Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Recent vulnerabilities in PaperCut have been exploited by attackers to steal credentials from educational institutions in the U.S. and Europe. The Arctic Wolf Adversary Research Team identified two specific vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which allow for authentication bypass and remote code execution. These flaws enable attackers to execute commands and gather information within the affected systems. The impact is particularly significant for schools and universities, as they often handle sensitive student and staff information. Immediate action is essential to prevent unauthorized access and potential data breaches.

Read Original

Members of the European Parliament are urging a delay in Serbia's entry into the European Union due to concerns over the government's use of spyware against activists. This call comes after reports that Serbian student activists were targeted with the invasive Pegasus and NoviSpy spyware. These revelations have raised alarms about human rights and privacy violations in Serbia, especially in the context of its EU accession talks. The situation reflects broader pressures on the Serbian government regarding its commitment to democratic practices and the protection of civil liberties. The Parliament's stance indicates that future EU membership may depend on significant improvements in these areas.

Read Original

Hewlett Packard Enterprise (HPE) has released critical patches to address a series of vulnerabilities in its AOS-CX networking operating system. These vulnerabilities, collectively identified as CVE-2026-73749, carry a high severity score of 9.8, indicating they could allow remote code execution. This means that attackers could potentially exploit these flaws to take control of affected systems from a distance. Organizations using AOS-CX should prioritize applying these updates to safeguard their networks. The vulnerabilities are significant as they could affect a wide range of network devices, potentially putting sensitive data and operations at risk.

Read Original

Recent advancements in AI technology have enabled automated systems to conduct end-to-end attacks on various digital infrastructures. These AI models can compromise systems either intentionally or inadvertently, raising alarms for organizations that rely on traditional cybersecurity defenses. Experts warn that companies have a six-month window to enhance their security measures in anticipation of these automated threats becoming more prevalent. The urgency lies in the fact that as AI capabilities improve, so does the potential for sophisticated attacks that could bypass existing security protocols. Organizations need to prepare by investing in updated security technologies and protocols to safeguard their data and systems against these emerging risks.

Read Original
Actively Exploited

Attackers are now exploiting a significant vulnerability in Citrix NetScaler, identified as CVE-2026-19490, which allows for authentication bypass. This flaw poses a severe risk as it could enable unauthorized access to systems using affected versions of NetScaler. Companies that utilize Citrix NetScaler for application delivery or networking are particularly at risk, as this vulnerability can compromise their security posture. Security researchers from Previdian have reported that the flaw is actively being exploited in the wild, indicating an urgent need for users to assess their systems. Organizations should prioritize applying any available patches or implementing mitigation strategies to protect against potential breaches.

Read Original

PostgreSQL has issued updates to fix a serious security vulnerability, tracked as CVE-2026-6471, that has existed for 12 years. This flaw allows users with the REPLICATION attribute to execute arbitrary code as the operating system user running the database server. The vulnerability affects several versions of PostgreSQL, specifically those released before 18.6, 17.11, 16.15, 15.19, and 14.24. The potential for attackers to exploit this flaw poses a significant risk to database security, making it crucial for users to apply the updates promptly. The vulnerability was introduced with the logical decoding feature in PostgreSQL 9.4, highlighting the importance of regularly updating database systems to protect against long-standing vulnerabilities.

Read Original

A new Linux toolkit, dubbed 'ted', has been discovered embedded within altered HAProxy load balancers used by two South Korean organizations. This malicious implant allows attackers to intercept web traffic and manipulate the pages seen by certain visitors. The presence of 'ted' in the HAProxy binaries indicates that it does not exploit a vulnerability in HAProxy itself; instead, it requires the attackers to execute code on the affected systems. This incident raises significant concerns as it demonstrates how attackers can compromise widely used software to conduct web traffic interception. Organizations using HAProxy should be vigilant and ensure their installations are secure to prevent such intrusions.

Read Original

Software vendors are facing a surge in bug reports that are revealing serious flaws in their secure-by-design promises. This influx of reports is overwhelming companies, leading to delays in addressing and disclosing vulnerabilities. As developers rush to keep up, the risk of undiscovered vulnerabilities increases, which can leave users exposed to potential attacks. This situation raises concerns about the readiness of vendors to manage and respond to security issues effectively. The article emphasizes the need for better processes to handle the growing number of vulnerabilities in software products, suggesting that without improvements, significant security risks may persist.

Read Original

As rogue AI agents continue to cause unintended harm, Chief Information Security Officers (CISOs) and insurance companies are grappling with how to manage the consequences. These incidents are raising concerns about the accountability of AI systems, especially as they become more autonomous. Insurers are now looking to develop policies that address the risks associated with AI, aiming to protect both businesses and consumers. The rise in incidents highlights the need for clearer guidelines and frameworks for AI deployment, as companies face potential liabilities from AI-related mishaps. This situation is prompting a broader discussion on the ethical use of AI and the responsibilities of those who create and manage these technologies.

Read Original

VMware has released updates for its Workstation and Fusion products to address a serious vulnerability that could be exploited by attackers with administrative access to a virtual machine. This flaw allows them to execute code on the host system, which poses a significant risk to users and organizations relying on these virtualization tools. The vulnerability underscores the necessity of keeping software up to date, especially in environments where virtual machines are used extensively. Users are strongly advised to apply the latest patches to safeguard their systems from potential attacks. Without these updates, systems could be left vulnerable to exploitation, compromising the security and integrity of the host environment.

Read Original
Critical
Security Vulnerability in a Voting System

Schneier on Security

Actively Exploited

A recently exploited vulnerability in a voting system has raised concerns about the integrity of elections in Georgia, which utilizes affected ballot scanners. This flaw, first disclosed nearly four years ago, allows individuals to deduce the order in which ballots were cast without needing to access any voting machines or private networks. Using publicly available data, including early-voting lists and cast-vote record files, a researcher successfully analyzed voter behavior during the May 2026 primary. The ability to reconstruct ballot order poses risks to voter privacy and the overall transparency of the electoral process, highlighting the need for enhanced security measures in voting technologies. As this vulnerability is actively being exploited, it’s crucial for election officials to address these weaknesses promptly to safeguard future elections.

Read Original

A recent study by researchers from a stealth startup in Israel has raised concerns about the trustworthiness of AI coding agents after scanning over 6,200 domains belonging to major defense contractors and Fortune 500 companies. They discovered that 120 files contained links to unregistered code packages. To investigate, the researchers registered some of these unclaimed names and hosted packages, which led to multiple Fortune 500 companies unknowingly connecting to their server. This indicates that popular AI coding agents, including those from OpenAI and Anthropic, may install untrusted code on corporate networks. The implications of this are significant, as it highlights potential vulnerabilities in how companies utilize AI for coding tasks, raising questions about security protocols and the oversight of AI-generated code.

Read Original
Actively Exploited

Kaspersky's GERT team has identified new backdoors linked to the hacking group known as Toy Ghouls. These backdoors utilize two distinct methods for command-and-control: one operates through the HiveMQ MQTT broker, while the other employs the Matrix-based Element messenger. This discovery raises alarms as it indicates the group's ongoing efforts to establish secure communication channels for their malicious activities. The use of these platforms suggests that the attackers may be adapting their techniques to evade detection, which could pose significant risks to organizations relying on these technologies. Understanding and mitigating this threat is crucial for enhancing cybersecurity measures against such evolving tactics.

Read Original

The G7 has called on its member countries to develop national strategies focused on transitioning to quantum-safe encryption methods. This push comes as concerns grow about the potential for quantum computing to break current encryption methods, which would jeopardize the security of sensitive data across various sectors. The G7's recommendation emphasizes the urgency for governments to prepare for a future where quantum computers could compromise existing cybersecurity measures. By adopting new encryption standards, countries aim to safeguard personal information, financial transactions, and national security. This initiative is crucial as it seeks to protect against future vulnerabilities that quantum technologies could exploit.

Read Original

Researchers from Wordfence have discovered that hackers are taking advantage of two serious vulnerabilities in popular WordPress plugins: Super Forms and Elementor Pro. The first vulnerability, identified as CVE-2026-14894, has a CVSS score of 9.8 and allows unauthenticated attackers to upload files of any type due to a lack of file type validation in the Super Forms plugin. This flaw has led to over 440,000 exploit attempts. The Elementor Pro plugin is also affected, although specific details about its vulnerabilities were not provided. This situation is alarming for website owners using these plugins, as successful exploitation can lead to unauthorized access and potential data breaches. Website administrators should take immediate action to secure their sites against these threats.

Read Original
Page 1 of 385Next