The U.S. has charged 17 individuals linked to the Mabna Institute, an Iranian hacking group, for allegedly stealing a staggering 31 terabytes of data over several years. This data breach primarily targeted American universities, private companies, and government agencies. The stolen information included sensitive academic research and personal data, raising concerns about the security of educational institutions and their ability to protect valuable intellectual property. The charges point to a larger issue of state-sponsored cyber espionage, illustrating the ongoing risks posed by hacking-for-hire operations. This incident not only affects the institutions involved but also highlights vulnerabilities in cybersecurity practices across the academic and governmental sectors.
Check Point Research has discovered a cybercrime operation called StopAndProtect that has compromised nearly 2,000 hacked WordPress websites. These sites have been repurposed into a network for delivering malware, stealing data, conducting surveillance, and facilitating ransomware attacks. This operation underscores the risks associated with insecure websites, as attackers can exploit vulnerabilities to turn legitimate platforms into tools for cybercrime. Website administrators must be vigilant in securing their WordPress installations to prevent such takeovers. This incident serves as a stark reminder of the ongoing challenges in maintaining website security and the potential consequences of neglecting it.
Recent warnings from the NSA and CISA indicate that hackers are using artificial intelligence to target Siemens programmable logic controllers (PLCs) in critical sectors across the United States. These PLCs are essential for managing industrial processes, making them attractive targets for cybercriminals. The advisory includes technical details and recommendations aimed at helping organizations protect their systems from potential attacks. This situation is particularly concerning given the vital role these systems play in infrastructure like power plants and manufacturing facilities. Companies that rely on Siemens PLCs should remain vigilant and implement the suggested protective measures to mitigate risks.
Researchers have identified a serious vulnerability in the Elementor Pro plugin for WordPress, designated as CVE-2026-32475. This flaw, which has a CVSS score of 9.0, allows unauthenticated attackers to upload malicious PHP files and execute code on affected sites. The issue is found within the Forms module's file upload functionality, posing a significant risk to WordPress installations using this plugin. If exploited, this could lead to unauthorized access and control over websites, making it crucial for users and site administrators to address the issue promptly. As the vulnerability is particularly dangerous, it is essential for those using Elementor Pro to take immediate action to secure their sites.
Online fraud is evolving, making it increasingly difficult for consumers and businesses to detect scams. According to Experian’s 2026 U.S. Identity & Fraud Report, fraud now encompasses a wide range of digital channels, including messages, websites, and account activities. As fraud tactics become more sophisticated, traditional security measures may not be enough to protect users. This shift poses significant risks to individuals and organizations, as it complicates the verification of identities and the detection of fraudulent activities. The report emphasizes the need for improved security practices to keep pace with these developments in fraud techniques.
Researchers at the University of Massachusetts Amherst have discovered a security flaw they call the 'Zombie Card attack,' which allows expired contactless credit cards to remain functional for unauthorized payments. Even after cardholders receive a replacement card, the old card can still be used, raising concerns about how expired cards are managed. The study emphasizes that many users do not follow issuer instructions to destroy expired cards, leading to potential misuse. This loophole poses a risk to both consumers and financial institutions, as it can facilitate fraud without the cardholder's knowledge. The findings were presented at the USENIX Security 2026 conference, prompting a call for better security practices around expired payment methods.
According to Rapid7's latest report, the number of high- and critical-severity vulnerabilities has surged to 8,539 in the second quarter of 2026, doubling from the previous year. This sharp increase poses a significant challenge for organizations trying to prioritize which vulnerabilities to address first. The speed at which exploit code can be developed and tested means that the window for mitigating these risks is shrinking. As companies face a growing list of security flaws, they need to rethink their patching strategies to effectively manage and respond to these vulnerabilities. Failing to do so could leave systems exposed to potential attacks.
The article discusses the proposal in Congress for an AI 'kill switch' to halt the operation of artificial intelligence systems in case of emergencies. However, the author argues that this approach may not be practical unless it addresses the underlying issue of identity-based access control. The concern is that simply having a kill switch won’t prevent misuse of AI or address security vulnerabilities. Instead, the focus should be on ensuring that only authorized users can access and control these powerful systems. This issue is particularly relevant as AI technology becomes more integrated into various sectors, raising questions about safety and accountability.
OpenAI's ChatGPT is currently facing a significant outage, affecting users' ability to log in, create new accounts, and access existing chats. This disruption has left many users stranded, unable to retrieve their previous conversations or utilize the service as intended. The exact cause of the outage has not been disclosed, but it raises concerns about service reliability and user data access. As ChatGPT is widely used for various applications, including education and customer support, this downtime could impact a large number of users and businesses relying on its functionality. OpenAI has acknowledged the issue and is likely working to resolve it quickly to restore normal operations.
Sakura Internet, a Japanese cloud and data center service provider, recently announced a security breach affecting up to 1.36 million customer accounts. Hackers gained unauthorized access to the company's sales management system, which contains sensitive customer contract and membership details. This incident raises concerns about the security of customer data and the potential for identity theft. Affected customers may need to monitor their accounts for unusual activity and consider changing their passwords. The breach highlights the ongoing vulnerability of cloud service providers to cyberattacks and the importance of robust security measures to protect user information.
The AI platform known as 'Kriminal' is stirring up concerns in the cybersecurity community due to its lack of restrictions on the use of its tools for potentially malicious purposes. While the company claims to prohibit illegal activities, it offers features that facilitate social engineering, offensive cybercrime, and open-source intelligence (OSINT) scanning. This means that anyone with cryptocurrency can access these capabilities, raising alarms about how easily they could be used for cybercriminal activities. The situation poses a significant risk, as it could empower bad actors to conduct cyberattacks more effectively. Experts are urging the cybersecurity community to monitor this platform closely to understand its implications for online safety and security.
CareCloud, a U.S. healthcare IT company, has revealed that a data breach earlier this year has affected over 3.7 million patients. This incident raises significant concerns about the security of sensitive health information, as attackers may have accessed personal details including names, addresses, and health records. The exposure of such data can lead to identity theft and other malicious activities, putting patients at risk. CareCloud is currently working to inform the impacted individuals and strengthen their security measures to prevent future breaches. The scale of this incident underscores the ongoing vulnerability of healthcare systems to cyberattacks, making it crucial for organizations to prioritize data protection and implement robust security protocols.
Katie Moussouris from Luta Security spoke with Dark Reading about a new insider threat model that organizations need to consider following a recent attack on Hugging Face. This incident has raised awareness about the potential risks posed by internal agents, such as employees or contractors, who may misuse their access to sensitive information. Moussouris emphasizes that companies must implement stronger monitoring and detection strategies to identify and mitigate these insider threats effectively. The discussion highlights a shift in focus for cybersecurity teams, who now need to account for risks not just from external attackers but also from trusted insiders. This change is crucial as organizations increasingly rely on AI and machine learning technologies, which can be exploited by those with inside knowledge.
Researchers have reported a remote Spectre attack targeting Cloudflare Workers, which led to the leakage of a JSON Web Token (JWT) from a co-located Worker. This attack was conducted at a rate of up to 12 bits per second, significantly faster than a similar attack demonstrated in 2021. In this experiment, the researchers controlled both the attacker and victim Workers within the production environment. This incident raises concerns for developers and businesses using Cloudflare's services, as it illustrates the potential vulnerabilities in shared environments where multiple Workers operate in close proximity. Understanding and addressing these vulnerabilities is crucial for maintaining the security of sensitive data handled by these applications.
U.S. agencies have issued a warning about an emerging threat from hackers using artificial intelligence to target water systems and other critical sectors. The focus of these attacks appears to be on Siemens S7 Series programmable logic controllers, which are commonly used in industrial settings. This could mark a significant shift in the tactics employed by cybercriminals, as they incorporate AI to enhance their attack strategies. The implications are serious, as these systems control essential services like water supply, making them attractive targets for malicious actors. Organizations in the affected sectors need to bolster their defenses to protect against these sophisticated threats.