Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

OpenAI has decided to pause some testing of its upcoming Astra model due to emerging security concerns. This model is part of their efforts to advance artificial intelligence, but potential vulnerabilities have raised alarms about its safety. The company is implementing tighter controls on how and when the model can be tested, aiming to ensure that security risks are adequately addressed before further development continues. This move is significant as it reflects growing awareness in the tech community about the implications of AI systems and their potential misuse. OpenAI's decision highlights the need for careful consideration of security in AI development, which could have broad implications for users and developers alike.

Read Original

In a recent article, Rishi Sharma discusses how large language models (LLMs) can be utilized to discover vulnerabilities in software systems. Researchers are exploring the potential of LLMs to automate the identification of security flaws, which could significantly enhance the efficiency of vulnerability assessments. This approach may help security teams prioritize and address vulnerabilities more effectively, potentially reducing the risk of exploitation. As organizations increasingly rely on complex software, the ability to quickly and accurately discover vulnerabilities is crucial in protecting sensitive data and maintaining system integrity. This emerging use of AI in cybersecurity underscores the need for continuous innovation in threat detection.

Read Original

A recent report from Make UK reveals that only about half of UK manufacturers have a cyber incident response plan in place, raising concerns about the industry's preparedness for cyber threats. Alarmingly, 30% of these manufacturers reported experiencing cyber incidents in the past year. The findings indicate significant gaps in cyber resilience among manufacturers, which could leave them vulnerable to future attacks. Without proper response plans, companies may struggle to recover from incidents, risking both financial loss and damage to their reputations. This situation calls for urgent action to bolster cybersecurity measures across the manufacturing sector, as the threat of cyberattacks continues to grow.

Read Original

Mozilla has issued a new GPG signing key for Firefox after the previous key was accidentally uploaded to a GitHub repository. This exposure led Mozilla to revoke the compromised key to maintain the integrity of their software signing process. Users who rely on GPG for verifying Firefox updates and packages need to switch to the new key to ensure they are receiving legitimate software. This incident emphasizes the importance of secure key management in software distribution, as any compromise can put users at risk of encountering malicious versions of the software. Mozilla is taking steps to prevent such occurrences in the future, but users must remain vigilant in managing their security settings.

Read Original

Cybersecurity researchers have identified a supply chain attack affecting BdThemes, a vendor known for its WordPress plugins. This incident has led to the temporary suspension of plugin downloads from the official WordPress repository. According to Wordfence researcher Paolo Tresso, the attack is notable because it did not involve any direct modifications to the source code within the repository. Instead, attackers exploited the system to create unauthorized administrative accounts for WordPress sites using affected plugins. This could allow unauthorized access to numerous WordPress installations, raising serious concerns for users relying on these plugins. WordPress site owners should remain vigilant and consider disabling affected plugins until further notice.

Read Original

Researchers at Nanyang Technological University used AI agents to examine the software behind 4G and 5G phone networks and discovered 84 security flaws, with 83 confirmed by developers. Among these, 81 have been assigned CVE numbers, indicating their severity. One particularly concerning flaw could allow an attacker to hijack a subscriber’s data session, redirecting their internet traffic to themselves instead of to the intended destination. This poses significant risks to user privacy and data security. Alarmingly, 23 of the identified vulnerabilities currently lack fixes, raising concerns about the security of 5G networks as they continue to roll out globally.

Read Original

Security researchers discovered that numerous companies are mistakenly sending sensitive information, such as injury reports and test credentials, to misconfigured email domains like @noreply.us and @noreply.net. These companies believe these addresses are inactive or not monitored, but the reality is that researchers have been receiving this confidential data due to the misconfiguration. This situation raises significant privacy concerns, as sensitive information is being exposed without the companies' knowledge. It highlights a crucial need for organizations to verify their email configurations to prevent unintended data leaks. If these issues are not addressed, they could lead to serious breaches involving personal or proprietary information.

Read Original

Klaviyo, a marketing automation platform, has faced a data leak due to a misconfiguration on its sign-up page. This flaw allowed third-party trackers to access sensitive customer information, including sign-up details and passwords. As a result, advertisers who utilized these trackers may have unintentionally received this private data. The incident raises significant concerns about user privacy and data security, particularly for those who trust Klaviyo with their personal information. Companies using Klaviyo should review their configurations and ensure they are protecting customer data from unauthorized access.

Read Original

LexisNexis has temporarily taken its services offline following unusual activity detected on third-party vendor servers earlier this week. The company acted swiftly to disconnect from these systems to safeguard its customers and contain any potential issues. While specific details about the nature of the unusual activity remain unclear, this incident raises concerns about the security of third-party vendor relationships and the potential risks they pose to service continuity. Customers relying on LexisNexis for legal, business, and academic resources may experience disruptions as the situation unfolds. It’s a reminder for companies to regularly assess their third-party vendor security measures to prevent similar incidents in the future.

Read Original

Microsoft Threat Intelligence has reported that a group known as Storm-1175, which is believed to operate from China, has exploited an authentication-bypass vulnerability (CVE-2026-18577) in N-able's N-central remote monitoring and management tool. This exploitation allowed the attackers to gain initial access to systems and subsequently deploy a new ransomware variant called StormEncryptor. Organizations using N-central are at risk, as the vulnerability could lead to significant data loss and operational disruption. The incident emphasizes the importance of monitoring for vulnerabilities in remote management tools, as they can be entry points for cybercriminals. Companies should ensure they are using the latest security updates and patches to protect against such threats.

Read Original

A recent analysis has uncovered 176 vulnerabilities in Samsung's proprietary mobile applications, which are pre-installed and cannot be removed by users. These apps operate outside of Google Play Protect, leaving them exposed to potential security risks. The vulnerabilities could allow attackers to exploit these apps, potentially compromising user data and device security. This is particularly concerning as Samsung devices are widely used around the world. Users of Samsung mobile devices need to stay alert and update their apps as soon as patches are available to mitigate these risks.

Read Original

Last year, hackers successfully breached a heat-and-power plant in Poland that provides energy to around 50,000 residents. The attackers gained access to the plant's operational technology network by exploiting a private Access Point Name (APN). This incident raises serious concerns about the security of critical infrastructure, as such breaches can disrupt essential services and pose risks to public safety. The attack highlights the vulnerabilities within industrial control systems, which often have insufficient protections against cyber threats. As the energy sector increasingly relies on digital technologies, it is vital for operators to enhance their cybersecurity measures to prevent similar incidents in the future.

Read Original
Actively Exploited

A vendor using the alias 'Gordon Freeman' has surfaced on the dark web, offering a massive database of Israeli citizens' personal information from 2005. This 7.5 GB dataset reportedly includes sensitive details such as national ID numbers, addresses, phone numbers, and family connections for nearly all residents of Israel. The sale of this data raises significant privacy concerns, as it could be used for identity theft, fraud, or other malicious activities. The exposure of such a comprehensive registry poses risks not only to individuals but also to national security, as the information could be exploited by various threat actors. Users and officials alike need to be aware of the potential ramifications of this data leak.

Read Original

Recent research has revealed a tactic known as 'GhostJacking,' where attackers exploit security alerts and blocked events to take control of AI agents. This manipulation allows them to hijack these systems, potentially leading to unauthorized access and misuse of sensitive data. The findings highlight significant gaps in identity governance, particularly how AI systems manage and respond to security incidents. Organizations using AI agents need to reassess their security protocols to safeguard against such vulnerabilities. This issue is particularly pressing as AI technology continues to be integrated into various sectors, raising concerns about its security and reliability.

Read Original
Actively Exploited

Recent attacks on water systems in multiple states have raised concerns about the security of critical infrastructure. These assaults are targeting poorly secured, Internet-exposed programmable logic controllers (PLCs), which are essential for managing water supply systems. Researchers suspect that the attacks may be linked to Iranian cyber actors, indicating a potential state-sponsored operation. This situation is alarming because it not only threatens the safety and functionality of water services but also highlights vulnerabilities in the management of essential public utilities. Authorities are urging water system operators to enhance their cybersecurity measures to prevent further incidents.

Read Original
Page 1 of 331Next