Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Intuitive Surgical, known for its robotic surgical systems, has disclosed a cyberattack that compromised some of its internal business applications. The breach occurred after an employee was targeted by a phishing attack, allowing unauthorized access to the company's systems. While the specific data accessed has not been detailed, this incident raises concerns about the security of sensitive information within the healthcare sector. As a leading provider of robotic surgery solutions, any disruption or potential data compromise could impact patient care and trust in their technologies. The company is likely reviewing its security protocols to prevent future incidents.

Impact: Internal business applications of Intuitive Surgical
Remediation: Strengthening employee training on phishing awareness and reviewing security protocols
Read Original

Franz Regul, the former Chief Information Security Officer for the Paris 2024 Olympics, addressed the unique cybersecurity challenges faced by the event, especially as it prepares for the upcoming games. With a focus on evolving threats, Regul implemented strategies to safeguard sensitive data and protect against potential attacks. As the Olympics draw nearer, the need for a strong cybersecurity framework becomes increasingly vital, particularly with the high-profile nature of the event attracting various malicious actors. The lessons learned from Paris 2024 will also inform security measures for the Milan Cortina 2026 Olympics, aiming to create a safer environment for athletes and spectators alike. This proactive approach to cybersecurity underscores the importance of preparedness in large-scale events.

Impact: Olympic Games cybersecurity systems
Remediation: Implementing advanced security protocols and continuous monitoring systems
Read Original

The RondoDox botnet has ramped up its operations, now targeting 174 different vulnerabilities and reaching a peak of 15,000 exploitation attempts each day. This botnet is adopting a more focused strategy, which raises concerns for organizations as it indicates a shift towards exploiting specific weaknesses rather than a broader, less efficient approach. The increase in targeted attacks could impact a wide range of systems and software that have these vulnerabilities, potentially leading to data breaches or system compromises. Companies and IT teams need to be vigilant and proactive in securing their systems against these threats to prevent exploitation. It’s crucial for affected organizations to review their security posture and apply necessary patches or updates.

Impact: N/A
Remediation: Organizations should apply security patches for identified vulnerabilities, review configurations, and enhance monitoring for unusual activity.
Read Original

The European Union has imposed sanctions on a Chinese company linked to a significant cyberattack that compromised approximately 65,000 devices. This action is part of a broader effort to address cyber threats from entities in China and Iran, which have been targeting EU member states and their partners. As a result of the sanctions, the affected companies and individuals will face asset freezes, travel bans, and restrictions on financial transactions with EU citizens and businesses. This move aims to hold accountable those responsible for cyberattacks and to deter future incidents. The situation underscores the ongoing cybersecurity challenges faced by nations and the need for coordinated international responses to cyber threats.

Impact: 65,000 devices, Chinese company involved in cyberattacks
Remediation: N/A
Read Original

Since 2020, a Chinese-linked hacking group known as CL-STA-1087 has been targeting military organizations in Southeast Asia. This group has utilized two types of malware, named AppleChris and MemFun, to carry out its espionage activities. The group's operations show a calculated approach, focusing on gathering specific intelligence rather than conducting widespread attacks. This ongoing campaign raises concerns about the security of military data in the region and highlights the risks posed by state-sponsored cyber espionage. The implications of such targeted attacks could undermine national security and diplomatic relations in Southeast Asia.

Impact: Southeast Asian military organizations
Remediation: N/A
Read Original
GitGuardian Reports an 81% Surge of AI-Service Leaks as 29M Secrets Hit Public GitHub

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

GitGuardian has reported a significant increase in the number of sensitive data leaks related to AI services, revealing that around 29 million secrets were publicly exposed on GitHub. This represents an 81% surge compared to previous records. These leaks often include API keys, passwords, and other confidential information that can be exploited by malicious actors. The findings raise concerns about the security practices of developers and organizations using AI tools, as these leaks can lead to unauthorized access and data breaches. Companies need to adopt stronger security measures to safeguard their sensitive information and prevent further exposure.

Impact: GitHub, AI services, API keys, sensitive data
Remediation: Companies should implement better security practices, including regular audits of code repositories and using secret management tools to prevent leaks.
Read Original

A recent report by Armis indicates a significant rise in cyberattacks from nation-state actors targeting UK businesses. The concept of 'mutually assured disruption,' which previously discouraged such attacks, appears to be losing its effectiveness. This shift raises concerns about the potential for increased cyber warfare, putting numerous companies at risk. The report suggests that many firms may not be adequately prepared for these state-backed threats, which could lead to severe disruptions in operations and data security. As tensions rise globally, businesses in the UK need to bolster their cybersecurity measures to defend against these evolving risks.

Impact: UK firms, particularly in critical sectors
Remediation: Companies should enhance their cybersecurity protocols, conduct regular security assessments, and train employees on recognizing phishing attempts and other cyber threats.
Read Original

Akamai has issued a warning about a new wave of cyberattacks that combine Layer 7 DDoS attacks, API abuse, and AI-driven tactics. These coordinated assaults are becoming more sophisticated and are increasingly difficult for organizations to detect and defend against. The blending of these attack vectors means that traditional defenses may not be sufficient, putting many companies at risk. As attackers enhance their methods, it's crucial for businesses to stay informed and adapt their security strategies accordingly. This trend could affect a wide range of industries, making it essential for companies to prioritize their cybersecurity measures.

Impact: Layer 7 DDoS attacks, API services
Remediation: Companies should enhance their monitoring and detection capabilities, implement rate limiting for APIs, and regularly update their security protocols to address evolving threats.
Read Original
Actively Exploited

According to a report from Akamai, API attacks have surged by 113% over the past year, marking a significant rise in the frequency of these incidents. The report reveals that a staggering 87% of organizations experienced at least one security issue related to APIs last year. This increase in API attacks poses serious risks, as APIs are critical for modern applications and are often targeted for sensitive data. The findings indicate that companies need to bolster their security measures to protect against these growing threats, as attackers are increasingly exploiting vulnerabilities in API implementations. With the rise of digital services, ensuring the security of APIs has become essential for safeguarding both organizational data and user information.

Impact: APIs, web applications, cloud services
Remediation: Organizations should implement API security best practices, including regular security assessments, access controls, and monitoring for unusual activity.
Read Original

Quantum computing has the potential to disrupt current encryption methods, putting sensitive data at risk. Experts warn that organizations need to start shifting to post-quantum cryptography to safeguard against future threats, particularly the 'harvest now, decrypt later' strategy used by attackers. This approach allows adversaries to collect encrypted data today and decrypt it later when quantum computers become powerful enough. Without proactive measures, businesses could face significant security vulnerabilities as quantum technology advances. Transitioning to new cryptographic standards is essential to protect data integrity and confidentiality in the coming years.

Impact: Current encryption standards, sensitive data across various sectors
Remediation: Transition to post-quantum cryptography standards
Read Original

Researchers have discovered a long-running cyberespionage campaign linked to Chinese hackers targeting military organizations in Southeast Asia. The attackers utilized advanced backdoor techniques and traditional evasion methods to maintain ongoing access to these sensitive networks. This campaign has raised concerns about the security of military operations and the potential for sensitive information to be compromised. The infiltration has reportedly been active for years, indicating that these hackers have been able to operate undetected for an extended period. This situation highlights the ongoing cybersecurity challenges faced by military organizations in the region and the need for enhanced defenses against such sophisticated threats.

Impact: Southeast Asian military organizations
Remediation: Organizations should conduct thorough security audits, implement advanced threat detection systems, and regularly update their cybersecurity protocols to counteract similar intrusions.
Read Original
Actively Exploited

The GlassWorm supply chain attack campaign has escalated, involving dozens of malicious Open VSX extensions and over 150 compromised GitHub repositories, according to reports from The Hacker News. This campaign targets software development environments, potentially affecting developers who use these extensions and repositories for their projects. By infiltrating trusted sources, attackers can distribute malicious code that may compromise the integrity of software development processes. Users and organizations relying on these platforms need to be vigilant and ensure their systems are secure to mitigate the risk of infection. The widespread nature of this attack highlights the growing threat to software supply chains and the need for heightened security measures in development practices.

Impact: Open VSX extensions, GitHub repositories
Remediation: Users should review and remove any suspicious Open VSX extensions and GitHub repositories. Implementing security best practices, such as using verified sources and regularly updating software, is recommended.
Read Original

According to Field Effect's 2026 Cyber Threat Outlook, compromised cloud identities were responsible for over 80% of the incident alerts investigated in 2025. This significant statistic indicates that attackers are increasingly targeting cloud services to gain unauthorized access. The shift in focus toward cloud identity compromises suggests that organizations need to bolster their security measures around these services. Companies that rely heavily on cloud infrastructure should prioritize identity management and implement stronger authentication processes to mitigate risks. This trend emphasizes the critical need for ongoing vigilance in cybersecurity practices as attackers adapt their strategies.

Impact: Cloud identity management systems, cloud service providers
Remediation: Implement stronger authentication measures, enhance identity management protocols, conduct regular security audits
Read Original

Microsoft has released an out-of-band update to address three vulnerabilities in Windows 11's Routing and Remote Access Service (RRAS). The vulnerabilities, identified as CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111, could potentially allow remote code execution when users connect to a malicious server. This is a serious concern as it could enable attackers to execute harmful code on affected systems. Users of Windows 11 should ensure they apply the latest updates to protect their devices from these risks. The prompt release of this patch reflects the urgency in addressing vulnerabilities that can be exploited remotely, highlighting the need for users to stay vigilant about software updates.

Impact: Windows 11, Routing and Remote Access Service (RRAS)
Remediation: Users should apply the latest updates provided by Microsoft to address the vulnerabilities. Specific patch numbers or versions were not mentioned, but keeping Windows 11 updated is essential.
Read Original
FBI Investigates Steam Games Linked to Malware and Crypto Wallet Theft

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

The FBI has issued a warning to gamers about malware embedded in certain Steam games that has been stealing sensitive browser data and draining cryptocurrency wallets. This malicious activity reportedly took place between May 2024 and January 2026, affecting users who downloaded these compromised games. The malware exploits vulnerabilities to access personal information, making it a significant concern for the gaming community, especially as the popularity of cryptocurrencies continues to rise. Gamers are advised to be cautious about the games they download and to monitor their cryptocurrency accounts for any unusual activity. This incident underscores the need for heightened security awareness among gamers.

Impact: Steam games, cryptocurrency wallets
Remediation: Users should avoid downloading games from untrusted sources and regularly check their cryptocurrency wallets for unauthorized transactions.
Read Original
PreviousPage 104 of 216Next