Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The White House has launched a new cybersecurity initiative named Gold Eagle, aimed at addressing the increasing risks posed by AI-driven cyberattacks. This federal hub will serve as a centralized resource for protecting critical infrastructure from these evolving threats. Gold Eagle is expected to streamline information sharing and enhance collaboration among government agencies and private sector partners. As cyber threats become more sophisticated, especially with the integration of artificial intelligence, initiatives like Gold Eagle are essential for bolstering national security. The establishment of this hub reflects a proactive approach to safeguard vital systems and data against potential breaches.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance aimed at improving collaboration between software manufacturers and security researchers. This initiative is designed to help companies better understand how to engage with researchers who identify vulnerabilities in their products. The guidance includes best practices for reporting security issues and highlights the importance of transparency in the process. By fostering a more cooperative relationship, CISA hopes to enhance the overall security of software and online services. This effort is particularly relevant as the frequency of cyber threats continues to increase, making it essential for organizations to address vulnerabilities swiftly and effectively.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The first, CVE-2023-4346, affects the KNX Protocol Connection Authorization Option 1, which has an overly restrictive account lockout mechanism, making it a target for attackers. The second, CVE-2026-46817, involves improper privilege management in Oracle E-Business Suite. These vulnerabilities pose significant risks, particularly to federal agencies, which are required by CISA's Binding Operational Directive 26-04 to prioritize rapid remediation of high-risk vulnerabilities. While this directive specifically applies to federal agencies, CISA encourages all organizations to adopt similar practices. Organizations that identify exploited vulnerabilities not listed in the KEV Catalog can submit them for potential inclusion.

Read Original

Progress has re-enabled access to its ShareFile Storage Zones Controller after a four-day suspension due to a credible external security threat. The company acted quickly to protect user data and ensure the safety of their cloud storage services. While details about the nature of the threat remain limited, the disruption affected users who rely on ShareFile for secure file storage and sharing. This incident underscores the importance of maintaining stringent security measures in cloud services, as even temporary outages can impact business operations. Users are encouraged to stay vigilant and monitor any communications from Progress regarding security updates.

Read Original

The U.S. has charged several Russian individuals and companies for operating cybercrime services that have been linked to various attacks on American entities. These suspects have already faced sanctions from the U.S. and its allies, indicating their longstanding involvement in malicious online activities. The charges reflect an ongoing effort by U.S. authorities to combat cybercrime and hold accountable those who facilitate it. This move is particularly significant as it aims to disrupt the infrastructure that supports cybercriminal activities, which have increasingly targeted businesses and government systems. The implications of these charges may extend to international relations and the ongoing battle against cyber threats.

Read Original

On July 14, researchers from OX Security revealed that several AsyncAPI npm packages were compromised, leading to the injection of malware capable of stealing information, stealing cryptocurrency, and allowing remote access to infected systems. The packages affected include @asyncapi/generator version 3.3.1 and @asyncapi/generator-components version 0.7.1, which collectively have over 2 million downloads each week. This incident poses significant risks to developers and organizations using these packages, as the malicious code could potentially lead to severe data breaches and financial losses. Users of these packages are urged to take immediate action to secure their systems and avoid using the compromised versions. The discovery of this attack underscores the vulnerabilities present in the npm ecosystem and the importance of maintaining vigilance against supply chain attacks.

Read Original

Spanish authorities have dismantled a significant cybercrime network responsible for stealing and laundering around €140 million. The group operated through various fraudulent schemes, including fake investment platforms, CEO fraud, invoice fraud, and man-in-the-middle attacks. Four individuals were arrested during the operation, with two detained in Portugal, one in Spain, and another in Panama. The investigation began when police identified 19 companies engaged in suspicious financial activities that suggested money laundering rather than legitimate business practices. This crackdown highlights ongoing issues with cybercrime and the need for vigilance among businesses and individuals alike.

Read Original

Nudge Security has rolled out new features to help organizations better manage the risks associated with OAuth grants and browser extensions. These two areas are increasingly targeted by attackers and can be challenging for IT teams to monitor. The new capabilities automatically identify and assess the risk of OAuth grants and browser extensions, flagging those that are deemed high-risk. Additionally, the system includes a human-in-the-loop process for remediation, allowing teams to make informed decisions as they respond to potential threats. This enhancement is part of Nudge Security's ongoing efforts to provide tools that improve enterprise security management.

Read Original

The article discusses how traditional methods of inspecting network traffic through cloud proxies are becoming outdated due to the rise of browser-based workflows and AI tools. As companies increasingly rely on SaaS applications and generative AI, the existing security models struggle to keep up with the complex nature of these environments. This shift means that employees may inadvertently expose sensitive information by using unsanctioned browser extensions or by interacting with autonomous agents. The author argues that simply inspecting packets is no longer sufficient to protect intellectual property and sensitive data. Organizations need to adapt their security measures to address these evolving threats and ensure that their data remains secure in this new landscape.

Read Original

Fortinet, Ivanti, and ServiceNow have all issued important patches for various vulnerabilities in their products. A notable issue was found in the ServiceNow AI platform, where a critical security flaw could allow remote attackers to execute arbitrary code. This vulnerability poses a significant risk to users, as it could enable unauthorized access and control over affected systems. Organizations using the ServiceNow platform should act quickly to apply the available updates to protect against potential exploitation. The situation serves as a reminder for companies to regularly update their software to mitigate risks from such vulnerabilities.

Read Original

Kaspersky's GReAT team has identified a new malware framework called OkoBot that specifically targets cryptocurrency users. This sophisticated malware utilizes a component known as TookPS to steal sensitive information, such as seed phrases, and monitor activities on Chromium-based browsers. Additionally, OkoBot can install various types of malware, including the Rilide stealer, which further compromises users' security. This threat is particularly concerning for those involved in cryptocurrency transactions, as it can lead to significant financial losses and privacy violations. Users need to be vigilant and consider enhancing their security measures to protect against these evolving threats.

Read Original

Progress has confirmed that a zero-day vulnerability was behind the recent disruption of its ShareFile service. This issue specifically impacted customers using the Storage Zones Controller, who experienced access problems. To address the situation, Progress has rolled out a fix that these customers can apply to restore functionality. The existence of a zero-day exploit raises concerns about the security of the affected systems, as attackers could have potentially leveraged this vulnerability before it was patched. Users of ShareFile should prioritize applying the fix to mitigate any risks associated with this vulnerability.

Read Original
Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding three vulnerabilities in on-premises SharePoint Server that are currently being exploited by attackers. These flaws affect SharePoint instances that are accessible via the internet, putting organizations at risk of unauthorized access and data breaches. Administrators are urged to take immediate action to protect their systems, as the vulnerabilities allow attackers to execute malicious commands and potentially compromise sensitive information. This situation is particularly concerning for businesses and government agencies that rely on SharePoint for collaboration and document management. Promptly applying available patches is essential to mitigate these risks and safeguard against ongoing exploitation.

Read Original

Siemens, Schneider Electric, and Rockwell Automation have addressed numerous vulnerabilities in their industrial control system (ICS) products. These fixes come as part of the latest ICS Patch Tuesday updates, which also prompted advisories from the Cybersecurity and Infrastructure Security Agency (CISA) and VDE CERT. The vulnerabilities could potentially expose systems to various cyber threats, affecting critical infrastructure and manufacturing sectors. Companies using these ICS products need to ensure they apply the latest patches to mitigate any risks associated with these vulnerabilities. This update is crucial for maintaining the security and integrity of industrial operations.

Read Original

Recent findings reveal that four npm packages associated with the @asyncapi namespace have been compromised to distribute a multi-stage botnet loader. The affected packages include @asyncapi/generator-helpers version 1.1.1, @asyncapi/generator-components version 0.7.1, @asyncapi/generator version 3.3.1, and specific versions of @asyncapi/specs (v6.11.2 and v6.11.2-alpha.1). This incident is significant as it exposes users of these libraries to potential malware infections, which could lead to broader security issues. Developers and organizations utilizing these packages should take immediate action to assess their systems for any unauthorized changes and consider removing the compromised packages until updates are available. This situation underscores the risks associated with open-source package management and the importance of vigilance in software supply chain security.

Read Original
PreviousPage 104 of 369Next