Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

FBI Chief Kash Patel’s Clothing Store Hacked in ClickFix Infostealer Attack

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

FBI Chief Kash Patel's clothing store fell victim to a ClickFix infostealer attack, which specifically targeted macOS users. The hackers tricked these users into downloading malware that steals sensitive information. This incident raises concerns not only for Patel as a public figure but also for the broader implications of malware targeting retail platforms. Such attacks can lead to significant data breaches, impacting customer trust and potentially leading to financial losses. Users of the compromised store should be vigilant about their personal data and consider reviewing their security measures to prevent similar threats in the future.

Impact: FBI Chief Kash Patel's clothing store, macOS systems
Remediation: Users should avoid downloading unverified software and consider using security tools to detect malware. Regularly updating macOS and using strong passwords can also help mitigate risks.
Read Original

A vulnerability in the Ghost Content Management System (CMS) has been exploited, leading to the hacking of over 700 websites, including those of prestigious institutions like Harvard and Oxford, as well as the search engine DuckDuckGo. This breach highlights the risks associated with using outdated or unpatched software, as attackers were able to take advantage of security flaws to gain unauthorized access. The incident raises concerns about the personal data and sensitive information that could be exposed on these compromised sites. Organizations using Ghost CMS need to ensure they are running the latest version and apply any available patches to protect their websites from similar attacks in the future.

Impact: Ghost CMS, websites of Harvard, Oxford, DuckDuckGo, and over 700 other sites
Remediation: Update to the latest version of Ghost CMS and apply all available security patches.
Read Original

Dutch authorities have arrested two men and confiscated 800 servers believed to be involved in cyberattacks and disinformation campaigns linked to Russian activities. The arrests took place in Amsterdam and The Hague, with the suspects facing charges for violating Dutch sanctions laws. These servers were reportedly used to undermine democratic processes and disrupt both public and economic systems. The operation is part of a broader effort to combat cyber threats that target national security and public trust. This incident underscores the ongoing battle against malicious cyber activities that seek to destabilize governments and influence public opinion.

Impact: Servers linked to a hosting provider supporting Russian cyber activities
Remediation: N/A
Read Original

The Oncology Institute has reported a data breach involving a third-party vendor, which has yet to be named. However, speculation points to TriZetto as a potential source of the breach. This incident raises concerns about the security of patient data, as healthcare organizations increasingly rely on third-party vendors to manage sensitive information. The breach could expose personal health information, putting affected patients at risk of identity theft and other privacy violations. As the investigation unfolds, it is crucial for healthcare providers to assess their vendor relationships and ensure that strong security measures are in place to protect patient data.

Impact: Patient health information, Oncology Institute data, TriZetto (speculated vendor)
Remediation: N/A
Read Original

U.S. state governments are ramping up their cybersecurity efforts to better protect local communities and critical services. Many states are establishing their own cyber defense programs, which include initiatives like cybersecurity clinics and regional security operations centers (RSOCs). These programs aim to reduce costs and enhance the cybersecurity workforce, ultimately improving the resilience of local infrastructures against cyber threats. As of April 2026, states are also looking to share services and centralize procurement to better manage cyber risks. This shift reflects a growing recognition of the importance of state-level involvement in safeguarding against increasing cyber threats.

Impact: N/A
Remediation: N/A
Read Original
Netherlands Busts Bulletproof Hosting Network Linked to Disinformation and Cybercrime

Hackread – Cybersecurity News, Data Breaches, AI and More

Dutch law enforcement has arrested two individuals involved in running a bulletproof hosting network that facilitated various cybercriminal activities, including disinformation campaigns and evasion of Russian sanctions. Bulletproof hosting refers to web hosting services that protect clients from legal action, allowing them to operate illicit activities with reduced risk of shutdown. This operation is significant as it targets the infrastructure that enables cybercrime and misinformation, which can have widespread effects on public trust and security. The dismantling of such networks is crucial for combating online threats and maintaining the integrity of information. Authorities are working to understand the full extent of the network's operations and its connections to larger cybercriminal organizations.

Impact: Bulletproof hosting services, disinformation operations, Russian sanctions enforcement
Remediation: N/A
Read Original

Anthropic's Mythos has identified around 23,000 potential vulnerabilities across 1,000 open-source software (OSS) projects. Among these, many have been confirmed as critical or high-severity issues, suggesting a significant risk to software security. As this number is expected to rise, it poses a serious concern for developers, companies, and users relying on these OSS projects. The findings highlight the need for heightened scrutiny and proactive measures to secure software environments. Open-source projects often rely on community contributions, which can lead to oversight in vulnerability management, making this situation particularly urgent.

Impact: 1,000 open-source software projects
Remediation: Developers should assess their projects for identified vulnerabilities and apply necessary patches or updates as they become available.
Read Original

Recently, researchers discovered that malicious tags were injected into Laravel-Lang packages, a popular library used in web development. Within a 15-minute window, these tags created backdoors that could exfiltrate continuous integration (CI) secrets, potentially putting many developers and projects at risk. This incident is particularly concerning because it affects a widely used package, meaning that numerous applications relying on Laravel-Lang could be compromised. Developers using these packages need to be vigilant and review their code for any unauthorized changes. The incident serves as a reminder of the importance of securing third-party libraries and regularly monitoring for vulnerabilities.

Impact: Laravel-Lang packages
Remediation: Developers should review their Laravel-Lang package versions and remove any malicious tags. It's advisable to update to the latest, verified versions and monitor CI systems for any signs of compromise.
Read Original

A newly discovered zero-click attack is targeting WhatsApp accounts on iPhones running iOS 16, allowing attackers to take control of accounts without any user interaction or warning. This means that users can find their accounts sending unauthorized messages, often asking contacts for money transfers, without realizing they’ve been compromised. The attack is particularly concerning because it does not require any linked devices, making it harder for users to identify or prevent the intrusion. As this vulnerability is actively exploited, users of WhatsApp on iOS 16 need to be vigilant and take precautions to protect their accounts. This incident highlights the ongoing challenges of mobile security and the importance of being cautious about unsolicited messages and requests.

Impact: WhatsApp, iPhones running iOS 16
Remediation: Users should consider updating their iOS to the latest version as soon as patches are available, enable two-factor authentication on their WhatsApp accounts, and be cautious of messages requesting money or sensitive information.
Read Original

Fraudsters are targeting Formula 1 fans with various scams, including fake streaming services and counterfeit merchandise. The Bitdefender Cybersecurity Grand Prix Fan Threat Index reveals that these scams are increasingly common, especially during major racing events where fan interest peaks. Unsuspecting fans may fall victim to these schemes, losing money and personal information. The article emphasizes the importance of awareness and vigilance among fans, encouraging them to verify the legitimacy of online services and products before making purchases. With the growing popularity of F1, these scams pose a significant risk to the fan community, making cybersecurity education essential.

Impact: Fake streaming services, counterfeit merchandise
Remediation: Fans should verify the legitimacy of streaming services and merchandise sellers, use official channels for purchases, and report suspicious activities.
Read Original

Dutch authorities have arrested two individuals and confiscated 800 servers linked to Stark Industries, a hosting provider allegedly involved in facilitating cyberattacks and disinformation campaigns. The investigation revealed that the suspects supported operations believed to be aligned with Russian interests. This crackdown highlights the ongoing efforts by law enforcement to disrupt networks that play a role in spreading false information and conducting cyber operations. As these incidents can undermine public trust and influence political landscapes, the authorities' actions aim to mitigate these risks and hold those responsible accountable. The seizure of such a large number of servers indicates the scale of the operations being targeted.

Impact: Stark Industries hosting services
Remediation: N/A
Read Original
Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A hacker is reportedly selling a massive database containing the personal information of 340 million OnlyFans users. This database appears to have been created by combining data from previous breaches and matching it with public profiles to identify real OnlyFans accounts. The implications are serious, as this kind of data leak can lead to identity theft, harassment, or other malicious activities targeting the users involved. OnlyFans users should be particularly cautious about their online security and consider changing their passwords and enabling two-factor authentication. This incident raises broader concerns about the security of online platforms and the risks associated with sharing personal information.

Impact: OnlyFans user accounts
Remediation: Users should change passwords and enable two-factor authentication.
Read Original

A significant security vulnerability has been identified in Ghost CMS, specifically a SQL injection flaw labeled CVE-2026-26980. Attackers are exploiting this weakness to inject harmful JavaScript code, which activates ClickFix attack flows across numerous websites utilizing this content management system. This exploitation poses a serious risk to users by potentially compromising their data and functionality of affected sites. Ghost CMS users, particularly those running outdated versions, should take immediate action to secure their systems. This incident highlights the ongoing need for vigilance in web security and the importance of keeping software up to date.

Impact: Ghost CMS versions vulnerable to CVE-2026-26980
Remediation: Users should update their Ghost CMS to the latest version that addresses CVE-2026-26980. Regularly applying security patches and monitoring for unusual activity can help mitigate risks associated with SQL injection vulnerabilities.
Read Original
Actively Exploited

Recent reports indicate that the popular npm package 'node-ipc' has been compromised with a credential-stealing malware. This incident affects developers who rely on this package for their applications, potentially exposing sensitive user information. Additionally, a new group called TeamPCP has emerged, deploying clones of the Shai-Hulud malware, which may pose further risks to various systems. Moreover, active supply chain attacks have targeted '@antv' packages on npm, putting more developers at risk. The compromised GitHub Action 'actions-cool/issues-helper' has also been found to redirect all tags to malicious endpoints, heightening concerns over the security of widely-used development tools. Developers and organizations should take immediate precautions to secure their environments and monitor for any unusual activity.

Impact: node-ipc npm package, @antv packages on npm, actions-cool/issues-helper GitHub Action
Remediation: Developers should remove the compromised packages immediately and replace them with verified alternatives. Regularly audit dependencies and update all packages to their latest, secure versions. Implement monitoring for suspicious activities in development environments.
Read Original

Anthropic's AI initiative, Project Glasswing, has identified over 10,000 serious vulnerabilities within just one month of operation. This alarming discovery exposes a significant gap in the ability of organizations to patch and manage these vulnerabilities effectively. The vulnerabilities range in severity from high to critical, raising concerns for companies and users who rely on the affected systems. As the number of vulnerabilities continues to grow, it becomes increasingly clear that many organizations struggle with timely patching and security management. This situation not only jeopardizes the security of sensitive data but also highlights the urgent need for improved cybersecurity practices across the industry.

Impact: N/A
Remediation: N/A
Read Original
Page 1 of 213Next