Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Cybersecurity researchers have identified a new Internet-of-Things (IoT) botnet framework called TuxBot v3 Evolution. This botnet appears to have been developed with some assistance from a large language model (LLM), although the results have not been entirely successful. Notably, when the developers prompted the AI to generate botnet code, it included a safety disclaimer that the developers did not remove. This incident raises concerns about the potential misuse of AI in creating malicious software. As IoT devices become more prevalent, any vulnerabilities or botnets that target them could impact a wide range of users and systems, making it crucial for manufacturers and users to enhance their security measures.

Read Original

During a recent confirmation hearing for Jay Clayton, the nominee for Director of National Intelligence (DNI), Democratic senators pressed him on various election security issues. Clayton denied being an 'election denier' but avoided giving direct answers to questions regarding the 2020 presidential election, his predecessor's involvement in a January raid on an election office, and broader election integrity concerns. This lack of clarity has left some senators feeling frustrated, as they sought assurances on the protection of future elections from interference and disinformation. The situation raises ongoing concerns about the federal government's commitment to safeguarding the electoral process, especially as the next elections approach. Ensuring election security is crucial for maintaining public trust in democratic institutions.

Read Original

The recent restrictions imposed by the US government on AI companies like Anthropic and OpenAI have sparked significant discussions in the UK and elsewhere about reducing dependence on American technology firms. This push for greater technological sovereignty comes as countries assess the implications of relying on foreign companies for critical AI capabilities. The situation raises concerns about data security and national interests, as countries may seek to develop their own AI models to safeguard against potential vulnerabilities and geopolitical risks. The call for sovereignty is not just about technology but also about ensuring that nations can protect their data and maintain control over their digital futures. As this dialogue progresses, it could lead to shifts in how AI technologies are developed and deployed globally.

Read Original
Critical
Fake Céline Dion Paris Tickets Sold on Facebook and Ticketmaster Clones

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Scammers are targeting fans of Céline Dion by selling fake tickets through Facebook and creating counterfeit websites that mimic legitimate ticket sellers like Ticketmaster and AXS. According to cybersecurity firm Group-IB, these scammers are taking advantage of fans looking to purchase tickets for Dion's shows, leading to potential financial losses for unsuspecting buyers. The fake tickets and websites can create significant confusion and frustration for those trying to enjoy live performances. It’s crucial for fans to be cautious and verify the authenticity of ticket sources to avoid falling victim to these scams, especially as live events resume post-pandemic.

Read Original

Recently, researchers discovered that five malicious versions of AsyncAPI packages were uploaded to the Node Package Manager (npm). These packages contained a remote access trojan designed to steal user credentials and other sensitive information. This supply-chain attack poses a significant risk, as developers who unknowingly downloaded these infected packages could have their systems compromised. The incident highlights the vulnerabilities within the npm ecosystem and the importance of scrutinizing third-party packages before use. Developers and organizations should be vigilant about the packages they incorporate into their projects to avoid similar attacks in the future.

Read Original

A vulnerability known as 'PromptFiction' has been addressed, but it had the potential to combine with another flaw, referred to as the 'Claude Flaw', to launch an end-to-end attack on targeted systems. This means that attackers could have exploited these vulnerabilities to send malicious prompts to AI agents, potentially compromising systems that rely on AI for various functions. While the 'PromptFiction' vulnerability has been fixed, the implications of the 'Claude Flaw' highlight ongoing security challenges in AI systems. Companies using AI technologies need to remain vigilant about such vulnerabilities to protect their systems from potential exploitation. It's crucial for organizations to regularly update their security measures and stay informed about emerging threats.

Read Original
Actively Exploited

A phishing campaign that lasted six months used seasonal eCards to trick victims into downloading legitimate Remote Monitoring and Management (RMM) tools. Attackers crafted emails that appeared to be friendly holiday greetings, leading individuals to believe they were receiving festive messages. Instead, these emails contained links that, when clicked, installed RMM software on the victims' devices without their knowledge. This tactic poses a significant risk as it allows attackers to gain remote access to the systems of unsuspecting users, potentially leading to data breaches and further exploitation. Companies and individuals need to be vigilant about unexpected emails, especially those that seem too good to be true, to avoid falling victim to similar attacks.

Read Original

A recently discovered vulnerability in Cursor allows attackers to execute arbitrary code on users' systems without their consent. By creating a malicious repository containing a 'git.exe' file in the project root, attackers can exploit this flaw, which Cursor executes automatically when the repository is accessed. This puts users at significant risk, especially those who frequently interact with repositories from untrusted sources or do not have adequate security measures in place. As there is currently no patch available to fix this issue, users should be cautious when using Cursor and consider limiting their exposure to potentially harmful repositories. This vulnerability serves as a reminder of the importance of maintaining security hygiene in software development environments.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to quickly address three vulnerabilities in SharePoint that are currently being exploited by attackers. Among these, two have been identified as zero-days, meaning they are actively targeted before a patch was made available. This situation poses significant risks to users of SharePoint, as attackers could gain unauthorized access to sensitive data or disrupt operations. Organizations that use SharePoint are advised to prioritize patching these vulnerabilities to protect their systems and data from potential breaches. Immediate action is crucial to mitigate the risks associated with these exploits.

Read Original

A new AI-powered system has been developed to automatically find complex software vulnerabilities, referred to as a 'vulnerability vending machine.' This system utilizes code slicing alongside large language models (LLMs) to discover previously unknown security flaws. Recently, it successfully identified and exploited a zero-day vulnerability in a WordPress plugin, which had not been publicly known before. The company behind this technology is also working on additional vulnerabilities that are currently under responsible disclosure, meaning they are notifying affected parties before making the details public. This development raises concerns about the ease of finding and exploiting software vulnerabilities, potentially putting many users and systems at risk if such tools become widely accessible.

Read Original

Recent reports indicate that Iran has exploited vulnerabilities in the Signaling System 7 (SS7) protocols, which are essential for 2G and 3G mobile networks. This manipulation allowed Iranian operatives to intercept and reroute calls and text messages globally, potentially tracking U.S. military personnel. The implications of this are significant, as it raises concerns about the security of mobile communications, especially for military and governmental operations. The ability to monitor communications could lead to increased risks for personnel and sensitive operations. This incident serves as a reminder of the vulnerabilities inherent in older telecommunications protocols and the need for enhanced security measures.

Read Original

Mozilla has rolled out updates for Firefox to fix two serious vulnerabilities that could be exploited by attackers. The flaws, identified as CVE-2026-15718 and CVE-2026-15719, involve issues with JavaScript: WebAssembly and site isolation in the DOM: Navigation component. Mozilla has warned users that exploit code for these vulnerabilities is already available publicly, increasing the urgency for users to update. It’s crucial for Firefox users to install these updates promptly to protect against potential attacks that could compromise their security and privacy. Keeping software up to date is a key defense against such risks.

Read Original
Actively Exploited

A newly discovered vulnerability, dubbed the '2-Click Cursor Exploit,' allows attackers to gain unauthorized access to developers' environments, potentially exposing sensitive secrets and source code. This exploit takes advantage of simple bugs that have been around for a long time, making it particularly concerning for organizations that rely on secure development practices. Developers using certain software tools could be at risk, as the exploit can lead to a complete takeover of their development environments. The implications are significant, as compromised environments can result in the theft of intellectual property and sensitive data. Companies are urged to review their security protocols and patch any vulnerabilities in their development tools as soon as possible.

Read Original

Recent research by Sophos reveals that compromised logins are now the leading method for ransomware delivery, surpassing traditional software vulnerabilities. This shift means that attackers are increasingly using phishing, brute force attacks, and other identity-based threats to gain access to networks. As a result, organizations may be at greater risk if they do not enhance their security measures around user credentials. Companies should prioritize employee training on recognizing phishing attempts and implement multi-factor authentication to bolster defenses. This change in attack vectors highlights the need for a more proactive approach to cybersecurity, particularly in safeguarding login credentials.

Read Original
Critical
PromptFiction Flaw Auto-Submitted Hidden Prompts in Claude Desktop

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A vulnerability in Claude Desktop has been discovered that allows attackers to submit hidden prompts with just one click. This flaw could lead to unauthorized access to chat conversations and even enable remote code execution on vulnerable systems. Users of Claude Desktop should be particularly cautious, as this could impact the integrity and confidentiality of their data. The ease of exploitation raises concerns about the potential for widespread misuse. It is essential for users to stay informed about this issue and apply any necessary updates or security measures as they become available.

Read Original
PreviousPage 103 of 369Next