The introduction of connectivity (e.g., IoT-connected cameras and building management systems) has optimized processes and service delivery, but it has also introduced new cyber exposures. Today, threat actors do not honor traditional network silos; they frequently compromise a web-facing IT asset or IoT device and move laterally into the operational technology (OT) environment to disrupt physical processes. Meeting a 72-hour incident reporting window is nearly impossible if your security team is relying on fragmented point solutions. Solutions that focus exclusively on passive OT network monitoring often leave massive blind spots — especially considering that IT and IoT devices can constitute up to 50% of an industrial environment. When an incident occurs, teams waste precious hours manually correlating alerts across disconnected tools rather than actively investigating the root cause. To comply with CCSPA and protect uptime, critical national infrastructure (CNI) operators must bridge the IT/OT security divide. Establish your CCSPA cybersecurity baseline The CCSPA requires operators to implement formalized cybersecurity programs. The foundation of any mature security program is a comprehensive asset inventory — you cannot secure what you cannot see. The Tenable One Exposure Management Platform helps organizations eliminate security blind spots by building a complete, unified inventory of all OT, IoT, and IT assets. Tenable goes beyond passive-only network monitoring with our proprietary Safe Active Query technology. This hybrid approach safely communicates with industrial devices in their native protocols to uncover significantly more assets than passive monitoring alone — including dormant process control systems, shadow IT, and unmanaged IoT — without disrupting process integrity or impacting equipment uptime. Prioritize what matter… Join the discussion | Tenable Research | 07/30/2026, 16:05:00 UTC Added: 07/30/2026, 16:20:43 UTC |
ZDI-26-453: GIMP HDR File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18300 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18300. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-454: GIMP PSD File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18301 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18301. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-455: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18302 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18302. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18303 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-457: GIMP TIF File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18304 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18304. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
Showing 1 to 10 of 24 results