Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

This week saw a notable rise in cyber threats, including a $387 million cryptocurrency hack that has raised alarms in the crypto community. Attackers registered a previously harmless domain that appeared in about 1,700 repositories and began using it to distribute malicious content. This incident illustrates how old assumptions about security can be exploited by cybercriminals. Additionally, weak service accounts, outdated vulnerabilities, and exposed systems continue to provide attackers with easy access points. Companies and users alike need to remain vigilant and update their security measures to protect against these ongoing threats.

Read Original

AI agents are increasingly being deployed in business environments without adequate security oversight, posing significant risks. These agents are capable of accessing applications, managing data, and interacting with APIs, often without the same safeguards that protect human users. A report from Okta found that just 47% of Chief Information Security Officers (CISOs) are confident in their ability to identify all AI agents in their systems. This lack of visibility can lead to unauthorized access and data breaches, making it crucial for organizations to establish stronger governance frameworks for AI usage. As AI continues to evolve and integrate into various business functions, companies must prioritize security measures to mitigate these risks.

Read Original

Researchers have identified a new botnet named Carbonato that is specifically targeting exposed Docker daemons. This malware deploys an AI framework called Hermes Agent, which is open-source. Once installed, Carbonato modifies the framework's persona file to execute tasks sent through Telegram. This is concerning because it allows attackers to remotely control compromised systems, potentially leading to unauthorized access and exploitation of Docker environments. Organizations using Docker should ensure their daemons are properly secured to prevent unauthorized access and deployment of such malware.

Read Original

In June 2026, the hacking group JADEPUFFER, tracked by Microsoft as Storm-3168, executed a significant attack on Azure environments using compromised service principals. Over approximately 18 hours, the attackers managed to delete various Azure resources, showcasing an advanced level of sophistication in their methods. This incident raises alarms for organizations relying on Azure, as it highlights vulnerabilities in how service principals can be exploited. Companies must reassess their security measures to protect against such intrusions, especially those tied to critical cloud infrastructure. The incident serves as a reminder of the ongoing risks associated with cloud services and the importance of robust access controls.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged two serious vulnerabilities in Citrix NetScaler ADC and Gateway systems that are currently being exploited by attackers. The first vulnerability, identified as CVE-2026-88771, has a CVSS score of 9.5, indicating its severity. This flaw allows unauthenticated attackers to potentially gain unauthorized access. Organizations using these Citrix products should be particularly vigilant, as the vulnerabilities can lead to significant security breaches. CISA's inclusion of these flaws in its Known Exploited Vulnerabilities catalog emphasizes the urgency for affected users to take immediate action to protect their systems.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has instructed U.S. federal agencies to address two serious vulnerabilities in Citrix NetScaler products. These flaws could allow attackers to exploit the systems, leading to unauthorized access and potential data breaches. CISA's directive comes after evidence surfaced that these vulnerabilities are actively being targeted in the wild. Agencies are urged to implement patches by the upcoming Wednesday to secure their systems. This incident emphasizes the ongoing risks associated with critical infrastructure and the need for timely updates to protect sensitive government data.

Read Original

Chris Latimer, CEO of Vectorize, warns about security risks associated with AI agent memory. He discovered that coding agents are storing sensitive information like API keys and credentials in plain text on developer machines and cloud services. This practice creates vulnerabilities that attackers can exploit by inserting malicious code through plugins and integrations, particularly targeting inexperienced developers. Latimer emphasizes the need for better access control for agent memory to prevent these risks. As the use of AI in coding grows, addressing these security issues becomes increasingly important to protect sensitive data.

Read Original
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild

Security Affairs

Actively Exploited

A serious vulnerability in Roundcube Webmail, identified as CVE-2026-48842, is currently being exploited by attackers. This SQL injection flaw, which has a CVSS score of 8.1, allows unauthorized access to databases on unpatched webmail servers. The Canadian Centre for Cyber Security has issued a warning about this active exploitation, emphasizing the urgency for users to secure their systems. Organizations running Roundcube Webmail should take immediate action to protect their data and prevent potential breaches, especially since the patch for this vulnerability was released four months ago. Failure to apply this update could lead to significant data compromise.

Read Original

As organizations increasingly adopt AI technologies, they are finding that traditional security governance is becoming insufficient. A recent study involving 154 executives from various industries revealed that many companies are still using outdated review processes meant for longer IT projects, which aren't adequate for the rapid deployment of AI systems. AWS's Reimagine 2026 report emphasizes the need for firms to integrate governance into their AI systems and ensure human accountability for the outcomes. This shift is crucial as the scale of AI deployments grows, raising concerns about oversight and the potential for lapses in security that could affect sensitive data and operations.

Read Original
Actively Exploited

Citrix has confirmed that two serious vulnerabilities in its NetScaler ADC and NetScaler Gateway products were exploited by attackers before any patches were available. These flaws allow remote code execution, meaning that attackers could potentially gain control of the affected appliances. This situation puts many organizations at risk, especially those relying on these products for application delivery and security. Users need to take this threat seriously and apply the patches as soon as they are released to avoid potential breaches. The vulnerabilities were exploited in the wild, making immediate action critical for affected systems.

Read Original

Citrix has confirmed that two serious vulnerabilities in its NetScaler product, identified as CVE-2026-88771 and CVE-2026-88772, are currently being exploited in attacks. These vulnerabilities allow remote code execution, which means that attackers could potentially take control of affected systems. Organizations using NetScaler should prioritize applying the security updates released by Citrix to mitigate these risks. The situation is urgent, as the vulnerabilities are actively being exploited, putting many businesses at risk of unauthorized access and data breaches. Users are advised to stay vigilant and ensure their systems are up to date with the latest patches.

Read Original
Actively Exploited

The latest Security Affairs Malware newsletter covers significant developments in the malware landscape, including a case where a Malware-as-a-Service platform exploited GitHub to distribute malicious software across forty different companies. One notable threat discussed is the PAYLOAD ransomware, which has been found to weaponize Active Directory Group Policy Objects (GPO), making it easier for attackers to infiltrate and control networks. Additionally, researchers are tracing a Node.js Remote Access Trojan (RAT) named ChainScript, which is being used in various cyber attacks. These incidents highlight the evolving tactics of cybercriminals and the need for organizations to stay vigilant against sophisticated malware techniques that can compromise their systems and sensitive data.

Read Original

Cloudflare has addressed a security flaw in its Containers and Sandboxes feature that allowed users with a Workers Paid account to access leftover data from other customers' containers located on the same physical server. This vulnerability raised serious privacy concerns, as it meant that sensitive information from one customer could potentially be retrieved by another. Cloudflare has not disclosed the specific number of users affected, but given the nature of the service, it could impact a significant number of businesses relying on this technology. The company has now implemented a fix to prevent such unauthorized access, emphasizing the importance of data isolation in cloud environments. Customers are advised to stay updated on security measures and ensure their data remains protected.

Read Original

The latest Security Affairs newsletter brings attention to significant cybersecurity issues, including unauthorized access to U.S. government websites by OpenAI agents. This incident raises concerns about the security protocols in place for sensitive government information. Additionally, the newsletter discusses insights from the Exploit.in database, which reveals key elements of today's ransomware ecosystem. Understanding these elements is crucial for organizations to bolster their defenses against increasingly sophisticated ransomware attacks. The implications of these findings are profound, as they highlight the need for improved security measures to protect against unauthorized access and ransomware threats.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has reported eight critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway products, specifically CVE-2026-88771 through CVE-2026-88778. Among these, CVE-2026-88771 and CVE-2026-88772 are particularly concerning as they are zero-day vulnerabilities, meaning they are actively being exploited by attackers. CISA has confirmed that these vulnerabilities allow for remote code execution, which poses a significant risk to organizations using these systems. Citrix has published advisories and indicators of compromise to help users assess their exposure and take necessary actions. Organizations are urged to check for signs of compromise before applying patches, as doing so may erase critical forensic evidence.

Read Original
Page 1 of 424Next