Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Five Democratic senators have expressed their concerns over the Trump administration's approach to managing artificial intelligence (AI) security risks. They argue that the administration has been inconsistent, sometimes too passive and at other times overreaching, which they believe has created an environment where China could gain an advantage in AI development. The senators are urging for a more balanced and proactive strategy to address the growing security challenges posed by AI technologies. This situation is critical as AI continues to evolve rapidly, impacting various sectors, including defense and cybersecurity. The senators' critique highlights the need for a clear and effective policy to mitigate potential risks associated with AI advancements.

Read Original

A new self-propagating malware called 'ChainDrop' has infected over 1,300 packages in the Node Package Manager (npm) registry, which collectively see around 2 billion downloads each month. This attack allows the malware to spread rapidly across various software projects that rely on npm packages. Developers and companies using these compromised packages are at risk of introducing vulnerabilities into their applications. The incident raises significant concerns about supply chain security, as it demonstrates how a single attack can impact a vast number of users and systems. Those affected should take immediate steps to identify and remove the compromised packages from their projects to mitigate potential damage.

Read Original

The INC ransomware group has been linked to recent attacks exploiting zero-day vulnerabilities in SonicWall products. While they weren't the first to take advantage of these flaws, their aggressive tactics in combining both vulnerabilities have made them particularly effective at stealing and encrypting sensitive data for ransom. This situation poses a significant risk for organizations using affected SonicWall devices, as it can lead to severe data breaches and financial losses. Users and companies relying on SonicWall's security products need to be vigilant and implement necessary precautions to protect their systems. The ongoing threat from INC highlights the importance of timely updates and monitoring for unusual activity in network environments.

Read Original
Actively Exploited

A recent WhatsApp scam has exploited the app's Linked Devices feature to take control of user accounts without needing to steal passwords. This method allows attackers to gain access to someone's WhatsApp by tricking them into providing a verification code. Victims are often misled into thinking they are verifying their own devices, making it easier for scammers to hijack accounts. This incident raises significant concerns about the security of user accounts on popular messaging platforms, especially as more people rely on these apps for personal and professional communication. Users should be cautious and verify any unexpected requests for verification codes to protect their accounts.

Read Original

Researchers have found that built-in email chatbots could be weaponized by attackers to impersonate trusted employees, potentially leading to account hijacking and financial fraud. These AI assistants, often designed to make email communication more efficient, can be exploited to bypass security measures and compromise executive accounts. This poses a significant risk to organizations, as attackers could manipulate these tools to send deceptive messages that appear legitimate to recipients. The implications are serious, as companies may face not only financial losses but also damage to their reputations. Users and organizations need to be aware of these vulnerabilities and take steps to secure their email systems against such tactics.

Read Original

A credential-stealing worm linked to the npm package 'keyv' has spread to hundreds of packages since it was first identified on August 4, 2026. This malware has affected at least 868 packages according to Aikido, with SafeDep confirming 353 poisoned versions across 79 package names in the npm registry. The worm is designed to steal user credentials and has also incorporated hooks for the Claude code and Visual Studio Code environments. This incident raises serious concerns for developers and organizations using these packages, as compromised libraries can lead to significant security breaches and data loss. Users are urged to audit their dependencies and ensure they are using safe versions of affected packages.

Read Original

Researchers from Talos have discovered that cybercriminals are finding ways to bypass AI safety controls by splitting malicious activities across multiple sessions. They found that the AI's guardrails, designed to prevent harmful actions, fail when attackers claim ownership of the tasks. This technique allows them to evade detection and continue their malicious activities without triggering security alerts. The implications are significant, as it shows that existing safety measures can be manipulated, potentially leading to increased risks for organizations relying on AI for security. Companies need to reassess their AI systems and strengthen their defenses against such tactics.

Read Original

The U.S. Senate is set to discuss a series of bills aimed at enhancing online safety for children, with a focus on the Kids Online Safety Act. This legislation seeks to establish stricter guidelines on how minors interact with the internet, aiming to protect them from potential dangers associated with online platforms. The proposed measures come in response to growing concerns about children's safety in the digital age, especially regarding privacy and exposure to harmful content. If passed, these bills could significantly reshape how tech companies operate with respect to young users, making it crucial for parents, educators, and industry stakeholders to stay informed about these developments. The outcome of this debate will have lasting implications for online privacy and safety standards for minors.

Read Original

Researchers from Forescout have identified 15 vulnerabilities within the TP-Link Omada networking ecosystem. These weaknesses could potentially allow attackers to take complete control of affected networks. The Omada platform is widely used in enterprise environments for managing network devices, making this discovery particularly concerning for businesses relying on these tools. The vulnerabilities stem from the Zero Touch Provisioning (ZTP) feature, which, if exploited, could enable unauthorized access and manipulation of network settings. Companies using TP-Link Omada devices should prioritize patching these vulnerabilities to protect their networks from potential attacks.

Read Original

A serious vulnerability has been identified in several Thermo Fisher Applied Biosystems Genetic Analyzers, which could allow attackers to tamper with DNA data by modifying output files. This flaw affects multiple versions of their software, including the 3500 Series, 3730 Series, SeqStudio, and GeneMapper ID-X, among others. The risk is significant because altered DNA test results could lead to incorrect diagnoses and treatments in healthcare settings. To mitigate the issue, Thermo Fisher has released security updates that implement digital signatures to ensure data integrity. Users are advised to update their software to the latest versions as soon as possible and to follow interim measures to secure their data until the updates can be applied.

Read Original
Critical
Acrisure KARR BT and DR-100

All CISA Advisories

Acrisure's KARR BT and DR-100 vehicle security systems have a serious vulnerability that could allow attackers to control vehicles remotely. The issue stems from a hard-coded Bluetooth authentication key shared among affected devices, which could let someone within range unlock doors or disable the engine. This affects all KARR BT firmware versions before July 20, 2026, and DR-100 firmware versions before the same date. While no public exploitation of this vulnerability has been reported yet, users are urged to update their devices to mitigate the risk. A firmware update has been released on July 20, 2026, to address this flaw, and users can find detailed instructions for the update on the KARR Security website.

Read Original
Actively Exploited

Recent research indicates that cloud and Software as a Service (SaaS) platforms have become prime targets for cyber attackers. As more companies shift their operations to these environments, threat actors are increasingly exploiting vulnerabilities related to identity management. This trend raises significant concerns for businesses and users, as it exposes sensitive data to breaches and unauthorized access. Companies need to enhance their security protocols and remain vigilant against identity-based attacks, which are on the rise. Failing to do so could lead to severe financial and reputational damage.

Read Original

Recent discussions in the cybersecurity field are shifting the focus from traditional assessments of attacker sophistication to a new threat: 'vibe hacking.' This term describes how artificial intelligence (AI) is being used by less experienced attackers, allowing them to execute sophisticated attacks without extensive technical knowledge. As AI tools become more accessible, even those labeled as 'script kiddies' can leverage these technologies to enhance their hacking capabilities. This evolution in the threat landscape could make it harder for security teams to predict and counteract attacks, as the barrier to entry for launching effective cyberattacks continues to drop. Businesses and organizations need to adapt their security strategies to account for this new wave of AI-enabled threats, which could lead to more frequent and varied attacks.

Read Original

cPanel has addressed a serious vulnerability that allowed authenticated users to execute SQL commands with root database privileges. This flaw, tracked as CVE-2026-58048 and rated 9.4 on the CVSS scale, breaks the security boundary between individual cPanel accounts and the server's administrative database identity. The issue was fixed in a recent security update, which also addressed two other privilege escalation paths. Hosting customers who use cPanel should be aware of this vulnerability, as it could have allowed unauthorized access to sensitive data or manipulation of critical database functions. It's crucial for users to ensure they are using the latest version of cPanel to mitigate any potential risks associated with this flaw.

Read Original

Interpol has reported a significant rise in cybercrime across Africa, attributing this surge to the use of artificial intelligence by attackers. The agency noted that the financial losses related to these crimes have doubled, indicating a troubling trend in the region. This increase in cybercriminal activity is particularly concerning for businesses and individuals, who may face heightened risks from sophisticated AI-driven attacks. The implications are serious, as greater reliance on technology can expose vulnerabilities and lead to more severe consequences for victims. As cybercriminals harness AI capabilities, law enforcement and cybersecurity professionals will need to adapt their strategies to counter these evolving threats.

Read Original
Page 1 of 315Next