Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A recent survey by SANS shows that the use of generative AI in cybersecurity has surged, with 78% of professionals incorporating it into their work by 2026, up from 50% the previous year. Despite this rapid adoption, many practitioners report issues with AI's reliability in detecting and responding to threats, with 63% noting significant shortcomings. This raises concerns about over-reliance on AI tools for cybersecurity tasks. Experts emphasize the value of human skepticism in assessing AI outputs, suggesting that a cautious approach is essential in preventing potential AI-driven attacks. As AI becomes more integrated into security strategies, balancing technology with human oversight will be crucial for effective defense.

Read Original

Researchers from Leipzig University and ipoque have developed a method to create fake smart home residents to aid in security research. Real-world data on how people interact with smart home devices is difficult to obtain due to the invasive nature of the research, which typically requires extensive monitoring in private homes. By simulating user behavior, the researchers aim to generate more comprehensive datasets without the need for prolonged surveillance of actual households. This approach could improve the understanding of security vulnerabilities in smart home technology, which is increasingly prevalent in everyday life. The outcome may lead to better security measures and protections for users of these devices.

Read Original

In a recent discussion, Chris Boehm from Zero Networks emphasized the risks associated with vendor relationships in cybersecurity. He pointed out that attackers are increasingly targeting the subcontractors of trusted vendors, which can lead to significant breaches. When a vendor's vendor is compromised, attackers can gain access to your systems using stolen credentials from these lesser-known companies. This situation highlights the need for organizations to vet not only their direct suppliers but also their supply chain partners. The implications are serious, as a breach could allow unauthorized access to sensitive data without the primary vendor even being aware of the risk. Companies should reassess their security protocols to include these indirect relationships to better protect their systems.

Read Original

Security researchers at Varonis have found vulnerabilities in Google Cloud's Dialogflow CX, a platform widely used for creating chatbots. These flaws could allow attackers to hijack AI agents, potentially leading to unauthorized access and misuse of chatbot functionalities. Organizations using Dialogflow CX should be particularly vigilant, as this could impact customer interactions and data security. The discovery raises concerns about the security of AI-driven applications and the need for more stringent safeguards in cloud-based platforms. Users are encouraged to review their configurations and stay updated on any fixes released by Google.

Read Original

In December 2025, an attack on Poland's power grid was attributed to Russia's FSB by both UK and EU authorities. The primary goal of the assault was to disrupt communication between renewable energy systems and power distribution operators, raising concerns about the security of critical infrastructure in the region. This incident is particularly alarming as it underscores the potential for state-sponsored cyber activities to impact essential services. The attack could have wide-reaching implications for energy security and stability in Poland and possibly beyond, as it highlights vulnerabilities in the infrastructure that supports renewable energy. Authorities are urging immediate action to bolster defenses against such cyber threats.

Read Original

The Los Angeles Police Department (LAPD) has terminated its contract with Flock Safety, a company that provides automated license plate recognition technology. This decision reflects growing concerns regarding privacy and the potential misuse of the data collected by Flock, particularly by federal agencies. The LAPD's move is part of a broader trend, as other cities like Mountain View, California, and South Portland, Maine have also ended similar contracts for the same reasons. These actions signal increasing scrutiny over surveillance technologies and their implications for civil liberties, raising questions about how law enforcement agencies balance security needs with privacy rights. The situation illustrates the ongoing debate surrounding the use of surveillance technology in policing and the need for clear regulations to protect citizens' data.

Read Original

The Argentine Football Association (AFA) experienced a security breach that was traced back to an infostealer infection nearly a year old. The incident came to light when mass emails were sent from AFA's legitimate domains, falsely accusing Egypt of having 'stolen' a win. This indicates that attackers may have gained control over AFA's email systems, potentially compromising sensitive information. The breach raises concerns about the security of sports organizations and the integrity of communications within such entities. It also highlights the ongoing risks posed by malware that can linger undetected for extended periods, allowing attackers to exploit the situation at will.

Read Original

The UK and EU have taken a significant step by jointly imposing sanctions on Russian individuals and entities involved in cyberattacks and disinformation campaigns targeting the region. This move marks the first time these two entities have collaborated on sanctions specifically related to cybersecurity threats. The sanctions aim to hold accountable those responsible for undermining democratic processes and destabilizing security through malicious online activities. The actions reflect growing international concern about the impact of Russian cyber operations on global stability, especially in the wake of ongoing geopolitical tensions. By targeting these cyber actors, the UK and EU hope to deter further attacks and protect their infrastructure and citizens from future threats.

Read Original

As federal support for election security diminishes, states are taking matters into their own hands by establishing their own election defense networks. Election officials are caught in a difficult position, facing pressure to comply with federal guidelines that they do not fully trust, while also worrying about potential criminal investigations. This situation raises concerns about the integrity of the electoral process and the security of voting systems. By creating localized networks, states aim to bolster their defenses against potential cyber threats, ensuring that elections can proceed without undue interference. This shift underscores a growing distrust in federal oversight and a move towards state-level autonomy in managing election security.

Read Original

Nihon Kotsu, Japan's largest taxi operator, has shut down parts of its systems following a cyberattack that compromised its infrastructure. The attack forced the company to suspend operations for some of its taxi services, impacting daily commuters and travelers relying on its fleet. While the specifics of the attack remain unclear, the incident raises concerns about the security of transportation networks in a country increasingly reliant on digital systems. As the company works to restore services, the event serves as a reminder for businesses to prioritize cybersecurity measures to protect against similar threats in the future.

Read Original

A malicious version of the Jscrambler npm package has been discovered, which includes infostealer malware. This compromised package has been downloaded nearly 1,500 times by users, potentially exposing their systems to security risks. Jscrambler, a company that specializes in client-side web security, reported the incident, highlighting the importance of scrutinizing third-party packages before installation. The malware is designed to steal sensitive information, which could lead to further security breaches for those affected. Users and developers should be cautious and ensure they are using legitimate versions of software packages to avoid falling victim to such attacks.

Read Original

Lidl has informed its online shop customers in Germany, Belgium, and the Netherlands about a data breach that involved the theft of personal data. This incident occurred due to a compromise of an external IT service provider, although payment information was not affected. The company reached out to customers last week to notify them of the breach and the potential risks associated with their stolen information. Customers should remain vigilant for any suspicious activity related to their personal data, as it could be used for identity theft or phishing attempts. This breach highlights the vulnerabilities associated with third-party service providers and the importance of robust security measures.

Read Original

Some companies are forming 'yellow teams' that combine software engineers and cybersecurity experts to explore the dual nature of artificial intelligence in security. These teams are tasked with developing both defense mechanisms against AI-driven attacks and offensive tools to test the effectiveness of AI in cybersecurity. The goal is to understand how AI can be used to enhance security measures while also recognizing its potential as a threat. This proactive approach could help organizations better prepare for future cyber threats that leverage AI technology. As AI continues to evolve, the collaboration between these teams may become essential for maintaining robust cybersecurity practices.

Read Original

Researchers have identified a new malware targeting macOS systems called CrashStealer, designed to steal sensitive information from compromised devices. What sets CrashStealer apart from other malware is its use of native C++ for implementation, rather than the more common AppleScript or Objective-C methods. This malware can validate the victim's login password locally, making it harder to detect. The use of a notarized dropper allows it to bypass Apple's Gatekeeper security checks, increasing its chances of successfully infecting systems. Users of macOS should be cautious and ensure their devices are protected against such threats, as this malware can lead to significant data breaches.

Read Original

GigaWiper is a newly discovered modular malware that enables attackers to carry out both backdoor and wiper functions, allowing them to choose how destructive their attacks can be. This malware draws elements from various existing malware families, making it more versatile and dangerous. While specific targets have not been disclosed, the presence of such a tool poses a significant threat to organizations, as it can lead to data loss and operational disruptions. The ability to customize the attack increases the potential impact on victims, making it critical for companies to stay vigilant and enhance their cybersecurity measures. Understanding how GigaWiper operates can help in developing better defenses against such dual-purpose malware.

Read Original
PreviousPage 109 of 370Next