Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Attackers are increasingly purchasing expired domain names to take advantage of their established online reputation and traffic. These domains, referred to as dropcatch domains, can be exploited for malicious purposes, including distributing malware, conducting scams, and setting up command-and-control (C2) infrastructure. Each day, around 65,000 domain names that have lapsed are re-registered by new owners, which presents a significant risk. This trend poses dangers to users and organizations as they may unwittingly interact with these compromised domains, leading to potential security breaches. Awareness of this tactic is crucial for internet users and companies to mitigate risks associated with these expired domains.

Read Original
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Security Affairs

Actively Exploited

A serious vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is currently being exploited by attackers. This flaw, which has a maximum severity score of 10.0, arises from insufficient authorization checks and poor input validation. Just days after SAP issued a patch, reports of active exploitation began to surface. This puts organizations using SAP Commerce Cloud at risk, as attackers could potentially gain unauthorized access to sensitive information or systems. Companies should prioritize applying the latest updates from SAP to protect their environments from these attacks.

Read Original

A new botnet named Evooo1Bot has emerged, targeting internet-facing routers and other gateway devices. Based on the Mirai malware, this botnet converts these devices into SOCKS5 traffic relay nodes, allowing attackers to route internet traffic through them. This can enable various types of malicious activities, including distributed denial-of-service (DDoS) attacks. The attack affects any vulnerable Linux-based routers or similar devices that are exposed to the internet, making it crucial for users and network administrators to secure their devices against unauthorized access. As the botnet continues to spread, it poses a significant risk to network integrity and privacy.

Read Original
Actively Exploited

The online gaming industry is facing a growing problem with identity fraud as it attracts both millions of legitimate players and skilled fraudsters. Recently, two men were charged for exploiting vulnerabilities within this sector. Their actions underline the risks that gamers face, including unauthorized account access and financial theft. As fraudsters become more sophisticated, it’s crucial for gaming companies and players alike to implement stricter security measures. This includes better identity verification processes and increased awareness about phishing scams, which can help protect users from falling victim to these scams.

Read Original

GeoServer is currently facing a serious security issue due to an unpatched zero-day vulnerability that allows for SQL injection and potentially remote code execution (RCE). This flaw has already attracted the attention of attackers who are probing exposed systems, raising concerns for organizations using this open-source geospatial platform. A security researcher named q1uf3ng disclosed the vulnerability, but as of now, there is no available patch to fix it. Companies running GeoServer should immediately assess their systems for exposure to this vulnerability and take steps to secure their installations. The urgency of the situation is heightened by the active exploitation attempts underway, making it crucial for users to act quickly to protect their data.

Read Original

Trezor has confirmed a data breach involving its shipping partner, affecting over 13,000 customers. Initially, it was thought that only recent orders were compromised, but new information indicates that older orders may also be at risk. This breach raises concerns about the potential exposure of personal information, which could lead to phishing attacks or other forms of identity theft. Trezor is advising customers to remain vigilant and take steps to secure their accounts. The incident highlights the vulnerability of third-party partnerships in the cryptocurrency space, emphasizing the need for companies to ensure the security of their supply chains.

Read Original

The U.S. judiciary will begin reporting on the use of hacking tools in wiretap investigations starting with the 2028 Wiretap Report, set to be published in 2029. This change aims to provide greater transparency regarding the methods law enforcement agencies use when conducting surveillance. By including data on network investigative techniques, the judiciary seeks to inform the public about how these tools are employed in criminal investigations. This move is significant as it could influence public perception and discussions around privacy rights and law enforcement practices. The decision reflects a growing demand for accountability in how technology is utilized by government entities.

Read Original

California has launched a new initiative to enhance cybersecurity measures in response to increasing threats. As part of this effort, every state agency is required to appoint an AI cybersecurity officer. Additionally, the state is establishing an AI cyber defense program, which will be managed by the Cybersecurity Integration Center. This initiative aims to strengthen the state's defenses against cyberattacks by integrating artificial intelligence into their security frameworks. The move is significant as it reflects a growing recognition of the need for advanced technologies to combat evolving cyber threats, ensuring that state agencies are better equipped to protect sensitive data and infrastructure.

Read Original

Cybercriminals are increasingly turning to expired domains, known as 'dropcatch' domains, to carry out their illicit activities. These domains are appealing because they come with existing trust, backlinks, and web traffic from their previous legitimate use, making them less suspicious to security systems compared to newly registered domains. This trend raises concerns for businesses and users alike, as these domains can be used for phishing, malware distribution, and other online scams. The use of such domains complicates the detection of malicious activities, as they can easily evade traditional security measures. It's crucial for organizations to stay vigilant and consider monitoring expired domains that could be repurposed for harmful activities.

Read Original

A newly discovered vulnerability in macOS, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and is being actively exploited for unauthorized cryptocurrency mining. This flaw affects the screen sharing feature of macOS, allowing attackers to hijack resources from targeted machines without user consent. Users of macOS devices should be particularly vigilant, as this vulnerability poses a risk to system performance and could lead to increased electricity costs due to the mining activities. It's crucial for users to stay updated on any patches or updates released by Apple to mitigate this issue and protect their devices from exploitation.

Read Original
Actively Exploited

The data extortion group known as ExfilSquad, which surfaced on July 26, has claimed responsibility for stealing data from 15 organizations. So far, they have publicly leaked information from 13 victims, indicating a significant impact on businesses in various sectors. ExfilSquad's tactics include threatening to release sensitive data unless a ransom is paid, which puts additional pressure on affected organizations to comply. This incident raises concerns about data security and the potential for reputational damage for the victims involved. Organizations must remain vigilant and consider strengthening their cybersecurity measures to prevent similar attacks in the future.

Read Original

In July, the ShinyHunters group executed a data breach involving RingCentral, a communications platform. This breach was the result of a sophisticated social engineering campaign, indicating that attackers used manipulation techniques to gain unauthorized access to sensitive information. The extent of the data compromised has not been specified, but given RingCentral's role in facilitating business communications, this incident raises significant concerns about the security of user data and the potential for further exploitation. Companies using RingCentral should assess their security measures and ensure that employees are trained to recognize social engineering tactics. This breach serves as a stark reminder of the vulnerabilities that can arise from human error in cybersecurity.

Read Original

As the energy sector increasingly adopts AI technologies, concerns are growing about the associated cybersecurity and supply chain risks. These advancements, while promising for efficiency and innovation, expose critical infrastructure to potential cyberattacks. For instance, AI systems can be vulnerable to manipulation, which could lead to disruptions in energy services or even safety hazards. Companies operating in this space need to be vigilant and bolster their cybersecurity measures to protect against these emerging threats. The implications are significant, as a successful attack could affect not just energy providers, but also the wider economy and public safety.

Read Original

The White House is expanding the role of private companies in offensive cyber operations, a move that raises governance and oversight concerns. Under this new initiative, private sector entities may be involved in cyber attacks against foreign adversaries. While the intention is to bolster national security and counter cyber threats, critics worry about the lack of regulation and the potential for abuse. This shift could lead to a scenario where private firms, rather than government entities, decide how and when to engage in hacking operations. The implications of this policy could affect international relations and the overall cybersecurity landscape in the U.S.

Read Original

Four hackers were arrested in Brazil, and three others face charges in Europe for orchestrating a bank fraud scheme that exploited a vulnerability in a service provider. The attackers managed to withdraw over €30 million from the accounts of customers at Commerzbank. This breach underscores the risks associated with third-party service providers and highlights the need for robust security measures. The incident not only affects the financial institution but also raises concerns for customers whose accounts were compromised. Authorities are taking steps to address the issue and prevent similar attacks in the future.

Read Original
Page 1 of 343Next