Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Recent findings from Microsoft's Security Research team reveal that attackers have exploited a serious vulnerability in the Zimbra Collaboration Suite (ZCS). The flaw, identified as CVE-2026-73570, allows for unauthenticated command injection, leading to remote code execution. This means that attackers can deploy web shells to access sensitive mailbox data. Organizations using ZCS should be particularly vigilant, as this vulnerability carries a high severity score of 8.9. The fact that attackers are taking advantage of this flaw emphasizes the importance of keeping software updated and applying patches promptly to safeguard against potential data breaches.

Read Original

Cisco has issued a warning about a critical zero-day vulnerability affecting its Catalyst SD-WAN Manager, which is used by companies to oversee their SD-WAN networks. The flaw, identified as CVE-2026-76504, allows remote attackers to exploit the system's API without needing any login credentials, essentially granting them admin-level access. This poses a significant risk to organizations using this management software, as it could lead to unauthorized control and potential data breaches. Cisco has released patches to fix the issue, but there are no workarounds available for users who need immediate protection. Companies are urged to apply the fixes as soon as possible to mitigate the risk of exploitation.

Read Original

Cybercriminals are exploiting ChatGPT's Custom GPTs feature to trick users into visiting harmful websites. These sites use ClickFix lures to deliver Remote Access Trojans (RATs), which can take control of victims' devices. This tactic was observed by Huntress in late September 2026 and represents a concerning trend where trusted AI platforms are manipulated to spread malware. Users who interact with these malicious GPTs may unknowingly expose their systems to significant risks. This incident serves as a reminder for individuals and organizations to be cautious when engaging with AI-driven tools and to verify the legitimacy of any offerings before clicking links.

Read Original

The article discusses emerging security risks associated with persistent AI coworkers, which operate continuously and often have standing access to systems. This creates identity risks that current security models are not equipped to handle. Experts from Token Security emphasize the need for these AI agents to have their own distinct identities, designated owners, and carefully scoped permissions to mitigate potential security issues. Additionally, implementing lifecycle controls for these agents is crucial to ensure that they do not pose an ongoing risk. As AI increasingly integrates into workplaces, addressing these identity and access challenges is vital to protect sensitive information and maintain organizational security.

Read Original

TeamViewer has issued an urgent warning for users to update their remote access software due to the discovery of several high-severity vulnerabilities in both its client and host applications. These flaws could potentially allow unauthorized access or control over user systems, putting sensitive data at risk. Users of TeamViewer are strongly advised to apply the patches as soon as possible to protect against potential exploitation. The vulnerabilities affect multiple versions of the software, which means that a wide range of users could be impacted. Failing to address these issues promptly could lead to serious security breaches for individuals and businesses alike.

Read Original

A recent report from security firm Glow revealed that AI coding agents inadvertently exposed over 13,000 internal images on public GitHub repositories. These images, belonging to developers from more than 300 organizations, included sensitive information such as customer billing records and unreleased feature screenshots. The issue primarily arose from developers using their personal GitHub accounts to share code review screenshots. This incident raises serious concerns about data privacy and security, as sensitive company information is now publicly accessible. Organizations need to reassess their use of AI tools and ensure that proper security measures are in place to protect internal data.

Read Original
Actively Exploited

Bitget, a cryptocurrency exchange, reported a significant security breach where attackers stole $387.5 million by exploiting a zero-day vulnerability in third-party security products. This incident raises serious concerns about the reliability of third-party security solutions, especially in the cryptocurrency sector where security is paramount. The breach underscores the importance of continuous monitoring and updating of security systems to prevent similar attacks. Users and investors need to be aware of the potential risks associated with using exchanges that may be vulnerable to such exploits. This incident serves as a stark reminder of the evolving tactics employed by cybercriminals and the need for robust security measures in digital finance.

Read Original
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

The Hacker News

Actively Exploited

Recently, researchers uncovered a serious vulnerability in Citrix NetScaler ADC and Gateway, identified as CVE-2026-88772, which has a CVSS score of 9.5. This flaw, categorized as a memory overflow issue in the Datagram Transport Layer Security (DTLS) protocol, allows attackers to execute shellcode without prior authentication. The vulnerability is currently being exploited in the wild, putting organizations using affected versions of Citrix NetScaler at significant risk. Companies should prioritize applying the latest security patches to safeguard their systems, as failure to do so could lead to unauthorized access and potential data breaches.

Read Original

A recently patched vulnerability in Unsloth Studio allows attackers to execute arbitrary Python code when inspecting AI models due to a misconfiguration in the trust_remote_code setting. This flaw can be exploited by malicious AI models, which poses a significant risk to users who rely on the platform for model evaluation and testing. The issue highlights the importance of secure coding practices and proper configuration management in AI development. Users of Unsloth Studio should ensure they apply the latest patches to mitigate this risk and safeguard their systems against potential exploitation. The vulnerability's existence raises concerns about the security of AI models and the potential for harmful code execution in environments that are supposed to be trusted.

Read Original

The FBI has issued a warning to members of the ShinyHunters extortion group, urging them to turn themselves in following the arrest of a man in the Netherlands believed to be a leader of the group. ShinyHunters is known for stealing and selling sensitive data from various companies. The arrest marks a significant development in the efforts to dismantle this cybercriminal organization, which has been linked to numerous data breaches and extortion attempts. Law enforcement is sending a clear message that individuals involved in such criminal activities may face serious consequences. This situation serves as a reminder of the ongoing challenges posed by cyber extortion groups and the importance of cybersecurity vigilance for businesses and individuals alike.

Read Original
Actively Exploited

Cybersecurity experts have reported that attackers are exploiting a zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772. This vulnerability allows hackers to deploy custom web shells and tunneling malware, which can lead to root access on affected systems. Once inside, attackers can steal credentials and move laterally across internal networks, posing a significant risk to organizations that rely on Citrix products. This incident is particularly concerning given the potential for widespread credential theft and internal network compromise. Organizations using Citrix NetScaler should take immediate action to assess their security posture and apply any available patches or mitigations.

Read Original

Two former members of the U.S. Air Force have been sentenced to a total of 189 months in federal prison for their involvement in a series of business email compromise (BEC) scams and phishing campaigns that spanned several years. These scams tricked businesses into transferring large sums of money by impersonating company executives or trusted partners through compromised email accounts. The actions of these individuals not only caused financial harm to various businesses but also highlighted the vulnerabilities in email communication systems. This case serves as a warning to organizations about the importance of email security and the need for robust verification processes to prevent similar attacks in the future.

Read Original

The Defense Advanced Research Projects Agency (DARPA) has selected Xint to enhance the security of military messaging applications using artificial intelligence. As the winner of the AIxCC competition, Xint will focus on analyzing the code and compiled binaries of these messaging apps for potential vulnerabilities. This new approach not only aims to protect military communications but could also benefit commercial software security. The implications are significant, as securing military messaging systems is critical for national security and operational integrity. By identifying weaknesses proactively, the initiative seeks to bolster defenses against potential cyber threats.

Read Original

Researchers from VUSec and Scuola Superiore Sant'Anna have identified a new variant of the Spectre vulnerability, known as Branch Target Reuse (BTR). This variant specifically targets Just-In-Time (JIT) engines found in web browsers, programming language runtimes, and even the operating system kernel. Affected systems span multiple CPU vendors, which raises concerns for a wide range of software and hardware users. This discovery is significant because it shows that even with existing defenses against Spectre, new methods can still leak sensitive information from memory. As these vulnerabilities can potentially expose user data, it's crucial for companies and developers to remain vigilant and update their systems as necessary.

Read Original
Actively Exploited

RatHat's command and control (C2) panel has been upgraded to build malware and utilize artificial intelligence to rank potential victims. This system is currently operational across nearly 100 deployments, indicating a significant expansion in its capabilities. The use of AI in this context suggests that attackers are becoming more sophisticated, enabling them to target victims more effectively. This development poses a serious risk to organizations, as it may lead to more tailored and damaging attacks. Companies and individuals should be aware of these evolving threats and take appropriate cybersecurity measures to protect themselves.

Read Original
Page 1 of 427Next