Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A significant security vulnerability in Cisco's Catalyst SD-WAN Manager has been exploited by attackers months before its public disclosure. The flaw, which was revealed in early June, was reportedly being used in attacks as early as March. This situation raises serious concerns for organizations using Cisco's SD-WAN technology, as they may have been at risk for an extended period without knowledge of the threat. Companies are urged to review their systems and apply any available patches to mitigate potential risks. The exploitation of this vulnerability highlights the importance of timely disclosures and the need for vigilance in monitoring systems for suspicious activity.

Impact: Cisco Catalyst SD-WAN Manager
Remediation: Organizations should apply the latest patches from Cisco for the Catalyst SD-WAN Manager.
Read Original

Australia's Security and Intelligence Organisation (ASIO) has created specialized teams to address cyber sabotage threats from nation-states targeting the country's critical infrastructure. This move, announced by ASIO Director-General Mike Burgess, reflects increasing concerns about foreign interference and cyber attacks aimed at essential services and systems. By focusing resources on these dedicated units, ASIO aims to enhance its capabilities in detecting and mitigating potential cyber incidents that could disrupt public safety and national security. This development is particularly important as nations globally face rising cyber threats, making it crucial for Australia to strengthen its defenses against such risks.

Impact: Australia's critical infrastructure systems
Remediation: N/A
Read Original

Account takeover attacks remain a significant challenge for organizations as attackers often exploit legitimate accounts and trusted services to gain unauthorized access. This issue complicates detection and response efforts for security teams. A recent webinar discussed how behavioral AI can enhance the identification of compromised accounts, enabling quicker responses to these incidents. The focus is on using advanced technology to automate workflows that can mitigate the risks associated with account takeovers. As these attacks can lead to severe data breaches and financial losses, understanding and addressing them is crucial for businesses and their customers.

Impact: Legitimate accounts on various online platforms
Remediation: Implement behavioral AI solutions to monitor account activity and automate response workflows.
Read Original

Cal Water, a utility in California, recently investigated a cyberattack attributed to the Iranian hacker group Handala. Despite the hackers claiming they could disrupt the water supply, Mandiant, the cybersecurity firm assisting in the investigation, found no evidence of any operational technology (OT) activity being compromised. This incident raises concerns about the security of critical infrastructure, especially given the attackers' bold claims. While the immediate threat appears to be contained, it serves as a reminder for utilities and other essential services to remain vigilant against potential cyber threats. Ensuring the integrity of water supplies is crucial for public safety and trust.

Impact: Cal Water, operational technology systems
Remediation: N/A
Read Original
Suspected Cyberattack Sends Fake Emergency Alert to Phones Across Brazil

Hackread – Cybersecurity News, Data Breaches, AI and More

A suspected cyberattack in Brazil has led to a fake emergency alert being sent to mobile phones across the country. In response to this incident, officials have taken the national alert system offline while they investigate the breach. The alert, which falsely warned of an emergency, has raised concerns about the security of communication systems and the potential for panic among the public. This incident highlights vulnerabilities in emergency notification systems and the importance of robust cybersecurity measures to protect against such attacks. Authorities are currently examining how the breach occurred and what can be done to prevent future incidents.

Impact: Brazil's national emergency alert system
Remediation: Taking the national alert system offline for investigation
Read Original

Recent research has explored how large language models (LLMs) are vulnerable to prompt injection attacks. The study reveals that LLMs don't just respond to role tags but also learn to recognize the style of text in different instruction blocks. This means that attackers could manipulate LLMs by using innocuous-seeming text to subtly influence their responses. The researchers argue that without a true understanding of roles, defenses against prompt injection will be an ongoing challenge. This is significant because it exposes a fundamental weakness in LLMs that could lead to misuse in various applications, affecting users and developers alike.

Impact: Large Language Models (LLMs)
Remediation: Developers should enhance role perception in LLMs to improve defenses against prompt injection.
Read Original

Richard Bejtlich discusses the challenges that security operations teams face when investigating incidents, despite having access to a wealth of telemetry data. Many teams struggle to answer fundamental questions about what happened, what evidence they have, and whether they're seeing the complete picture. Bejtlich emphasizes the need for teams to move beyond just relying on alerts for initial triage and to adopt a more thorough investigative approach. This shift is crucial for improving incident response and ensuring that security teams can effectively protect their organizations from potential threats.

Impact: N/A
Remediation: N/A
Read Original

A recently discovered flaw in macOS allows standard users to disable Endpoint Detection and Response (EDR) and Mobile Device Management (MDM) features, which are critical for maintaining device security and management. This vulnerability could be exploited by malicious actors to weaken security controls, making it easier for them to execute attacks or gain unauthorized access to sensitive data. All macOS versions that support EDR and MDM functionalities are affected. Organizations using these features should be particularly vigilant, as the ability for unauthorized users to disable such protections can lead to significant security risks. As of now, there is no indication that this vulnerability is being actively exploited in the wild, but the potential for misuse remains a concern for IT departments.

Impact: macOS versions with EDR and MDM features
Remediation: Users should ensure that EDR and MDM settings are monitored regularly and consider implementing additional access controls to prevent unauthorized changes.
Read Original

Kaspersky researchers have examined the growing cybersecurity threats facing small and medium-sized businesses (SMBs) in 2026. They found that attacks using fake artificial intelligence tools are on the rise, alongside traditional phishing schemes. These tactics are particularly concerning as they can lead to data breaches and the sale of sensitive information on the dark web. SMBs, which often lack the resources of larger corporations, are especially vulnerable to these types of attacks. Companies need to enhance their security measures and educate employees about recognizing scams to protect themselves against these evolving threats.

Impact: N/A
Remediation: N/A
Read Original

Curl, the widely used open-source data transfer tool, has patched a vulnerability that has existed for 25 years. This update also addresses a total of 18 medium and low-severity vulnerabilities. The fixes are crucial for developers and organizations that rely on Curl for transferring data over various protocols, as these vulnerabilities could potentially be exploited if left unaddressed. Users of Curl should ensure they update to the latest version to protect their systems and data from possible attacks. Regular updates are essential in maintaining security, especially with tools that have been in use for such a long time.

Impact: Curl versions prior to the latest release.
Remediation: Users should update to the latest version of Curl to apply the patch.
Read Original

A serious vulnerability in Cisco Catalyst SD-WAN, identified as CVE-2026-20245, has been exploited by hackers for months before it was publicly disclosed. This flaw, which has a CVSS score of 7.8, allows authenticated attackers to execute privileged commands on affected systems. Google-owned Mandiant reported that the exploitation occurred at least two months prior to the disclosure, raising concerns about the security of networks using this technology. Organizations using Cisco Catalyst SD-WAN should take immediate action to secure their systems, as this vulnerability poses a significant risk to network integrity. The incident serves as a reminder of the importance of timely disclosure and patch management in cybersecurity.

Impact: Cisco Catalyst SD-WAN
Remediation: Organizations should apply the latest security updates from Cisco for the Catalyst SD-WAN and ensure that all systems are patched against CVE-2026-20245. Regularly monitor for any updates from Cisco regarding this vulnerability and implement additional security measures such as network segmentation and strict access controls.
Read Original

Entrust has launched a new biometric authentication solution designed to enhance security during high-risk transactions such as account recovery and large purchases. As cybercriminals increasingly target these vulnerable moments, traditional authentication methods are proving inadequate. The new system aims to confirm the identity of users more effectively, reducing the risk of account takeovers. By focusing on verifying the individual behind a transaction rather than just granting access, Entrust hopes to strike a balance between security and user experience. This advancement is crucial for organizations looking to prevent fraud while maintaining a seamless process for their customers.

Impact: Entrust's Biometric Authentication solution
Remediation: Organizations should implement Entrust's Biometric Authentication solution to enhance security during high-risk transactions.
Read Original

A new backdoor known as Mistic has been discovered in a series of financially motivated cyberattacks targeting organizations across various sectors, including insurance, education, IT, and professional services. This backdoor, also referred to as MLTBackdoor, has been linked to an initial access broker called KongTuke. Researchers from Symantec and Carbon Black's Threat Hunter Team have traced the deployment of Mistic back to April 2026. The stealthy nature of this backdoor raises concerns as it allows attackers to infiltrate systems undetected, potentially leading to data theft or other malicious activities. Organizations in the affected sectors should be on high alert and strengthen their cybersecurity measures to combat this emerging threat.

Impact: Organizations in insurance, education, IT, and professional services sectors
Remediation: Organizations should enhance their cybersecurity protocols, monitor for unusual activity, and consider implementing advanced threat detection systems.
Read Original

The National Institute of Standards and Technology (NIST) has opened up its updated guidance on Internet of Things (IoT) security for public review. This guidance is designed to set cybersecurity standards for IoT devices used in federal agencies' networks. By establishing clear product requirements, NIST aims to enhance the security posture of these devices, which are increasingly integrated into critical government operations. The public review period allows stakeholders, including industry experts and the general public, to provide input on the proposed guidelines. This initiative is significant as it addresses growing concerns over the vulnerabilities associated with IoT devices, which can be entry points for cyberattacks.

Impact: IoT devices used in federal agencies' networks
Remediation: N/A
Read Original

A recently discovered vulnerability in Cisco Catalyst SD-WAN has been exploited by an unknown attacker for at least two months before its public disclosure. This security flaw, identified as CVE-2026-20245, has a high severity rating of 7.8 and allows an authenticated local attacker to execute arbitrary commands with elevated privileges. This means that if an attacker gains access to a system, they could potentially take control of critical functions within the network. Companies using Cisco Catalyst SD-WAN should be aware of the risk posed by this vulnerability and take immediate action to protect their systems. The findings from Mandiant underscore the importance of timely patching and monitoring for unusual activity in network environments.

Impact: Cisco Catalyst SD-WAN
Remediation: Companies should apply any available patches for the Cisco Catalyst SD-WAN and closely monitor their systems for unauthorized access attempts. Regular updates and security audits are recommended to mitigate risks associated with this vulnerability.
Read Original
Page 1 of 233Next