Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A 16-year-old security researcher discovered a significant vulnerability in Titan, an internal analytics service used by Microsoft. This flaw potentially allowed unauthorized users to access a massive database containing 17 trillion rows of sensitive data, including employee records and Bing search analytics. Meanwhile, Citrix has been dealing with the fallout from two zero-day vulnerabilities in its NetScaler product, which have reportedly been exploited globally for weeks. Citrix has released patches for eight critical and high-severity vulnerabilities, but the ongoing exploitation raises concerns for organizations using these systems. The incidents serve as a reminder of the vulnerabilities that can exist even in well-established services and the need for constant vigilance in cybersecurity.

Read Original

Authorities in Jordan have detained a suspect linked to the ShinyHunters digital extortion group, a notorious outfit known for hacking and selling stolen data. The suspect, identified as Saif al-Din Khader, also known as 'Rey,' was taken into custody on September 29, 2026. Reports indicate that he is cooperating with the FBI to help identify other members of the group. ShinyHunters has been responsible for several high-profile data breaches, impacting various companies and putting sensitive information at risk. This development could lead to further arrests and a crackdown on the group's activities, which have affected numerous organizations worldwide.

Read Original

A newly identified cyber espionage group, TA419, believed to be linked to China, is targeting U.S. experts in artificial intelligence. The group has conducted several credential phishing campaigns aimed at professionals in think tanks, universities, and the legal sector. Attackers are impersonating well-known economists, AI policymakers, and even an employee from Anthropic to specifically target these experts. This type of cyber activity raises concerns about the security of sensitive information related to AI policy, especially given the growing importance of AI in global economics and regulation. The attacks indicate an ongoing effort to gather intelligence on U.S. AI initiatives and strategies.

Read Original
High
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI

Hackread – Cybersecurity News, Data Breaches, AI and More

A hacker known as 'Rey' from the group ShinyHunters has been detained in Jordan. This individual is reportedly cooperating with the FBI following claims that ShinyHunters was involved in significant data breaches affecting both the FBI and various corporations. The implications of this detention could be far-reaching, as ShinyHunters has a history of selling stolen data from high-profile breaches. If Rey provides valuable information to the FBI, it could lead to further arrests or a crackdown on similar hacking groups. This situation emphasizes the ongoing battle between law enforcement and cybercriminals in the realm of data security.

Read Original

A hacker linked to the ShinyHunters group, operating under the alias 'Rey', has reportedly been detained in Jordan. This individual is said to be cooperating with the FBI, providing information that could help locate other members of the extortion group. ShinyHunters is known for its involvement in data breaches and selling stolen information online. The arrest could potentially lead to significant developments in efforts to dismantle this hacking organization and protect victims of their attacks. The cooperation with law enforcement may also encourage other members to turn themselves in or provide intelligence on ongoing criminal activities.

Read Original

MI5, the UK's domestic intelligence agency, has issued a warning that over 100 academics in the United Kingdom have been linked to research funded by China's Ministry of State Security (MSS). This research effort is reportedly aimed at enhancing China's intelligence capabilities. The alert, released on September 30, 2026, highlights the activities of the China General Technology Research Institute (CGTRI), which is believed to play a significant role in supporting these initiatives. The implications of this situation are serious, as it raises concerns about intellectual property theft and national security, particularly given the sensitive nature of the research involved. The involvement of such a large number of academics suggests a broader trend of foreign influence and espionage in academic settings, which could undermine trust in international collaborations.

Read Original
Critical
Dutch Institute for Vulnerability Disclosure Breached via Zammad 0-Days

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

The Dutch Institute for Vulnerability Disclosure has suffered a breach due to two zero-day vulnerabilities in Zammad, a customer support software. Attackers exploited these vulnerabilities in an AI-driven attack, allowing them to execute remote code and gain root access to the system. This incident raises significant concerns about the security of software tools that organizations rely on for handling sensitive information. As a result, the breach may affect not only the institute but also other users of Zammad, highlighting the need for heightened vigilance in software security measures. Organizations using Zammad should assess their systems immediately to mitigate potential risks.

Read Original

Fortra has released patches to address several critical vulnerabilities in its BoKS software, which is used for secure access and authentication. These vulnerabilities could allow attackers to bypass authentication, execute arbitrary shell commands, and cause memory corruption. This puts organizations that rely on BoKS at risk of unauthorized access and potential data breaches. Users of the affected software should prioritize applying these patches to protect their systems. The flaws were serious enough to warrant immediate action, and companies should ensure their installations are up to date to mitigate any risk.

Read Original

Some users of the iPhone 18 Pro Max on the AT&T network are experiencing a significant issue where their devices are stuck in SOS mode, preventing them from making calls or sending texts. Apple has acknowledged the problem and announced that affected phones will need to be replaced for free. While two software updates have been identified that could potentially prevent this issue, they do not resolve the problem for devices already affected. This situation is concerning for users who rely on their phones for communication, as it disrupts essential services. Users experiencing this issue should seek a replacement from Apple to restore their device's functionality.

Read Original

RemoteThreat, a startup focused on offensive cyber operations, is working to advance red teaming techniques. Their goal is to simulate the capabilities of modern attackers, which are becoming increasingly sophisticated. This approach encourages security teams to test their defenses in scenarios where standard protections may fail. By evolving traditional methods, RemoteThreat aims to help organizations better prepare for real-world cyber threats. The emphasis on understanding what happens after defenses are breached is crucial for improving overall security posture.

Read Original

Frontline Education has reported a data breach affecting multiple school districts after hackers exploited a weakness in third-party software. The breach allowed unauthorized access to sensitive employee information, notably including Social Security numbers. This incident raises serious concerns about the security of personal data in educational institutions, which are often targeted due to the sensitive nature of their records. Affected districts will need to address potential identity theft risks and enhance their cybersecurity measures to protect against future breaches. School employees should remain vigilant for any unusual activity related to their personal information.

Read Original

The Warlock ransomware group, believed to be linked to China, has targeted several critical sectors, including a water utility, a telecom provider, a regional government body, and a university. They exploited vulnerabilities in SharePoint to gain initial access to these organizations' systems. This breach raises serious concerns about the security of essential services, as the affected sectors play vital roles in public health and communication. The attacks highlight the ongoing risks posed by ransomware groups and the need for organizations to strengthen their cybersecurity defenses. As the frequency of such incidents increases, it is crucial for companies to assess their vulnerabilities and implement robust security measures.

Read Original

Experts and policymakers are raising important legal questions regarding the accountability of AI companies in the event of agentic AI hacks. These types of hacks involve AI systems taking autonomous actions that lead to security breaches or other harmful outcomes. The challenge lies in existing laws and regulations, which may not clearly define responsibility for these incidents. As AI technology evolves, there is a growing concern about how to hold companies accountable when their systems are misused. This situation calls for a reevaluation of legal frameworks to ensure that AI developers are responsible for the actions of their creations, especially as they become more capable of operating independently.

Read Original

GitLab has announced a significant security flaw in its AI Gateway that could allow a logged-in user with Duo Agent Platform access to execute commands on the gateway. This vulnerability affects organizations that self-host their GitLab instances, as the AI Gateway serves as the link between these instances and AI models. The issue has been addressed in the latest releases, specifically versions 19.2.4, 19.3.2, and 19.4.1. Users of the affected versions are urged to update promptly to mitigate any risks associated with this flaw. Failure to act could leave systems vulnerable to unauthorized command execution.

Read Original

Dell has issued security updates to fix several serious vulnerabilities in its Container Storage Modules (CSM), which could allow attackers to gain unauthorized administrative access and potentially control Kubernetes nodes. One of the most critical flaws, identified as CVE-2026-63688, has a CVSS score of 10.0, indicating its severity. These vulnerabilities could be exploited without authentication, putting systems at risk of being taken over. Organizations using Dell's CSM should prioritize applying these updates to protect their environments. The implications of these flaws are significant, as they could lead to unauthorized access to sensitive data and disruption of services.

Read Original
Page 1 of 434Next