Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

On March 13, the WebFiling service of Companies House was taken offline after a security issue was discovered that exposed sensitive data of company directors. This incident raises concerns about the privacy and security of personal information for those listed as directors, as it could potentially be misused by malicious actors. Companies House, which is responsible for registering company information in the UK, has not provided detailed information about the nature of the data that was exposed or how many individuals were affected. The downtime of the service indicates a proactive measure to prevent further unauthorized access. This situation emphasizes the importance of maintaining secure systems, especially when handling sensitive personal data.

Impact: Companies House WebFiling service, director data
Remediation: Service taken offline to prevent further exposure
Read Original

Intuitive has reported a data breach resulting from a phishing attack that compromised sensitive information. The stolen data includes customer business and contact details, as well as employee and corporate data. This breach could potentially expose affected individuals and businesses to identity theft and fraud. Phishing attacks are a common tactic used by cybercriminals to gain unauthorized access to systems, making this incident a reminder of the constant need for vigilance in cybersecurity practices. Organizations are encouraged to review their security protocols and educate employees about recognizing phishing attempts to mitigate future risks.

Impact: Customer business and contact information, employee data, corporate data
Remediation: Organizations should implement phishing awareness training for employees and review security protocols to prevent similar attacks.
Read Original

In the latter half of 2025, there was a significant rise in credential theft incidents, primarily driven by advancements in infostealer malware and AI-powered social engineering tactics. Attackers are increasingly logging into accounts rather than using traditional methods to break in. This trend affects not only individual users but also organizations that store sensitive data, making them more vulnerable to breaches. The use of sophisticated malware makes it easier for cybercriminals to harvest login credentials, which can lead to unauthorized access and data theft. Companies and users alike need to be vigilant and implement stronger security measures to protect against these evolving threats.

Impact: User accounts, organizational credentials, sensitive data systems
Remediation: Implement multi-factor authentication, regularly update passwords, and monitor account activity for suspicious logins.
Read Original

The GlassWorm malware has resurfaced, launching a coordinated attack on over 400 code repositories and packages across platforms like GitHub, npm, and VSCode/OpenVSX. Researchers discovered that this supply-chain campaign targets developers by compromising popular software extensions and packages, potentially allowing attackers to inject malicious code into legitimate projects. This incident affects a wide range of developers and organizations relying on these platforms for their software development needs. The implications are significant, as compromised code can lead to broader security vulnerabilities in applications that utilize these affected packages. Developers are urged to audit their dependencies and ensure they're using trusted sources to mitigate the risk of infection.

Impact: GitHub, npm, VSCode, OpenVSX
Remediation: Developers should audit their code dependencies and avoid using unverified packages. Regularly updating software and using security tools to monitor for vulnerabilities is also recommended.
Read Original

As ransomware payments decline to historic lows, attackers are changing their tactics to adapt to the shrinking market. Research indicates that many ransomware actors are moving away from using sophisticated tools like Cobalt Strike and are instead relying on native Windows tools to carry out their attacks. This shift comes as the frequency of data theft incidents is increasing, suggesting that attackers are looking for ways to maintain their profitability despite the challenges. The implications of this trend are concerning for organizations, as it may lead to more widespread and varied attacks that are harder to detect and defend against. Companies need to stay vigilant and adapt their security measures to counter these evolving threats.

Impact: Cobalt Strike, native Windows tools
Remediation: Organizations should enhance their security protocols, monitor for unusual activity, and consider training staff on recognizing potential threats.
Read Original

A phishing attempt targeting a C-suite executive at cybersecurity firm Outpost24 recently came to light. The attackers used trusted brands and domains to trick the executive into revealing their login credentials. Although the attack was ultimately unsuccessful, it raises concerns about the vulnerabilities even experienced professionals face when dealing with sophisticated phishing schemes. This incident serves as a reminder for organizations to remain vigilant and reinforce security training, particularly for high-level staff who are often prime targets for attackers. The tactics employed in this case reflect the evolving strategies of cybercriminals, making it crucial for companies to continually update their defenses against such threats.

Impact: Outpost24, C-suite executive credentials
Remediation: Companies should enhance security awareness training for employees, particularly executives, and implement multi-factor authentication to protect against phishing attacks.
Read Original

The European Union Council has imposed sanctions on three Chinese and Iranian firms, along with two individuals, due to their involvement in cyberattacks aimed at critical infrastructure in Europe. These actions come as a response to increasing concerns over cyber threats that target essential services and systems, which could potentially disrupt daily life and national security. The sanctions serve as a warning to other entities that engage in similar malicious activities. This incident underscores the ongoing geopolitical tensions surrounding cybersecurity and the measures governments are willing to take to protect their infrastructures. The names of the sanctioned entities have not been disclosed, but the EU's firm stance indicates a commitment to countering cyber threats collaboratively.

Impact: N/A
Remediation: N/A
Read Original

Stryker, a major medical device manufacturer, recently experienced a cyberattack that has raised concerns among security experts. While the company claims to have contained the incident, experts warn that the recovery process could lead to costs in the millions. This incident affects Stryker's operations and could impact healthcare facilities that rely on their medical equipment. The potential financial burden from recovery efforts and the risk of operational disruptions highlight the ongoing challenges companies face in dealing with cyber threats. As organizations become increasingly reliant on technology, the implications of such attacks can be far-reaching, affecting patient care and the overall healthcare system.

Impact: Stryker medical devices and systems
Remediation: N/A
Read Original
Actively Exploited

Researchers have discovered a serious vulnerability in Android that allows attackers to hijack mobile payment applications using a technique called LSPosed-based runtime manipulation. This attack can bypass security measures such as SIM binding, which is intended to protect users' financial transactions. As a result, anyone using affected payment apps could be at risk of fraud and unauthorized transactions. This incident highlights the ongoing challenges in mobile security, especially for users who rely on their devices for financial activities. Users should be cautious and consider reviewing their app security settings until further protections are implemented.

Impact: Android mobile payment applications, particularly those using LSPosed framework
Remediation: Users should monitor their payment app security settings and stay updated with any security patches from app developers.
Read Original

The UK Companies House has acknowledged a security vulnerability that potentially exposed sensitive details of millions of businesses. This flaw could allow unauthorized individuals to access company information and modify official records. The agency has confirmed that the issue could have serious implications for the integrity of business data in the UK, raising concerns about identity theft and fraud. As Companies House holds critical information about registered companies, this exposure poses a significant risk to both businesses and consumers. Authorities are urging companies to remain vigilant and review their security practices in light of this breach.

Impact: Companies House records of millions of firms in the UK
Remediation: Companies should review security measures and monitor for suspicious activity.
Read Original

The Warlock Ransomware Group has recently enhanced its operations by using a new technique called BYOVD, which allows them to conduct stealthier activities across networks. This technique, combined with other tools, enables the group to exploit systems more effectively and avoid detection. The implications of this development are significant, as it suggests that organizations may be at greater risk of ransomware attacks that can spread quickly across their networks. Companies should be vigilant and ensure their security measures are robust enough to counter these evolving tactics. Users need to stay informed about such threats to protect their data and systems.

Impact: N/A
Remediation: Organizations should enhance their network monitoring, apply security patches, and ensure that endpoint protection solutions are updated to defend against these threats.
Read Original

The RondoDox botnet is ramping up its activities, now targeting 174 different vulnerabilities with an alarming rate of 15,000 exploitation attempts each day. This more focused campaign signals a strategic shift in how the botnet operates, making it a significant concern for cybersecurity experts. Organizations and individuals who use software with these vulnerabilities are at heightened risk of being attacked. The botnet's ability to exploit these flaws could lead to unauthorized access, data breaches, and other serious security incidents. As researchers continue to monitor this situation, it's crucial for affected users to take preventive measures and patch their systems promptly.

Impact: 174 vulnerabilities across various software and systems
Remediation: Users should apply the latest security patches and updates from their software vendors to mitigate these vulnerabilities. Regularly updating systems and conducting vulnerability assessments are also recommended.
Read Original

Researchers have identified a security vulnerability called 'CursorJack' that affects the Cursor IDE, a development environment used for coding, particularly in AI projects. This flaw allows attackers to exploit malicious deeplinks, which can lead to unauthorized code execution if users inadvertently approve these links. The risk is significant because it can compromise the integrity of the code being developed, potentially leading to the introduction of harmful code into applications. Developers using the Cursor IDE should be aware of this vulnerability and take precautions to avoid falling victim to such attacks. The implications extend beyond individual users, as compromised code could lead to broader security issues in applications that rely on this development environment.

Impact: Cursor IDE
Remediation: Users should be cautious about clicking on unknown links and consider reviewing security settings in the Cursor IDE. No specific patches or updates are mentioned.
Read Original

The article emphasizes the need for Chief Information Security Officers (CISOs) to take immediate action to secure AI agents, which are increasingly being integrated into business processes. It stresses the importance of identity-based access control to prevent unauthorized use and potential data breaches. This is particularly relevant as AI agents operate autonomously and can access sensitive data and systems. By implementing strong access controls, organizations can mitigate risks associated with misuse and data exposure. As AI technology continues to evolve, ensuring its security is crucial for protecting both company assets and customer information.

Impact: AI agents, data systems
Remediation: Implement identity-based access control measures
Read Original

Researchers have identified a new font-rendering attack that can trick AI tools into overlooking malicious commands embedded in seemingly harmless HTML on webpages. This technique manipulates how text is displayed, making it difficult for AI assistants to recognize and respond to the hidden threats. The attack poses a significant risk, as it can be used to bypass security measures and deliver harmful instructions without triggering alerts. Users and organizations relying on AI for automated tasks or security monitoring need to be aware of this vulnerability, as it could lead to unauthorized actions or data breaches. The discovery emphasizes the need for enhanced scrutiny of web content, especially as AI tools become more integrated into everyday applications.

Impact: AI tools, web browsers, HTML rendering systems
Remediation: Users should implement stricter content filtering and validation measures on webpages to detect and block suspicious HTML. Regular updates to AI tools and security software are recommended to improve detection capabilities.
Read Original
PreviousPage 103 of 216Next