Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Ahmed Elbadawy, a member of the cybercrime group known as Scattered Spider, has pleaded guilty to participating in a series of cybercrimes that allowed him to amass significant wealth. Prosecutors have indicated they are pursuing the forfeiture of approximately $17.6 million in virtual currencies, along with luxury vehicles, jewelry, and designer bags linked to his illegal activities. This case exemplifies the ongoing challenges law enforcement faces in tackling organized cybercrime. The financial proceeds from such crimes not only enrich the perpetrators but also fund further illicit activities, making it crucial for authorities to act decisively against such networks. The resolution of this case could have implications for how similar crimes are prosecuted in the future.

Read Original

The article discusses the limitations of Multi-Factor Authentication (MFA) in protecting against OAuth consent abuse. While MFA adds an extra layer of security, it doesn't address the need for proper governance of OAuth protocols, which can lead to unauthorized access when users mistakenly grant permissions. Companies must implement least-privilege scopes and actively monitor consent to ensure that users are not giving away more access than necessary. Additionally, quick revocation of permissions is crucial in mitigating potential breaches. This issue is particularly relevant as OAuth is widely used across various applications, making proper management essential to safeguard user data.

Read Original

A security researcher has made public exploit code for four vulnerabilities in the Linux kernel that allow local users to gain root access, which is the highest level of control on a computer. These vulnerabilities have been patched in recent updates, meaning that systems with the latest kernel versions are not at risk. However, machines running older versions of the kernel could be vulnerable, putting them at potential risk of exploitation. Users and administrators are strongly advised to update their systems to the latest kernel version to prevent unauthorized access. The release of this exploit code increases the urgency for users to ensure their systems are secure, as it makes it easier for attackers to leverage these flaws if they remain unpatched.

Read Original

Researchers have identified a significant software decoder flaw that was able to grant attackers remote code execution privileges. This vulnerability, which has since been patched, put user accounts and production environments at risk, affecting major platforms like Meta's product suite and an OpenAI software repository. The ability for attackers to exploit this flaw raises serious concerns about the security of widely used software components. Organizations that rely on these products should ensure they have implemented the necessary patches to protect their systems. This incident serves as a reminder of the ongoing challenges in software security and the need for vigilant monitoring and updates.

Read Original

WordPress has patched several vulnerabilities in its core software, including a serious flaw that could let attackers install themes from the official WordPress.org directory without user consent. This vulnerability, dubbed Click2Shell by researchers at pwn.ai, specifically affects logged-in administrators who click on a specially crafted link. While the flaw requires user interaction to exploit, it poses significant risks as it could lead to unauthorized code execution on compromised sites. Website owners using WordPress should ensure they update their installations promptly to protect against potential exploitation. The discovery of this vulnerability emphasizes the ongoing need for vigilance in web application security.

Read Original
Actively Exploited

Gyazo, a popular image-sharing platform, has confirmed a significant data breach due to a vulnerability in its server. Hackers exploited this flaw to access and steal approximately 23.6 million user records, which raises serious concerns about data privacy and security for those affected. The breach likely includes sensitive information that could be used for identity theft or other malicious purposes. This incident serves as a reminder for users to be vigilant about their online security and for companies to prioritize robust security measures. Gyazo has not yet released specific details on how they plan to address this vulnerability or secure their systems moving forward.

Read Original

International security agencies from the U.S., Japan, Germany, and Australia have raised alarms about a group of North Korean hackers known as WaterPlum. These attackers are posing as potential employers to lure job seekers, ultimately infecting over 30,000 devices worldwide. By exploiting the job application process, they aim to steal sensitive information, including cryptocurrency and personal data. This tactic not only threatens individuals looking for work but also highlights the growing trend of cybercriminals using social engineering to manipulate victims. The situation underscores the need for vigilance among job seekers and the importance of verifying the legitimacy of potential employers before sharing any personal information.

Read Original

Transparent Tribe, a cyber threat group linked to Pakistan, has launched new attacks targeting government and defense sectors in India and Afghanistan. Researchers from Zscaler ThreatLabz identified a set of new tools used in these attacks, including RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The group is utilizing private GitHub repositories for command and control (C2) operations, making detection more challenging. This activity is significant as it underscores the ongoing cyber risks faced by sensitive government entities in the region. The use of novel tools indicates that the attackers are evolving their methods, which may lead to increased threats for the affected organizations.

Read Original

A new malware campaign is using fake GitHub repositories that mimic well-known software companies to distribute an information stealer called Rapuncel. Researchers have identified that these SEO-optimized repositories are designed to trick users into downloading malicious software disguised as legitimate applications. The Rapuncel malware is previously undocumented, making it particularly concerning as it could target unsuspecting users who rely on popular software solutions. This situation raises alarms for individuals and organizations alike, as it highlights the risks of downloading software from unofficial channels. Users are advised to be cautious and verify the authenticity of any software before installation.

Read Original

A new cybersecurity threat involves fake calendar invites that can bypass security software and compromise users' systems. These malicious invites can embed themselves directly into a user's calendar, potentially leading to infections that may steal personal information or deploy harmful software. Users across various platforms are at risk, particularly those who frequently use digital calendars for work or personal scheduling. It’s crucial for individuals and organizations to be vigilant about the invites they accept and to verify the sender's identity before engaging with any calendar event. Implementing security measures, such as using email filtering tools and educating users about recognizing suspicious invites, can help mitigate these risks.

Read Original

This article brings attention to several significant cybersecurity incidents that may have been overlooked. A ransomware developer has been sentenced, highlighting ongoing legal actions against cybercriminals. Additionally, the Plugin4Shell vulnerability has been exploited in an AI attack, raising concerns about the security of widely used plugins. Furthermore, a critical flaw in SAP systems has been identified, which could potentially expose sensitive data. These incidents serve as a reminder of the evolving threats in cybersecurity and the importance of staying informed about vulnerabilities that could affect organizations and users alike.

Read Original

A new ransomware variant called Settra has been identified by Huntress researchers, who observed its deployment in attacks targeting the retail and manufacturing sectors. The attacks involved techniques that came into play after the initial compromise, suggesting that attackers are using advanced methods to infiltrate systems and spread the ransomware. This variant poses a significant risk as it can disrupt operations in critical industries, potentially leading to data loss and financial damage. Companies in these sectors should be vigilant and enhance their cybersecurity measures to defend against such threats. The emergence of Settra highlights the ongoing challenges organizations face in protecting their networks from increasingly sophisticated ransomware attacks.

Read Original

Microsoft has addressed a serious security flaw in Azure AI Foundry, identified as CVE-2026-85889, which has been assigned a maximum severity score of 10.0. The vulnerability stems from a lack of authentication for critical functions, allowing unauthorized users to escalate their privileges over a network. This flaw could potentially let attackers gain higher-level access than intended, posing significant risks for organizations using the platform. Fortunately, Microsoft has implemented fixes, and users do not need to take any additional action to secure their systems. However, the incident emphasizes the importance of vigilance in cloud security practices.

Read Original

Researchers from Hacktron successfully accessed OpenAI employee accounts by exploiting a flaw in the sign-in process, which was partly created using AI tools. This breach allowed them to potentially view internal OpenAI code. The researchers received a bug bounty for their demonstration, indicating that the vulnerability was taken seriously by OpenAI. This incident raises concerns about the security of AI companies and the potential risks associated with AI-generated code. It highlights the importance of securing access to sensitive employee accounts to prevent unauthorized access to proprietary information.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The vulnerabilities, identified as CVE-2025-39964 and CVE-2026-53266, affect the Linux kernel and are categorized as a race condition and an out-of-bounds write, respectively. These types of vulnerabilities are commonly targeted by cybercriminals and pose significant risks to federal agencies. The recent Binding Operational Directive (BOD) 26-04 emphasizes that federal agencies must prioritize quick fixes for these high-risk vulnerabilities. While the directive is aimed at federal agencies, CISA encourages all organizations to adopt similar measures for vulnerability management. Organizations aware of other exploited vulnerabilities can submit them for consideration to be added to the KEV Catalog.

Read Original
Page 1 of 409Next