Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The UK government has updated its National Risk Register to include warnings about the potential severity of cyber-attacks. This update indicates a growing concern over the impact that such attacks could have on critical infrastructure and national security. Officials are urging businesses and public sector organizations to bolster their cybersecurity measures in light of these threats. The register serves as a guide for preparedness and response strategies, emphasizing the need for vigilance against increasingly sophisticated cyber threats. This move underscores the importance of being proactive in cybersecurity, as attackers are constantly evolving their tactics.

Read Original

SonicWall has issued a warning about active attacks targeting two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 appliances. These vulnerabilities were identified by Adam Babis from SonicWall's Product Security Incident Response Team (PSIRT) and include a serious flaw that allows for arbitrary command execution. The company has confirmed that these vulnerabilities are being actively exploited in the wild, which poses a significant risk to organizations using these appliances. Users of the SMA 1000 series should be particularly vigilant, as the exploitation could lead to unauthorized access and control over their systems. It's crucial for affected organizations to take immediate action to protect their networks.

Read Original

Nigeria is stepping up its cybersecurity measures by introducing new regulations that require organizations to report cyberattacks. This move aligns the country with other nations that are pushing for greater transparency in the face of rising cybercrime. As attackers increasingly target businesses for financial gain, the government aims to hold companies accountable for their security practices. This initiative is particularly important as it seeks to create a safer digital environment for both businesses and consumers in Nigeria. By mandating disclosure, the hope is to improve the overall response to cyber threats and reduce the impact of future attacks.

Read Original

SingGuard-NSFA is an open-source framework designed to address operational risks in AI workflows. It features four models with varying parameter sizes, all built on the Qwen3.5 backbone. The framework organizes risks according to the CIA triad—confidentiality, integrity, and availability—and identifies 185 risk variants. These variants are grouped into broader categories and validated against OWASP guidelines. This initiative is significant for developers and organizations using AI, as it provides a structured approach to identifying and mitigating potential threats in AI systems.

Read Original

SonicWall has reported that two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances are currently being exploited. One of these vulnerabilities, identified as CVE-2026-15409, has a critical CVSS score of 10.0 and allows remote attackers to execute arbitrary commands through a server-side request forgery (SSRF). This means that attackers can potentially gain unauthorized access to sensitive systems. The exploitation of these vulnerabilities poses a significant risk to organizations using these appliances, as it could lead to severe security breaches. SonicWall's warning emphasizes the urgency for users to address these issues to protect their networks.

Read Original

The ransomware group D1R has claimed responsibility for accessing a database belonging to Synopsys, reportedly containing 40,000 entries. They allege that this information was then used to target Bosch, suggesting that sensitive intellectual property was stolen in the process. Synopsys has denied these claims, which raises questions about the security of their systems and the potential impact on Bosch and other companies. If the claims are true, it could mean serious repercussions for the affected organizations, including financial losses and reputational damage. The situation underscores the ongoing challenges companies face in protecting their data from cybercriminals.

Read Original

Callum Dare, a 26-year-old from Wales, has been sentenced to prison for his involvement in multiple swatting incidents across the UK, US, and Canada. He served as an administrator for Doxbin, a dark web site notorious for doxxing and enabling harassment. Swatting is a dangerous practice where false emergency reports are made to provoke a heavy police response, often resulting in severe consequences for the victims. This case emphasizes the serious legal repercussions of participating in online harassment and swatting schemes, which can endanger lives and waste valuable law enforcement resources. The sentencing serves as a warning to others involved in similar activities that such actions will not go unpunished.

Read Original
Actively Exploited

A new remote access Trojan (RAT) called LabubaRAT has been discovered, which poses a significant risk to users by disguising itself as NVIDIA's container runtime toolkit. The malware uses a file named 'nvidia-sysruntime.exe' to trick users into executing it, potentially leading to unauthorized access to their systems. This tactic of impersonation could mislead individuals and organizations, making it easier for attackers to infiltrate networks. Users of NVIDIA software, especially those involved in containerization or graphics processing, should be particularly cautious. The emergence of LabubaRAT serves as a reminder of the ongoing challenges in cybersecurity and the need for vigilance against such deceptive tactics.

Read Original

The White House has introduced a new initiative called the 'Gold Eagle' clearinghouse, designed to tackle cyber threats associated with artificial intelligence. This clearinghouse is already operational, gathering intelligence on vulnerabilities in AI systems and prioritizing necessary patches to address these security issues. The move aims to enhance cybersecurity measures as AI technologies become more prevalent in various sectors. By streamlining the response to AI-related vulnerabilities, the government hopes to protect critical infrastructure and sensitive data from potential cyberattacks. This initiative is particularly significant as the use of AI continues to grow, increasing the attack surface for cybercriminals.

Read Original

SonicWall has issued a warning about two vulnerabilities in its SMA1000 series, identified as CVE-2026-15409 and CVE-2026-15410. These flaws are being actively exploited by attackers in zero-day attacks, meaning they are being targeted before a fix has been widely implemented. As such, SonicWall is urging all users of the SMA1000 series to apply the newly released security updates to protect against these threats. Failure to patch could leave systems vulnerable to unauthorized access and potential data breaches. Users should prioritize this update to maintain the security of their networks.

Read Original

On July 13, 2026, KFC Japan experienced significant delivery disruptions due to a cyberattack targeting a logistics company that supplies ingredients to its restaurants across the country. The attack affected the systems responsible for transporting food items, leading to delays and shortages at various KFC locations. This incident not only impacts KFC's operations but also raises concerns about the security of third-party vendors that play a critical role in supply chains. As businesses increasingly rely on external partners, this attack underscores the need for stronger cybersecurity measures to protect against similar incidents in the future. The situation is still developing, and KFC has not disclosed further details about the nature of the attack or its consequences.

Read Original

Arizona has launched its second regional Security Operations Center (RSOC) aimed at enhancing cyber defense capabilities. Located at Glendale Community College and Paradise Valley Community College, this center will be operated by students, providing hands-on experience in cybersecurity. The initiative is part of a broader effort to bolster the state's cyber resilience, especially as cyber threats continue to evolve and impact various sectors. By involving students, the program not only helps to prepare the next generation of cybersecurity professionals but also addresses the growing demand for skilled workers in the field. This development comes at a time when many organizations are increasingly vulnerable to cyber attacks.

Read Original

The article discusses the difficulties teams face in reconstructing control-plane activity in cloud environments, even when logging is enabled. Structural issues within organizations often hinder their ability to analyze logs effectively, which can prevent timely responses to security incidents. This lack of visibility into control-plane activities can leave organizations vulnerable to potential threats. As remote work and cloud adoption increase, understanding and addressing these issues becomes crucial for security teams. Ultimately, the ability to analyze control-plane activity is essential for maintaining security and compliance in cloud infrastructures.

Read Original

Spanish authorities have successfully dismantled a significant cyber fraud operation that generated around €140 million (approximately $160 million) through various scams, including investment fraud and business email compromise (BEC) attacks. Four individuals were arrested as part of this operation, which highlights the ongoing battle against sophisticated cybercrime. The group exploited vulnerabilities in online investment platforms, tricking victims into transferring money under false pretenses. This incident serves as a reminder of the growing threats posed by cybercriminals and the importance of vigilance in online transactions. Law enforcement's success in this case may deter future attacks and offers hope for victims seeking justice.

Read Original

Recent research has identified vulnerabilities in Automated Frequency Coordination (AFC) systems used for 6 GHz Wi-Fi networks. These systems typically trust data from client devices without verification, which opens the door for attackers to spoof locations and disrupt network traffic. This could have serious implications for critical systems that rely on these networks for communication and operation. The potential for location spoofing means that malicious actors could interfere with bandwidth allocation and network stability, affecting users and organizations that depend on reliable Wi-Fi. As 6 GHz Wi-Fi becomes more common, addressing these vulnerabilities is crucial to prevent disruptions.

Read Original
PreviousPage 105 of 369Next