Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Trezor has confirmed a data breach involving its shipping partner, affecting over 13,000 customers. Initially, it was thought that only recent orders were compromised, but new information indicates that older orders may also be at risk. This breach raises concerns about the potential exposure of personal information, which could lead to phishing attacks or other forms of identity theft. Trezor is advising customers to remain vigilant and take steps to secure their accounts. The incident highlights the vulnerability of third-party partnerships in the cryptocurrency space, emphasizing the need for companies to ensure the security of their supply chains.

Read Original

The U.S. judiciary will begin reporting on the use of hacking tools in wiretap investigations starting with the 2028 Wiretap Report, set to be published in 2029. This change aims to provide greater transparency regarding the methods law enforcement agencies use when conducting surveillance. By including data on network investigative techniques, the judiciary seeks to inform the public about how these tools are employed in criminal investigations. This move is significant as it could influence public perception and discussions around privacy rights and law enforcement practices. The decision reflects a growing demand for accountability in how technology is utilized by government entities.

Read Original

California has launched a new initiative to enhance cybersecurity measures in response to increasing threats. As part of this effort, every state agency is required to appoint an AI cybersecurity officer. Additionally, the state is establishing an AI cyber defense program, which will be managed by the Cybersecurity Integration Center. This initiative aims to strengthen the state's defenses against cyberattacks by integrating artificial intelligence into their security frameworks. The move is significant as it reflects a growing recognition of the need for advanced technologies to combat evolving cyber threats, ensuring that state agencies are better equipped to protect sensitive data and infrastructure.

Read Original

Cybercriminals are increasingly turning to expired domains, known as 'dropcatch' domains, to carry out their illicit activities. These domains are appealing because they come with existing trust, backlinks, and web traffic from their previous legitimate use, making them less suspicious to security systems compared to newly registered domains. This trend raises concerns for businesses and users alike, as these domains can be used for phishing, malware distribution, and other online scams. The use of such domains complicates the detection of malicious activities, as they can easily evade traditional security measures. It's crucial for organizations to stay vigilant and consider monitoring expired domains that could be repurposed for harmful activities.

Read Original

A newly discovered vulnerability in macOS, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and is being actively exploited for unauthorized cryptocurrency mining. This flaw affects the screen sharing feature of macOS, allowing attackers to hijack resources from targeted machines without user consent. Users of macOS devices should be particularly vigilant, as this vulnerability poses a risk to system performance and could lead to increased electricity costs due to the mining activities. It's crucial for users to stay updated on any patches or updates released by Apple to mitigate this issue and protect their devices from exploitation.

Read Original
Actively Exploited

The data extortion group known as ExfilSquad, which surfaced on July 26, has claimed responsibility for stealing data from 15 organizations. So far, they have publicly leaked information from 13 victims, indicating a significant impact on businesses in various sectors. ExfilSquad's tactics include threatening to release sensitive data unless a ransom is paid, which puts additional pressure on affected organizations to comply. This incident raises concerns about data security and the potential for reputational damage for the victims involved. Organizations must remain vigilant and consider strengthening their cybersecurity measures to prevent similar attacks in the future.

Read Original

In July, the ShinyHunters group executed a data breach involving RingCentral, a communications platform. This breach was the result of a sophisticated social engineering campaign, indicating that attackers used manipulation techniques to gain unauthorized access to sensitive information. The extent of the data compromised has not been specified, but given RingCentral's role in facilitating business communications, this incident raises significant concerns about the security of user data and the potential for further exploitation. Companies using RingCentral should assess their security measures and ensure that employees are trained to recognize social engineering tactics. This breach serves as a stark reminder of the vulnerabilities that can arise from human error in cybersecurity.

Read Original

As the energy sector increasingly adopts AI technologies, concerns are growing about the associated cybersecurity and supply chain risks. These advancements, while promising for efficiency and innovation, expose critical infrastructure to potential cyberattacks. For instance, AI systems can be vulnerable to manipulation, which could lead to disruptions in energy services or even safety hazards. Companies operating in this space need to be vigilant and bolster their cybersecurity measures to protect against these emerging threats. The implications are significant, as a successful attack could affect not just energy providers, but also the wider economy and public safety.

Read Original

The White House is expanding the role of private companies in offensive cyber operations, a move that raises governance and oversight concerns. Under this new initiative, private sector entities may be involved in cyber attacks against foreign adversaries. While the intention is to bolster national security and counter cyber threats, critics worry about the lack of regulation and the potential for abuse. This shift could lead to a scenario where private firms, rather than government entities, decide how and when to engage in hacking operations. The implications of this policy could affect international relations and the overall cybersecurity landscape in the U.S.

Read Original

Four hackers were arrested in Brazil, and three others face charges in Europe for orchestrating a bank fraud scheme that exploited a vulnerability in a service provider. The attackers managed to withdraw over €30 million from the accounts of customers at Commerzbank. This breach underscores the risks associated with third-party service providers and highlights the need for robust security measures. The incident not only affects the financial institution but also raises concerns for customers whose accounts were compromised. Authorities are taking steps to address the issue and prevent similar attacks in the future.

Read Original

The National Institute of Standards and Technology (NIST) is grappling with a significant increase in reported vulnerabilities, which are being driven by advancements in AI technology. Researchers are finding that AI can both identify and exploit these vulnerabilities at an alarming rate. As the volume of these vulnerabilities continues to rise, NIST is exploring whether AI could also serve as a solution to manage and mitigate these risks. This situation is concerning for organizations that rely on software and digital systems, as the growing number of vulnerabilities could lead to increased cybersecurity incidents. The ongoing research suggests that while AI presents challenges, it may also offer tools to enhance security measures.

Read Original

Researchers have confirmed that the cyber extortion group ExfilSquad has accessed and stolen sensitive data from at least 13 different organizations. This data has been published by the group through torrents, making it publicly available. The nature of the stolen information remains unspecified, but the breach underscores significant security vulnerabilities within these organizations. As the leaked data could potentially be used for further attacks or identity theft, companies need to assess their security measures and respond swiftly to mitigate any potential fallout. This incident serves as a reminder of the ongoing risks posed by cybercriminals who exploit weaknesses in security protocols.

Read Original
Actively Exploited

A recently patched vulnerability in SAP Commerce Cloud, classified as a maximum-severity remote code execution flaw, is now being actively targeted by attackers. The flaw was fixed just three days ago, and threat intelligence firm Defused has reported that cybercriminals are already exploiting it. This vulnerability puts users of SAP Commerce Cloud at risk, as it allows unauthorized code execution, potentially leading to data breaches or service disruptions. Companies using this platform need to ensure they apply the latest security updates to protect their systems. The urgency of the situation is underscored by the rapid exploitation following the announcement of the patch, making swift action essential for affected organizations.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.

Read Original

A new botnet called Evooo1Bot has emerged, built on the Mirai framework and featuring enhanced capabilities. This botnet is designed to convert compromised edge devices into persistent proxies, which can be exploited for various malicious activities. Researchers have noted that this could significantly impact Internet of Things (IoT) devices, making them potential tools for cybercriminals. The ability to create proxies means that attackers can mask their identity and amplify their operations, raising concerns about privacy and security. Users of affected devices need to be vigilant and improve their security measures to prevent being turned into unwitting participants in these attacks.

Read Original
Page 1 of 342Next