Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

BleepingComputer

Actively Exploited

Cisco has confirmed that a serious authentication bypass vulnerability, labeled CVE-2026-20079, exists in its Secure Firewall Management Center (FMC) software. This flaw allows attackers to bypass authentication mechanisms, putting systems at risk of unauthorized access. Cisco has noted that this vulnerability is currently being exploited in active attacks, which raises significant concerns for organizations using their firewall management solutions. Users of Cisco's Secure FMC should take immediate action to protect their systems, as the potential for data breaches and unauthorized activities is heightened. The situation emphasizes the need for prompt updates and vigilance in cybersecurity practices.

Read Original

AdaptHealth, a healthcare company, has confirmed that a cyberattack in July exposed the personal information of 4.1 million individuals. The breach was linked to the ShinyHunters threat group, known for targeting various organizations. While the specific details about the type of data compromised have not been disclosed, such breaches in the healthcare sector raise significant concerns about patient privacy and data security. AdaptHealth's incident underscores the ongoing risks that healthcare companies face from cybercriminals. Users whose data may have been compromised should remain vigilant for potential phishing attempts or other scams that could arise from this breach.

Read Original

Recent reports indicate that several Chinese espionage groups are actively exploiting a series of zero-day vulnerabilities, targeting various organizations. These vulnerabilities are linked in a 'triple-link chain,' which makes them particularly dangerous as attackers can leverage multiple weaknesses simultaneously. Proofpoint has noted that the exploitation is ongoing and anticipates that the scope of these attacks will expand further. Organizations should be vigilant and assess their security measures to protect against these threats, as the risk of data breaches and espionage increases with such active exploitation. The situation underscores the need for enhanced monitoring and prompt patch management to safeguard sensitive information.

Read Original

Lawmakers are urging the U.S. Treasury to impose sanctions on groups that are allegedly engaging in hacking-for-hire activities targeting American citizens and businesses. Among those affected is the wife of Mike Rogers, a GOP Senate candidate in Michigan, highlighting the personal stakes involved in this issue. The call for sanctions comes amid rising concerns over the impact of these hackers on national security and public safety. By sanctioning these groups, lawmakers hope to deter future cyberattacks and protect individuals from becoming victims. This situation illustrates the growing threat posed by mercenary hackers and the need for a strong governmental response to such cybercrime.

Read Original

The U.S. Department of Justice has taken significant steps to disrupt an online scam marketplace known as Xinbi Guarantee. This platform was involved in offering various scam services through Telegram channels. As part of the operation, authorities seized two cryptocurrency wallets containing approximately $52.8 million and deployed a specialized team to Madagascar to dismantle 13 scam compounds linked to Chinese organized crime. This crackdown not only aims to halt ongoing scams but also serves as a warning to those involved in similar illicit activities. The incident highlights the growing international efforts to combat online fraud and the role of cryptocurrency in facilitating these operations.

Read Original

U.S. cybersecurity and intelligence agencies have reported that six Chinese AI companies have been conducting large-scale distillation attacks on American frontier AI models since at least late 2024. These attacks involve extracting valuable data and insights from advanced AI systems, which could give the attackers a competitive edge in AI development. The U.S. authorities are concerned about the implications of this activity, as it not only threatens intellectual property but also raises national security issues. This incident highlights the ongoing tensions between the U.S. and China regarding technology and innovation. Companies involved in AI development should be particularly vigilant about protecting their models from such attacks.

Read Original

Veradigm, a healthcare technology company, has reported a data breach linked to a ransomware attack on one of its third-party vendors. This incident has resulted in the exposure of personal information belonging to patients, raising significant concerns about privacy and security in the healthcare sector. The breach was acknowledged after a ransomware group claimed responsibility for the attack, highlighting the vulnerabilities that can arise from third-party partnerships. Patients whose data may have been compromised include those who used services associated with Veradigm and its vendor. This incident underscores the need for stronger security measures across all levels of healthcare technology providers to protect sensitive patient information.

Read Original

Brett Leatherman, the FBI's cyber chief, expressed concerns about the private sector's reluctance to share information about cyber threats. He noted that many companies misunderstand how the FBI uses data collected during cyber incidents. This data is essential for aiding victims and supporting investigations. The lack of information sharing could hinder efforts to combat cybercrime effectively and protect businesses from future attacks. By collaborating more openly, the private sector can enhance collective cybersecurity efforts and better defend against evolving threats.

Read Original

A new cybersecurity threat known as 'workflow identity hijacking' has emerged, allowing attackers to bypass standard security measures and gain access to an organization's sensitive data. This type of attack exploits unauthenticated entry points by sending seemingly benign requests, which can lead to significant data breaches. Organizations that rely on automated workflows are particularly at risk, as these systems often have less stringent access controls. The implications of such attacks are severe, as they can compromise valuable enterprise information and disrupt business operations. Companies should review their authentication processes and security protocols to prevent such vulnerabilities.

Read Original
Actively Exploited

Multi-factor authentication (MFA) is generally considered a strong defense against account takeovers, but attackers are now focusing on exploiting weaknesses in account recovery processes. Researchers from Specops point out that the methods used to reset passwords and alter authentication methods are becoming the new targets for social engineering attacks. This shift means that even with MFA in place, users can still fall victim if their recovery options are compromised. The article emphasizes the necessity for more stringent identity verification practices at service desks to thwart these types of attacks. Strengthening these processes is crucial to preventing unauthorized access to accounts, which can lead to significant data breaches and financial losses.

Read Original

FBI officials have warned that artificial intelligence is enhancing the capabilities of cyber adversaries, making it easier for them to launch attacks. During discussions at the Billington CyberSecurity Summit and in an interview with CyberScoop, they emphasized the need for organizations to focus on fundamental cybersecurity practices, such as regular software patching. The FBI's new cyber strategy highlights that while AI can be a powerful tool for defense, it is also being misused by criminals. This situation calls for heightened vigilance and a return to basic security measures to protect against evolving threats. Companies and individuals must prioritize these practices to mitigate risks associated with AI-driven attacks.

Read Original

According to a report by SpyCloud, non-human identities have become the primary entry point for hackers targeting corporations. These identities, often associated with automated accounts or bots, present a significant risk as they can easily bypass traditional security measures. This trend indicates that companies need to enhance their defenses against these types of attacks, as they can lead to unauthorized access and potential data breaches. The findings suggest a shift in tactics among cybercriminals, who are increasingly using these non-human identities to infiltrate systems. Businesses should reevaluate their security protocols to address this emerging threat and better protect sensitive information.

Read Original

US intelligence agencies have raised concerns that China is actively extracting advanced artificial intelligence capabilities from foreign models through a method known as distillation. This process involves capturing the outputs and reasoning of existing AI models to create new ones, effectively allowing China to enhance its own AI technologies without directly developing them. The implications of this practice are significant, as it could allow China to gain a competitive edge in AI, which is increasingly important for national security and economic power. This situation calls for vigilance among US companies and researchers to protect their intellectual property and ensure that their AI advancements are not compromised. Understanding and addressing these tactics is crucial for maintaining a technological advantage.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating that these flaws are currently being exploited in the wild. The vulnerabilities include a heap-based buffer overflow in Fortinet products (CVE-2025-25249), an authentication bypass in Citrix NetScaler (CVE-2026-19490), an out-of-bounds write in Google Chromium's V8 engine (CVE-2026-87491), and another authentication bypass affecting Cisco Firewall Management Center (CVE-2026-20079). These vulnerabilities pose significant risks, especially to federal agencies, which are urged to prioritize quick remediation efforts based on a directive from CISA. While the directive primarily affects federal entities, CISA encourages all organizations to adopt similar risk-based practices to address these vulnerabilities effectively. Organizations are also invited to report any exploited vulnerabilities not yet listed in the KEV Catalog for evaluation.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has released an updated guide aimed at helping organizations mitigate insider threats that can arise in both physical and cyber environments. This guide provides new insights and strategies for identifying and addressing risks posed by employees or contractors who may intentionally or unintentionally compromise security. The update emphasizes the importance of a proactive approach, advising companies to implement measures that promote a culture of security awareness and to establish clear reporting mechanisms for suspicious activities. This guidance is crucial for organizations looking to enhance their security posture in an age where threats can come from within as well as from external attackers. The implications of not addressing these threats can lead to significant data breaches and financial losses.

Read Original
Page 1 of 393Next