Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Hackers are exploiting two serious vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to bypass authentication, potentially enabling them to log in as site administrators without proper credentials. This poses a significant risk to websites using the affected plugin, as unauthorized access could lead to data breaches or site manipulation. WordPress site owners need to be aware of this security issue and take prompt action to secure their installations. It's crucial for users to update their plugins and monitor for any suspicious activity to mitigate these risks.

Read Original

A new bipartisan Senate bill aims to enhance the energy sector's defenses against emerging cyber threats posed by quantum computing. The legislation directs the Federal Energy Regulatory Commission (FERC) to take into account the potential risks from quantum computers and the need for post-quantum cryptography in its reliability standards. This is significant because quantum computing has the potential to break traditional encryption methods, which could leave critical infrastructure vulnerable. By proactively addressing these threats, the bill seeks to ensure that the energy sector can maintain its security and reliability in the face of rapidly evolving technology. This move illustrates a growing recognition among lawmakers of the need to prepare for future cybersecurity challenges.

Read Original

The Department of Defense has paused the implementation of CMMC Phase 2, which was intended to enhance cybersecurity standards among defense contractors. Despite this suspension, companies in the defense sector are still required to comply with existing cybersecurity requirements to protect sensitive information. This decision affects a wide range of contractors who must continue to meet the standards set by previous phases of the Cybersecurity Maturity Model Certification (CMMC). The pause raises questions about future compliance timelines and the overall effectiveness of cybersecurity measures within the defense supply chain. Contractors should stay informed and maintain their cybersecurity protocols to safeguard their systems against potential threats.

Read Original
Actively Exploited

Cybercriminals are exploiting the excitement surrounding the upcoming game, GTA VI, by distributing a fake 113GB build that contains malware. This malicious software is cleverly concealed within massive empty files, hiding a small but dangerous payload. Many eager fans are falling victim to this scam, with some even encouraging each other to download the file to verify the authenticity of the leaks. This situation raises significant concerns about user safety, as individuals risk infecting their own computers in pursuit of gaming news. It's a stark reminder that in the world of gaming, especially during hype periods, caution is essential to avoid malware traps.

Read Original

The National Institute of Standards and Technology (NIST) has identified 23 new security challenges that arise specifically in multi-cloud environments. This guidance is aimed at encouraging the cybersecurity community to address these unique risks, which can complicate data management and security protocols across different cloud platforms. As more organizations adopt multi-cloud strategies for flexibility and cost-effectiveness, understanding these challenges becomes critical to safeguarding sensitive information. NIST's call to action is particularly relevant for businesses that rely on multiple cloud services, as they face increased complexity in ensuring their data remains secure. The agency's emphasis on collaboration within the cyber community underscores the need for innovative solutions to these emerging issues.

Read Original

ReliaQuest, a cybersecurity company, has confirmed that an employee was targeted in a social engineering attack by hackers impersonating a member of their security team. This incident follows a previous breach involving the hacker group ShinyHunters, known for stealing and leaking data from various organizations. Although ReliaQuest has stated that no data was successfully stolen in this attempt, the incident raises concerns about the effectiveness of internal security protocols and employee training regarding social engineering tactics. It serves as a reminder of the ongoing risks that companies face from sophisticated phishing schemes and the need for vigilant security practices. The implications of such attacks can be significant, leading to potential data breaches and loss of trust among clients and partners.

Read Original

This week saw a rise in attacks leveraging AI to exploit Programmable Logic Controllers (PLCs), which are crucial in industrial automation. Researchers noted that trusted tools have been manipulated, making it easier for attackers to exploit existing vulnerabilities in these systems. Additionally, there were reported breaches involving GitLab, where sensitive data was compromised, and Stripe faced key leaks that could jeopardize user accounts. These incidents emphasize the need for companies to prioritize security measures and update their systems regularly to fend off these evolving threats. The implications are significant, as industries rely heavily on these technologies, and any exploitation can lead to serious operational disruptions.

Read Original

The OWASP Foundation has introduced the 'LLM Top 10', a list focused on vulnerabilities associated with Large Language Models (LLMs) that application security teams should be aware of. This list identifies potential risks such as data leakage, prompt injection, and model inversion attacks that can affect the integrity and confidentiality of applications using LLMs. Companies leveraging these models for various applications, including chatbots and automated content generation, need to understand these vulnerabilities to protect their systems. The growing use of LLMs in commercial products means that addressing these risks is crucial for maintaining user trust and ensuring the security of sensitive data. Organizations are encouraged to implement security measures and best practices to mitigate these vulnerabilities.

Read Original

A breach at a South Korean government-backed startup platform has exposed encrypted personal data due to a mismanaged encryption key that was inadvertently included in an API. This incident raises serious concerns about data protection practices, as the encryption key should have been kept separate from the sensitive information it was meant to secure. The exposure affects users of the platform, potentially compromising their personal information. Experts from Penta Security emphasize the critical need for companies to implement better key management practices to prevent such vulnerabilities. This breach serves as a reminder to all organizations about the importance of safeguarding encryption keys to protect user data effectively.

Read Original

Artificial intelligence is accelerating the discovery of cybersecurity vulnerabilities at a pace that outstrips the ability to fix them. This trend is occurring against a backdrop of stricter regulations aimed at improving cybersecurity standards. As more vulnerabilities are identified, the pressure is mounting on companies to address these issues promptly. Failure to keep up could leave organizations exposed to attacks, which could have serious implications for data security and compliance. The cybersecurity community is being urged to prioritize vulnerability management and ensure that remediation efforts keep pace with discovery.

Read Original

In July 2026, a suspected cyber attack linked to Iranian hackers caused a British power plant to go offline for four days. This incident raised concerns about the resilience of the UK's power grid and its ability to withstand cyber threats, especially given the timing of the attack coinciding with a similar incident affecting over 30 community water utilities in the United States. The shutdown of the power plant emphasizes the vulnerabilities present in critical infrastructure and the potential for significant disruption from foreign cyber actors. As the UK grapples with these mounting threats, it becomes increasingly important for authorities to assess and strengthen the security of essential services. This incident serves as a reminder of the ongoing risks posed by cyber attacks on vital infrastructure.

Read Original
Actively Exploited

Doubloon Dredger is a malicious campaign that exploits Notion and uses harmful PDFs to steal Microsoft authentication tokens. This means that attackers can gain unauthorized access to user accounts by intercepting the tokens, which are crucial for logging into Microsoft services. The campaign targets individuals and organizations that use Notion for collaboration and document management, potentially compromising sensitive information. Users are at risk of having their accounts hijacked, leading to data breaches and other security concerns. It's crucial for users to be cautious about the files they open and to ensure their security settings are up to date to mitigate this threat.

Read Original

The Dutch Data Protection Authority has imposed a hefty fine of 825 million euros on Uber for breaching the EU’s General Data Protection Regulation (GDPR). This penalty stems from the company's use of automated systems to suspend driver accounts without adequate justification. Many drivers were affected by these suspensions, which raised concerns about transparency and fairness in Uber's practices. The fine emphasizes the need for companies to comply with data protection laws and ensure that their automated processes do not violate individuals' rights. This incident serves as a reminder that regulatory bodies are actively monitoring compliance and are willing to impose significant penalties for violations.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities Catalog, specifically CVE-2026-21962, which affects Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. This vulnerability involves improper access control and has been linked to active exploitation, making it a significant risk for federal agencies and other organizations. CISA's Binding Operational Directive (BOD) 26-04 mandates that federal agencies prioritize fixing high-risk vulnerabilities like this one, especially on publicly exposed systems. While the directive is aimed at federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Companies are urged to act swiftly to mitigate this risk and report any additional vulnerabilities for consideration in the KEV Catalog.

Read Original

In 2023, the Spring Application Framework has seen significant security updates, with 91 vulnerabilities patched this year alone. This marks a notable increase compared to previous years, where only 16 vulnerabilities were addressed in 2025 and 22 in 2024. These vulnerabilities can potentially affect a wide range of applications built on the Spring Framework, which is widely used in enterprise software development. Developers and organizations utilizing Spring should prioritize updating to the latest versions to safeguard their applications. As cyber threats continue to evolve, keeping software up to date is crucial for maintaining security and protecting sensitive data.

Read Original
Page 1 of 363Next