Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Recent discussions have intensified around the risks associated with advanced artificial intelligence technologies. As AI models grow more powerful, experts are raising alarms about their potential misuse by individuals with malicious intentions. This includes fears that AI could be leveraged for cyberattacks, misinformation campaigns, and other criminal activities. The debate is not new, but the increasing capabilities of AI systems have made these concerns more pressing. Researchers and industry leaders are urging for a more cautious approach to AI development and implementation to mitigate these risks.

Read Original

Revolut has suffered a data breach that exposed personal and financial information of its users. The company inadvertently shared this sensitive data with a third party that was posing as a government agency. This incident raises significant concerns about the security of customer information and the potential for identity theft or fraud. Affected users may now face risks associated with their exposed data, which could include unauthorized transactions or other forms of financial exploitation. Revolut has not disclosed how many users were impacted or what specific information was leaked, but the incident underscores the need for strict verification processes when handling sensitive data.

Read Original

The article discusses how the rapid discovery of vulnerabilities, particularly in the context of artificial intelligence, has outpaced the ability of cybersecurity defenders to assess which ones require urgent attention. In the first half of 2026 alone, over 35,000 Common Vulnerabilities and Exposures (CVEs) were published, marking a significant increase from previous years. This surge creates a dilemma for security teams who must prioritize their responses amid an overwhelming volume of findings. The focus is on the need for improved validation processes to help defenders identify which vulnerabilities pose the greatest risk. As the landscape evolves, organizations need to adapt their strategies to effectively manage these vulnerabilities and protect their systems.

Read Original

Revolut, a fintech company, has reported a data breach involving the exposure of sensitive customer information. Attackers managed to impersonate a government agency and trick Revolut into sharing data from an unspecified number of customers. The breach has resulted in the potential compromise of financial information and passport details. This incident raises significant concerns about the security of customer data and the effectiveness of identity verification processes used by financial institutions. Customers of Revolut should be vigilant and monitor their accounts for any unusual activity as the company investigates the breach and works to enhance its security measures.

Read Original
Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are actively exploiting a high-severity vulnerability in GitLab. This flaw could allow attackers to take control of affected systems, which poses significant risks for organizations using the platform. GitLab users must be vigilant, as the vulnerability is being targeted in the wild. It’s crucial for companies to apply any available patches or updates to secure their systems. Failure to address this issue could lead to unauthorized access and data breaches, impacting the integrity of their operations.

Read Original

Researchers at KTH Royal Institute of Technology created a model of an industrial network to test its defenses against cyber attacks. Over 14 days, they simulated multiple attacks and analyzed the network traffic to train a defense agent. This agent monitors packet counts across different segments of the network, allowing it to detect intruders' movements and decide when to intervene. This study is significant because it explores proactive defense mechanisms in critical infrastructure, which is increasingly vulnerable to cyber threats. As industries rely more on interconnected systems, enhancing security measures like this could help protect essential services from potential disruptions.

Read Original

A recent survey by ManageEngine, which involved 700 IT and cybersecurity leaders from the US and Canada, reveals that organizations tend to lose focus on cybersecurity shortly after experiencing a breach. Despite the overwhelming majority, 91%, expressing confidence in their current cybersecurity measures, only 8% believe that cybersecurity will remain a top priority once the immediate crisis is over. This trend indicates that while breaches prompt a temporary spike in security attention, organizations often revert to their previous practices and priorities, potentially leaving them vulnerable to future incidents. The findings suggest that a more sustained commitment to cybersecurity is necessary to effectively mitigate risks. This situation is concerning for both organizations and their stakeholders, as it may lead to increased exposure to cyber threats over time.

Read Original

A recent report from DigiCert warns that the shift to 47-day public TLS certificates by 2029 will significantly increase the burden of certificate management for businesses. Organizations will face the need to renew certificates over eight times more frequently than before and will have to perform domain validations 40 times more often. This change could lead to costly outages, with failures potentially costing companies upwards of $250,000. The report emphasizes that companies should prepare for these challenges to avoid disruptions that can impact business operations. Proper certificate management is essential to prevent unexpected downtime and financial losses.

Read Original

AWS has launched a new tool called the Deception Benchmark, designed to evaluate how effectively AI models can differentiate between real security vulnerabilities and benign code that may appear risky. This initiative aims to help researchers and security teams better understand the limitations of AI in vulnerability detection. High rates of false positives—instances where safe code is incorrectly flagged as a threat—can lead to increased workloads and alert fatigue for security professionals, potentially undermining trust in AI-driven solutions. By making this dataset publicly available, AWS hopes to streamline the research process and improve the overall efficacy of AI in security tasks such as vulnerability triage and incident response. This is significant as companies increasingly rely on AI for their cybersecurity efforts, and addressing false positives is crucial for maintaining confidence in these systems.

Read Original
Actively Exploited

The latest issue of the Security Affairs Malware newsletter covers significant developments in malware research. One notable focus is on REVSTEALER, which is ramping up its activities, posing a risk to users through information theft. Researchers also discuss techniques for deobfuscating JSCeal’s compiled V8 bytecode, which could help security professionals better understand and combat this malware. Additionally, the DPRK APT group has been linked to the Ted backdoor and curlRAT, which are targeting South Korean media and automotive sectors. These findings emphasize the ongoing challenges that organizations face in defending against sophisticated malware attacks.

Read Original
Actively Exploited

A group of hackers associated with a China-aligned espionage unit is taking advantage of a serious vulnerability in Tencent's Sogou Input Method for Windows, identified as CVE-2026-51990. This flaw allows attackers to install the GrayRabbit backdoor, which can give them unauthorized access to infected systems. The Sogou Input Method is widely used for typing Chinese characters, meaning a large number of users could be at risk. It's crucial for Tencent to address this vulnerability quickly to protect users from potential data breaches and espionage activities. Organizations using this software should prioritize patching and monitoring their systems for any unusual activity.

Read Original

Dario Amodei, the CEO of Anthropic, has raised concerns about the rapid advancement of artificial intelligence and its potential risks. He warns that within the next six to twelve months, AI systems could become capable of coordinating large groups of agents that might compromise the entire internet. This situation underscores the urgent need for the AI industry to develop and implement effective safety measures before these technologies become too powerful. Amodei's comments highlight the balance that must be struck between innovation and safety in AI development. As AI capabilities grow, the industry must prioritize security to prevent misuse that could lead to widespread disruption.

Read Original
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 Hours

Security Affairs

Actively Exploited

GitLab disclosed a severe vulnerability, CVE-2026-85706, on September 10, 2026, which has a maximum severity score of 10.0. This path traversal flaw affects the repository commits API, allowing attackers to read files that should remain inaccessible without authentication. Within just 24 hours of the public announcement, malicious actors began exploiting this vulnerability, raising concerns about the security of GitLab instances. Organizations using GitLab should prioritize patching this vulnerability to protect sensitive information from unauthorized access, as attackers can exploit the flaw with a single crafted HTTP request. The rapid exploitation of this vulnerability underscores the need for timely updates and proactive security measures in software development environments.

Read Original

Microsoft has reported two recent phishing campaigns where attackers exploited third-party email services to send out fraudulent messages. Between August 3 and 5, 2026, more than a million scam emails were dispatched, impersonating CEOs to deceive recipients. These campaigns utilized social engineering tactics focused on passkeys to gain unauthorized access to Microsoft cloud accounts, leading to potential data breaches. As a result, both individuals and organizations using Microsoft cloud services could be at risk of financial fraud and data exfiltration. This incident underscores the ongoing challenges in cybersecurity, particularly in safeguarding sensitive information against increasingly sophisticated phishing attempts.

Read Original

Last week, a Linux rootkit was discovered on F5 BIG-IP APM devices, raising significant security concerns for organizations relying on this technology. The rootkit allows attackers to gain unauthorized access and control over affected systems, potentially leading to data breaches or further attacks. Additionally, vulnerabilities in Cisco's FMC (Firepower Management Center) were actively exploited, putting users at risk of unauthorized access and manipulation of security policies. These incidents highlight the need for organizations to ensure their devices are updated and secured against such threats. Companies should prioritize patching and monitoring their systems to mitigate these risks.

Read Original
Page 1 of 400Next