Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Cisco has issued a warning about a serious vulnerability in its AsyncOS software for the Cisco Secure Email Gateway, identified as CVE-2026-76461. This flaw, which has a CVSS score of 9.8, allows unauthenticated remote attackers to execute root commands due to insufficient validation in the email parsing logic. The vulnerability is currently being exploited in the wild, putting users at significant risk. Organizations using affected versions of the Cisco Secure Email Gateway should take immediate action to protect their systems. This incident underscores the importance of timely updates and vigilance in cybersecurity practices.

Read Original

Homebrew, a popular package manager for macOS and Linux, released version 7.0.0 on Sunday, addressing eight security vulnerabilities in the process. The most critical issue involved a flaw that allowed unsigned removal metadata for casks—Homebrew's method for installing prebuilt applications—to execute commands with elevated privileges (sudo). To mitigate this risk, the development team removed the vulnerable recovery code and the related API accessors that could be exploited. This update is particularly important for developers who rely on Homebrew for managing their software installations, as it helps protect their systems from potential abuse. Users are encouraged to update to the latest version to safeguard against these vulnerabilities.

Read Original

Japan's Digital Agency has reported a significant data breach affecting around 246,000 records containing sensitive personal information of government employees. The breach is linked to a flaw in a Virtual Private Network (VPN), which allowed unauthorized access to these records. This incident raises concerns about the security of government digital infrastructure and the potential for misuse of the exposed data. With personal information at risk, affected individuals may face identity theft or other privacy violations. The agency is urging immediate action to address the vulnerability and protect sensitive information moving forward.

Read Original

A severe vulnerability identified as CVE-2026-85706 has been discovered in both the GitLab Community Edition and Enterprise Edition. This flaw is categorized as a path traversal vulnerability and carries a maximum CVSS score of 10 out of 10, indicating its potential for serious exploitation. Organizations using affected versions of GitLab could see significant risks to their software supply chains, as attackers could exploit this vulnerability to access sensitive files and data. Companies using these GitLab instances are urged to take immediate action to protect their systems and data. The urgency of addressing this issue is underscored by the potential for attackers to exploit it in real-world scenarios, putting countless users and organizations at risk.

Read Original

An attacker gained unauthorized access to the network of 3BB, a major broadband provider in Thailand, using a legitimate remote management tool called MeshCentral. This allowed the attacker to maintain control over internal machines and potentially harvest subscriber credentials. The breach was discovered by the cybersecurity firm Hunt.io, which found an exposed server containing the attacker’s tools and a list of compromised data. This incident raises concerns about the security of management tools and the potential for attackers to exploit legitimate software for malicious purposes. Users of 3BB and similar services should be vigilant about their account security and monitor for any suspicious activity.

Read Original

Researchers have identified a new hardware attack named DDRop that compromises memory protection in Intel and AMD's confidential computing systems. This attack allows an unauthorized user, who already has control over the server's software, to manipulate memory writes. By inserting a small circuit, the attacker can cause the processor to read outdated encrypted data as if it were current. This vulnerability poses significant risks for organizations relying on Intel TDX and AMD SEV-SNP technologies for secure computing, as it undermines the confidentiality of sensitive data. Companies using these systems should be aware of the potential for exploitation and take action to secure their environments.

Read Original

A Chinese hacking group known as Red Heron has exploited a recently discovered vulnerability in Gitea, a platform for managing Git repositories. This group scanned over 1,300 Gitea instances across multiple countries, successfully compromising 13 organizations in six different nations. Notably, they maintained a separate list of nearly 500 systems based in Taiwan. The rapid exploitation of this vulnerability highlights the risks associated with internet-facing applications, especially when they are not adequately secured. Organizations running Gitea should take immediate action to assess their systems and apply necessary updates to prevent similar attacks.

Read Original

Anthropic recently reported on a group of threat actors in northern Yemen involved in developing advanced weaponry using AI technologies. This group is working on three significant projects: a guided rocket that employs a basic flight computer for homing guidance, a multi-stage ballistic missile with a range exceeding 2,000 kilometers, and a variant of missiles called the 'R2000' set, which includes a hypersonic glide vehicle. The use of AI in these weapons systems raises serious concerns about the potential for increased conflict and the proliferation of sophisticated military capabilities. As these technologies become more accessible, they could fall into the hands of various actors, posing risks to regional and global security.

Read Original

WordPress is implementing an automated security review process for all plugin updates before they are distributed via the WordPress.org update API. Previously, only new plugins underwent a review, leaving updates vulnerable to potential security risks. This change aims to analyze each update for security issues, ensuring that users receive safer versions of plugins. David Perez from WordPress stated that this initiative is crucial as updates are continuously released, which could introduce risks if not properly vetted. By enhancing the security review process, WordPress seeks to protect its vast user base from potential threats associated with plugin vulnerabilities.

Read Original
Actively Exploited

A newly discovered malicious Twitch browser extension has been found to be forwarding OAuth tokens from users to a Russian bot service. This incident affects around 31,000 Twitch users, putting their accounts at risk. OAuth tokens are critical for accessing user accounts without needing to share passwords, so their exposure can lead to unauthorized access and potential account takeovers. Users of the affected extension should immediately remove it from their browsers, change their Twitch passwords, and consider revoking any third-party access to their accounts. This incident serves as a reminder for users to be cautious about the extensions they install and to regularly monitor their account activity for any suspicious behavior.

Read Original

The article discusses how attackers are increasingly using artificial intelligence to enhance their exploits and automate various aspects of cyberattacks. This includes using AI to test defenses and streamline their operations, which raises concerns about the potential for AI models to act beyond their intended parameters. Alongside these AI-related threats, familiar vulnerabilities continue to pose risks, with attackers exploiting outdated bugs and weak system configurations. The report also mentions specific incidents like the WeChat worm and PaperCut attacks, emphasizing the need for organizations to stay vigilant against both new and old security issues. The combination of advanced AI techniques and persistent vulnerabilities creates a challenging environment for cybersecurity.

Read Original
Actively Exploited

A human attacker exploited a remote code execution (RCE) vulnerability in Marimo, gaining access to an SSH bastion in just eight seconds. This rapid exploitation raises significant concerns about the security of systems using this technology, as it demonstrates how quickly attackers can breach defenses. The incident underscores the necessity for organizations to promptly patch vulnerabilities and enhance their security protocols. As the threat landscape continues to evolve, companies must remain vigilant and proactive in addressing potential weaknesses in their systems. This incident serves as a stark reminder of the importance of timely updates and security measures.

Read Original

Recent discussions have intensified around the risks associated with advanced artificial intelligence technologies. As AI models grow more powerful, experts are raising alarms about their potential misuse by individuals with malicious intentions. This includes fears that AI could be leveraged for cyberattacks, misinformation campaigns, and other criminal activities. The debate is not new, but the increasing capabilities of AI systems have made these concerns more pressing. Researchers and industry leaders are urging for a more cautious approach to AI development and implementation to mitigate these risks.

Read Original

Revolut has suffered a data breach that exposed personal and financial information of its users. The company inadvertently shared this sensitive data with a third party that was posing as a government agency. This incident raises significant concerns about the security of customer information and the potential for identity theft or fraud. Affected users may now face risks associated with their exposed data, which could include unauthorized transactions or other forms of financial exploitation. Revolut has not disclosed how many users were impacted or what specific information was leaked, but the incident underscores the need for strict verification processes when handling sensitive data.

Read Original

According to MarketsandMarkets, the cyber warfare market is expected to double by 2031 due to an increase in both defensive and offensive cyber capabilities within the military. This surge in spending is a direct response to the growing number of cyber attacks targeting military systems. As nation-states and other threat actors continue to refine their tactics, the military's need for advanced cybersecurity measures is becoming increasingly urgent. This shift not only impacts defense contractors but also raises concerns about national security and the protection of sensitive military information. The anticipated growth in this sector reflects a broader recognition of the critical role cybersecurity plays in modern warfare.

Read Original
Page 1 of 401Next