Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

On July 13, the U.S. Treasury's Office of Foreign Assets Control sanctioned a VPN provider named 1VPNS and a cryptor seller for their roles in facilitating ransomware attacks that have inflicted billions of dollars in losses on critical infrastructure. These sanctions target two individuals and the company for supplying essential tools and infrastructure to various ransomware groups. The actions aim to disrupt the operations of these gangs that have been wreaking havoc on businesses and institutions across the U.S. by demanding hefty ransoms. This move underscores the government's ongoing efforts to combat cybercrime and protect essential services from further exploitation. By cutting off the resources that enable these cybercriminals, authorities hope to reduce their operational capabilities significantly.

Read Original
Actively Exploited

A threat actor has created nearly 300 fake GitHub repositories that mimic legitimate software and security projects to spread infostealer malware. This malware is designed to steal sensitive information from users who mistakenly download these malicious programs, thinking they are legitimate. Researchers discovered that these counterfeit repositories could easily deceive unsuspecting developers and users, leading to potential data breaches. The incident raises concerns about the security of open-source platforms like GitHub, where users often rely on repository authenticity to download software safely. Users and organizations need to be vigilant and verify the legitimacy of software before downloading to avoid falling victim to these types of attacks.

Read Original

The D1R cybercrime group has claimed responsibility for stealing sensitive data from both Synopsys and Bosch, threatening to release the information unless a ransom is paid. However, Synopsys has conducted an investigation and found no evidence that any data breach occurred on their end. This situation raises concerns about the potential for misinformation and the tactics used by cybercriminals to instill fear and pressure companies into paying ransoms. It also highlights the need for organizations to remain vigilant and prepared for such threats, even when claims do not hold up under scrutiny. The implications of these threats can be significant, particularly for companies that handle sensitive data, as they can affect reputation and trust among customers.

Read Original

SAP has issued critical updates in July 2026 to fix several vulnerabilities, including a serious flaw in the SAP NetWeaver Application Server ABAP, identified as CVE-2026-44747. This vulnerability has a CVSS score of 9.9 and involves an out-of-bounds write issue that could allow an authenticated attacker to exploit memory management errors. If successfully executed, this could lead to memory corruption, potentially enabling attackers to expose or modify sensitive data. Organizations using the affected SAP NetWeaver Application Server should prioritize these updates to protect their systems from possible exploitation. Timely patching is crucial to maintaining the integrity and confidentiality of their data.

Read Original

SonicWall has identified two vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances, known as CVE-2026-15409 and CVE-2026-15410, which are currently being exploited by attackers. The company is urging its customers to upgrade to a fixed firmware version immediately and to check for signs of compromise on their systems. If any indicators of compromise are found, SonicWall recommends that organizations re-image their hardware or redeploy their virtual appliances, change all user and administrator passwords, and reset any Time-based One-Time Password (TOTP) tokens. This situation raises concerns for organizations relying on these appliances for secure remote access, as attackers could exploit these vulnerabilities to gain unauthorized access to sensitive information. Swift action is essential to mitigate potential risks.

Read Original
Critical
Upwind Finds Coordinated Supply Chain Campaign Compromising Multiple AsyncAPI npm Packages

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Researchers at Upwind have identified a coordinated supply chain attack that has compromised multiple AsyncAPI npm packages. This attack affects various repositories, publishing pipelines, and developer systems, putting many developers at risk. The compromised packages could potentially allow attackers to inject malicious code into applications that rely on these libraries, posing a significant threat to the integrity of software projects. Developers using these AsyncAPI packages should be vigilant and assess their systems for any signs of compromise. This incident serves as a reminder of the vulnerabilities within software supply chains and the need for enhanced security measures.

Read Original

Adobe has released patches to address serious vulnerabilities in ColdFusion that could allow attackers to run arbitrary code or gain elevated privileges. These flaws pose a significant risk to users and organizations that rely on ColdFusion for web applications. If exploited, they could lead to unauthorized access and potential data breaches. It’s crucial for affected users to apply these updates as soon as possible to protect their systems from potential attacks. Adobe's quick response highlights the ongoing need for vigilance in maintaining software security.

Read Original
Critical
Tego AI Finds Claude Tag Slack Integration Can Trigger Unauthorized Enterprise Actions

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Researchers at Tego AI discovered a significant security issue with the Claude Tag integration for Slack, which could allow unauthorized actions within enterprise environments. The integration, designed to enhance productivity, has vulnerabilities that could let attackers execute actions without proper authorization, potentially compromising sensitive company operations. This flaw raises concerns for businesses using this tool, as it could lead to data breaches or manipulation of enterprise systems. Companies need to assess their use of the Claude Tag integration and take immediate steps to secure their Slack environments. The issue highlights the risks associated with integrating AI tools into workplace applications.

Read Original

Progress Software has confirmed that a serious zero-day vulnerability led to the emergency shutdown of ShareFile Storage Zone Controllers last week. Users of ShareFile, a cloud-based file sharing and storage service, were affected as the company worked to address the flaw. Progress has since released security updates to patch this vulnerability, which could have potentially allowed unauthorized access or data breaches. This incident is significant because it underscores the risks associated with cloud storage services, highlighting the need for users to ensure their systems are updated promptly to protect sensitive data.

Read Original

The article discusses the increasing autonomy of advanced artificial intelligence models, which are now operating with less human oversight. This shift has raised concerns among some state governments, prompting them to consider legislation aimed at ensuring transparency in the deployment and use of these AI systems. The lack of clear guidelines and oversight can potentially lead to significant risks, including misuse or unintended consequences of AI technologies. As AI continues to evolve, it's crucial for regulators to establish rules that can keep pace with these advancements, ensuring that safety and ethical considerations are prioritized. This situation highlights the need for ongoing dialogue and collaboration between technologists, policymakers, and the public to navigate the complexities of AI deployment.

Read Original

A new attack method is being rented out on a large scale, posing challenges for cybersecurity defenses. This particular technique manages to bypass traditional antivirus (AV) and endpoint detection and response (EDR) solutions, making it difficult for organizations to detect. Researchers suggest that the most effective way to identify this threat is through YARA analysis. This situation raises concerns for companies relying on standard security measures, as it indicates a shift in how attackers are approaching their targets. Organizations should consider updating their detection strategies to include YARA rules to improve their defenses against this emerging threat.

Read Original

The article discusses a method called TTP chaining, which helps organizations assess their vulnerability to cyber attacks without the need to run potentially harmful exploits. Many organizations are unable to test their systems directly due to the risk involved, especially if the systems are critical. By validating the attack techniques that an exploit relies on, companies can better understand their security posture and determine the potential for exploitation. This approach allows for a safer evaluation of vulnerabilities, which is particularly important for organizations that cannot afford downtime or disruptions. It emphasizes the need for proactive security measures in a landscape where threats are constantly evolving.

Read Original

VMware has patched seven serious vulnerabilities in its Avi Load Balancer that could allow attackers to bypass authentication, execute remote code, escalate privileges, and traverse directories. These vulnerabilities pose a significant risk to organizations relying on this load balancing technology, as they could lead to unauthorized access and control over systems. Users of VMware Avi Load Balancer should prioritize applying the latest patches to safeguard their environments. The severity of these vulnerabilities highlights the ongoing need for vigilance in cybersecurity practices, especially for widely used infrastructure components.

Read Original

Researchers have identified two significant access control vulnerabilities in the RabbitMQ message broker service. These flaws could allow attackers to access confidential OAuth client secrets and potentially take over enterprise messaging systems. Additionally, the vulnerabilities may enable attackers to bypass tenant boundaries, which is a serious concern for organizations using RabbitMQ in multi-tenant environments. The security team at Miggo discovered and reported these issues, emphasizing the need for companies to address them promptly to protect their messaging infrastructure. This situation is particularly urgent as leaked OAuth secrets can lead to further compromises within affected systems.

Read Original

Researchers have identified a serious vulnerability in Cursor, a widely used AI coding platform. This flaw allows attackers to execute malicious code automatically when users interact with compromised repositories. The issue was reported back in December, but it has not yet been resolved, putting users at risk of falling victim to poisoned repository attacks. This is particularly concerning for developers who rely on Cursor for coding tasks, as the vulnerability could lead to unauthorized access or data breaches. Users should be cautious when using Cursor until a fix is implemented to mitigate this risk.

Read Original
PreviousPage 106 of 369Next