Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

IQVIA, a healthcare data analytics company, has been fined €7 million (about $7.8 million) by Italy's Data Protection Authority for failing to adequately anonymize health data. The GPDP reported that this lapse in data processing practices potentially exposed the personal information of around one million patients, raising serious concerns about privacy and data security. The fine signals a growing scrutiny on companies handling sensitive health information and emphasizes the need for robust data protection measures. In an era where personal data is increasingly vulnerable to breaches, this incident serves as a reminder for organizations to prioritize compliance with data protection regulations to safeguard patient information. The implications of this case could lead to stricter enforcement of data privacy laws across Europe and beyond.

Read Original

Microsoft has issued urgent security updates to fix a serious vulnerability in Microsoft Exchange Server, identified as CVE-2026-96940. This flaw allows attackers who already have access to the server to gain elevated privileges, potentially enabling them to access other users' mailboxes. Rated 8.8 on the CVSS scale, this vulnerability poses a significant risk to organizations using affected versions of Exchange Server. Companies need to apply the updates promptly to protect sensitive information and maintain user privacy. Failing to address this issue could lead to unauthorized access and data breaches.

Read Original

This week, several cybersecurity threats have emerged, particularly involving vulnerabilities in NetScaler and FortiMail. These zero-day vulnerabilities are actively exploited, allowing attackers to gain unauthorized access to systems. Additionally, there are concerns regarding AI coding leaks that could expose sensitive information, alongside ongoing issues with Spectre v2 vulnerabilities that affect various processors. Law enforcement has also made strides in tackling ransomware, leading to arrests that could disrupt ongoing attacks. Organizations using affected systems need to prioritize patching and enhancing their security measures to mitigate these risks.

Read Original

Researchers have reported that attackers are trying to exploit a serious vulnerability in the Realtek Jungle software development kit (SDK). This flaw has already been patched, but the exploitation attempts aim to deploy a malware botnet named Cling. What makes Cling notable is its use of standard STUN (Session Traversal Utilities for NAT) protocols to create a command-and-control channel, which is an unusual method for botnet communication. This situation raises concerns for companies using the affected SDK, as it emphasizes the need for timely updates and vigilance against emerging threats. Users and organizations should ensure they have applied all relevant security patches to prevent potential exploitation.

Read Original

Google has paused its Open Source Software Vulnerability Rewards Program (OSS VRP) due to a surge in AI-generated spam reports. This program was designed to reward individuals who identify vulnerabilities in open-source software. The influx of low-quality, AI-generated submissions overwhelmed the review process, prompting Google to halt new entries. This decision affects researchers and developers who rely on the program to report genuine vulnerabilities and earn rewards. It raises concerns about the effectiveness of bug bounty programs in the face of advanced AI tools that can generate misleading or irrelevant reports.

Read Original

A serious security vulnerability in Rejetto's HTTP File Server (HFS), tracked as CVE-2026-61500, is currently being exploited by attackers. This flaw, which has a CVSS score of 9.3, arises from a weak pseudo-random number generator that allows for session forgery. Essentially, this means that an attacker can predict the session key, granting them unauthorized access to the server. The vulnerability poses a significant risk to users of HFS, as it can lead to remote code execution, allowing attackers to execute commands on the server. Organizations using this software need to take immediate action to protect their systems from potential exploitation.

Read Original

David Robinson, a safety veteran at OpenAI, has resigned and voiced concerns about the company's culture and its rapid pace of AI development. In his resignation essay, he expresses worries that the current environment at OpenAI could lead to significant risks in AI safety, suggesting that the company's drive for innovation may overlook critical safety measures. Robinson's departure is notable because it reflects broader concerns within the AI community about the implications of fast-tracked AI advancements. His comments may resonate with other experts who fear that without a strong focus on safety, the potential for misuse or unintended consequences of AI technologies could increase. This situation raises questions about how companies balance innovation with ethical considerations and safety protocols.

Read Original

Rey, a suspected leader of the ShinyHunters extortion group, has been arrested in Jordan. This group is known for stealing data from various companies and then extorting them for ransom. Following his arrest, Rey is reportedly cooperating with the FBI to help identify other members of the group, which could lead to further arrests and disrupt their criminal activities. The ShinyHunters have been linked to multiple high-profile data breaches, affecting both businesses and consumers, making this development significant in the ongoing fight against cybercrime. The arrest may also provide insights into the methods and operations of this notorious group, potentially preventing future attacks.

Read Original

Citrix has announced security updates for a serious vulnerability in its NetScaler ADC and Citrix NetScaler Gateway products, identified as CVE-2026-88779. This memory overflow flaw has a CVSS score of 8.7, indicating a high level of severity. Attackers are actively exploiting this zero-day vulnerability in targeted attacks, which can disrupt SAML (Security Assertion Markup Language) deployments, potentially knocking them offline. Users of these systems should prioritize applying the available security updates to mitigate the risk of exploitation. This incident underscores the need for organizations to stay vigilant about their cybersecurity practices, especially when using widely deployed network infrastructure.

Read Original

In the first quarter of 2026, researchers from Huntress discovered that 45% of endpoint-related security incidents involved the misuse of legitimate remote monitoring and management (RMM) software. This finding indicates that attackers are increasingly taking advantage of tools that IT teams use to manage systems remotely, making their activities appear normal and less suspicious. Huntress ranked various attack tactics by frequency and potential damage, placing RMM abuse at the top of the list. The implications of this trend are significant, as it suggests that organizations need to be more vigilant in monitoring their RMM software usage to prevent unauthorized access and potential data breaches. Companies should implement stricter controls and monitoring on RMM tools to mitigate these risks.

Read Original
Actively Exploited

Citrix has issued urgent updates to address a denial-of-service vulnerability in its NetScaler product, identified as CVE-2026-88779. This flaw has already been exploited in zero-day attacks, raising concerns about its potential for remote code execution as well. The vulnerability affects users of Citrix’s NetScaler, which is widely used for application delivery and load balancing. Companies using this system should prioritize applying the latest patches to protect their environments. The fast-tracked response from Citrix indicates the seriousness of the threat, as attackers are actively exploiting this vulnerability in the wild.

Read Original
Actively Exploited

The latest Malware Newsletter from Security Affairs reports on several new malware threats. Notably, a new information stealer named Lunex has been identified, which is being deployed through Bring Your Own Vulnerable Driver (BYOVD) techniques. Additionally, researchers are warning about Agentic-driven cloud attacks that exploit compromised service principals, indicating a growing trend in cloud-based vulnerabilities. The newsletter also mentions the resurgence of TraderTraitor backdoors, which are targeting victims who seemingly have no ties to cryptocurrency. These developments signal a shift in malware tactics and highlight the need for heightened security measures across various digital environments.

Read Original

A 16-year-old security researcher discovered a significant vulnerability in Titan, an internal analytics service used by Microsoft. This flaw potentially allowed unauthorized users to access a massive database containing 17 trillion rows of sensitive data, including employee records and Bing search analytics. Meanwhile, Citrix has been dealing with the fallout from two zero-day vulnerabilities in its NetScaler product, which have reportedly been exploited globally for weeks. Citrix has released patches for eight critical and high-severity vulnerabilities, but the ongoing exploitation raises concerns for organizations using these systems. The incidents serve as a reminder of the vulnerabilities that can exist even in well-established services and the need for constant vigilance in cybersecurity.

Read Original

The latest Security Affairs newsletter covers a range of cybersecurity issues, including a new macOS backdoor disguised as a fake Zoom installer. This backdoor, known as CloudSyncD, poses a significant risk to macOS users who may unknowingly install this malicious software. Additionally, a critical vulnerability in GitLab's AI Gateway, identified as CVE-2026-90970, has been patched, addressing a serious security flaw that could have been exploited by attackers. The newsletter also highlights the Antino backdoor, which has been linked to various cyberattacks. These incidents emphasize the need for users and organizations to remain vigilant about the software they install and to apply security updates promptly.

Read Original

Authorities in Jordan have detained a suspect linked to the ShinyHunters digital extortion group, a notorious outfit known for hacking and selling stolen data. The suspect, identified as Saif al-Din Khader, also known as 'Rey,' was taken into custody on September 29, 2026. Reports indicate that he is cooperating with the FBI to help identify other members of the group. ShinyHunters has been responsible for several high-profile data breaches, impacting various companies and putting sensitive information at risk. This development could lead to further arrests and a crackdown on the group's activities, which have affected numerous organizations worldwide.

Read Original
Page 1 of 435Next