Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

A serious SQL injection vulnerability in Metabase has been exploited in zero-day attacks, resulting in unauthorized access to customer data. This flaw has specifically affected companies like Framework and Tally, raising concerns about the security of user information stored in Metabase instances. Attackers have taken advantage of this weakness to steal sensitive data, which highlights the urgent need for affected organizations to address the vulnerability promptly. Users and companies relying on Metabase should be vigilant and ensure their systems are secure against potential breaches. The situation emphasizes the importance of maintaining robust security measures, especially when using widely-used data analysis tools.

Read Original

Unlimited Technology Systems, a healthcare software provider, has reported a significant data breach that has affected over 3.8 million individuals. The breach, which took place in October 2025, has raised serious concerns about the security of personal information in the healthcare sector. While the company has not disclosed specific details about how the breach occurred, the scale of the incident suggests that sensitive data may be at risk. This situation highlights the growing vulnerability of healthcare organizations to cyberattacks, emphasizing the need for robust security measures to protect patient data. Affected individuals may face risks such as identity theft or fraud, making timely notification and support essential.

Read Original
Actively Exploited

A vishing group identified as UNC6671 has shifted its focus to targeting mergers and acquisitions (M&A) firms with extortion schemes. This group, known for using voice phishing tactics, aims to exploit sensitive financial data and negotiations occurring in these high-stakes environments. Experts are advising firms to implement managed-device logins and closely monitor audit logs to combat the rising threat of phishing-led data theft. The implications of this shift are significant, as M&A firms often handle large sums of money and confidential information, making them prime targets for attackers seeking to leverage that data for financial gain.

Read Original

Zbtlink is facing scrutiny after claims from VulnCheck CTO Jacob Baines, who alleges that Zbtlink routers are designed to communicate with command and control servers, likening this feature to a 'phone-home trojan horse.' This allegation raises concerns about potential security vulnerabilities in Zbtlink products. The company has paused firmware downloads, which could indicate a response to these claims or an effort to address any underlying issues. Users of Zbtlink routers may need to be cautious about their device security and monitor for any unusual activity. The implications of these claims could be significant, as users’ personal data and privacy might be at risk if the allegations are proven true.

Read Original

Walmart is facing a lawsuit in the U.S. District Court for the Northern District of Illinois over allegations that it secretly collects voiceprints from customers who call its stores. The lawsuit claims that Walmart records these calls and extracts vocal characteristics to create mathematical templates that can identify callers in the future. This raises significant privacy concerns, especially regarding how data is collected and used without explicit consent. If the allegations are proven true, it could lead to serious implications for Walmart's operations and customer trust, especially in a time when data privacy is a major concern for consumers. The case could set a precedent for how companies handle customer data in the future.

Read Original

Recent research has shown that more than half of security patches generated by artificial intelligence are likely to fail in fully addressing vulnerabilities. In some cases, these AI-generated solutions may even create new vulnerabilities that attackers can exploit. This raises significant concerns for organizations relying on AI to automate their security measures, as they may inadvertently introduce more risks instead of mitigating them. Companies and security teams should be cautious and verify the effectiveness of AI-generated patches before implementation to prevent potential exploitation. The findings serve as a reminder that while AI can aid in cybersecurity, it should not be solely depended upon without thorough human oversight.

Read Original

A new report from Chainalysis reveals a troubling trend where criminals are using physical violence, known as 'wrench attacks,' to steal cryptocurrency from victims. These attacks often involve assailants targeting individuals in their homes or public spaces, demanding access to digital wallets and private keys. This method of theft is particularly alarming because it combines traditional robbery tactics with the growing popularity of virtual currencies. Victims can suffer significant financial losses, and this shift in criminal strategy raises concerns about the safety of cryptocurrency holders. As the market for digital currencies expands, users need to be more vigilant about their physical security and take precautions to protect their assets.

Read Original
Actively Exploited

OpenAI recently disrupted a significant scam operation in Cambodia that used ChatGPT to facilitate various fraudulent activities. Criminals were exploiting the AI to run romance scams, fake investment schemes, and impersonate police officers, with reports suggesting potential links to human trafficking as well. This operation highlights how advanced AI tools can be misused for malicious purposes, impacting vulnerable individuals who might fall prey to these scams. The Cambodian authorities, in collaboration with OpenAI, are taking steps to address these issues and prevent further exploitation. This incident serves as a reminder for users to remain vigilant and cautious when engaging online, especially in sensitive areas like finance and personal relationships.

Read Original

China is currently reviewing products from Palo Alto Networks due to security concerns. This move raises questions about the trustworthiness of foreign cybersecurity products in the region. A spokesperson for Palo Alto Networks reassured that this review will not affect their ability to provide support or services to customers in China. The implications of this review could impact the company's market presence in the country and signal wider scrutiny of foreign technology firms by Chinese authorities. As geopolitical tensions continue to shape the tech landscape, such actions could influence how companies operate in sensitive markets.

Read Original
Actively Exploited

Researchers at Arctic Wolf have discovered that the LightSpy spyware, which has been linked to Chinese state-backed hackers since its initial identification in 2018, has now expanded its reach into over a dozen countries. Originally a tool for espionage, LightSpy has transformed into a commercial spyware platform, suggesting a shift in its usage and potential targets. The spyware is capable of infiltrating personal devices, raising concerns for individuals and organizations alike. This evolution indicates a growing threat to privacy and security, as more users may find themselves vulnerable to surveillance. The implications are significant, as this spyware could be utilized against a wide range of targets, including government officials and private citizens, making it crucial for users to remain vigilant about their digital security.

Read Original

Researchers at Pwn have identified a serious vulnerability in WordPress, dubbed the XSS2Shell flaw, which allows attackers to take control of an admin account and execute remote code. The issue arises when a user inputs a non-existent username, triggering a response from WordPress that contains a minor formatting error. This flaw can be exploited to gain unauthorized access to the server. WordPress users are strongly advised to update their installations to the patched versions to protect against this vulnerability. Failure to do so could leave sites open to full server takeover, posing significant risks to website security and data integrity.

Read Original

A recent study examining over 6,000 software patches has revealed that AI-generated patches are not as reliable as hoped, failing to resolve issues half the time. Even when patches do work, they can inadvertently cause new bugs or disrupt existing functionalities. Additionally, some patches may leave systems vulnerable to bypass attacks, raising concerns about their overall effectiveness. This is particularly important for software vendors and developers, as it highlights the risks associated with relying on automated solutions for security fixes. As organizations continue to adopt AI for various tasks, including security, they need to weigh the benefits against the potential for new problems introduced by these technologies.

Read Original

Levi Strauss & Co. has reported that hackers successfully infiltrated its systems by using social engineering tactics on three employees. This manipulation allowed the attackers to access and steal sensitive corporate data stored on the employees' machines. Such incidents highlight the vulnerabilities that organizations face when employees are targeted directly, emphasizing the need for stronger security awareness training. The breach raises concerns not only for Levi's but also for its customers and partners, as stolen corporate data can lead to further exploitation or misuse. Companies need to remain vigilant and implement robust security protocols to protect against similar attacks in the future.

Read Original

SIM swapping is a technique where attackers take control of a victim's phone number by persuading the mobile carrier to transfer the number to a new SIM card. This can lead to unauthorized access to personal accounts, including banking and social media, potentially resulting in identity theft. Many phones do not block this type of attack by default, leaving users vulnerable. To protect themselves, users should enable specific security settings offered by their mobile carriers, such as adding a PIN or password to their accounts. This issue is significant because it affects anyone who relies on their phone number for account verification, making it crucial for users to take these steps to secure their information.

Read Original

A cyberattack has disrupted operations at all three ports in North Carolina by targeting their gate systems. The U.S. Coast Guard is currently monitoring the situation as officials investigate the breach and assess its impact on port activities. This incident raises concerns about the security of critical infrastructure, as port operations are vital for trade and transportation. The extent of the disruption and the specific nature of the attack have not been fully disclosed, but it highlights the increasing vulnerability of essential services to cyber threats. Ongoing investigations will determine the long-term implications for port security and operations.

Read Original
Page 1 of 325Next