Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability, CVE-2008-4128, to its Known Exploited Vulnerabilities Catalog. This vulnerability affects Cisco IOS and is associated with cross-site request forgery, which allows attackers to exploit vulnerable systems. It poses significant risks, particularly for federal agencies, as it can lead to total control over affected assets after exploitation. CISA's Binding Operational Directive 26-04 emphasizes the need for federal agencies to prioritize rapid remediation of such high-risk vulnerabilities. While this directive primarily applies to federal agencies, CISA encourages all organizations to adopt similar practices for managing vulnerabilities effectively. Agencies are also urged to check for any compromises before applying patches to mitigate risks.

Read Original

Progress Software has disabled access to its ShareFile accounts due to a credible external security threat involving the Storage Zone Controllers (SZC). These controllers are the on-premises servers where organizations store files shared through ShareFile. On July 10, the company alerted customers via email, instructing them to manually shut down their servers hosting these controllers. This measure aims to protect users from potential security breaches. Customers using ShareFile should take immediate action to secure their data and prevent unauthorized access.

Read Original

The European Union and the United Kingdom have imposed sanctions on multiple Russian individuals and entities linked to the GRU, Russia's military intelligence agency. These sanctions stem from accusations that these hackers coordinated a series of cyberattacks targeting various sectors across Europe. The EU claims that this network of hacking groups has been responsible for significant disruptions and breaches, impacting both public and private organizations. By taking this action, the EU and UK aim to hold Russia accountable for its cyber operations and deter future attacks. This situation underscores the ongoing tensions between Western nations and Russia regarding cybersecurity and geopolitical stability.

Read Original
Critical
Siggen Backdoor Hits Windows Developers Via Infected Visual Studio Projects

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Researchers from Dr.Web have identified a new backdoor named Siggen that targets Windows developers. This malware spreads through infected Visual Studio projects and utilizes Steam for command and control (C2) operations. Once installed, it can steal sensitive information, including user credentials and cryptocurrency data. The incident poses a significant risk to developers who may unknowingly incorporate these malicious projects into their work, potentially compromising their systems and data. The use of a popular platform like Steam for C2 makes it a notable concern for the developer community and highlights the need for vigilance against such threats.

Read Original

Cybersecurity researchers have identified an intrusion involving an unknown attacker who used a PowerShell script suspected to be AI-generated for mapping Active Directory (AD). The script was designed to locate the Domain Controller, enumerate users, computers, and domains, and create an AD report in HTML format. This type of activity poses significant risks as it can lead to unauthorized access and data breaches within organizations. Companies with Active Directory systems should be vigilant and enhance their security measures to prevent such intrusions. The incident underscores the evolving tactics of cybercriminals who are increasingly utilizing sophisticated tools to exploit vulnerabilities in network environments.

Read Original

Cybersecurity agencies from 12 countries have issued a warning about Russian state-backed hackers who are exploiting weak SNMP (Simple Network Management Protocol) credentials in routers worldwide. This attack targets devices with known vulnerabilities, allowing the hackers to potentially gain control over network infrastructure. The issue is particularly concerning as routers are critical components in both corporate and home networks, meaning that a successful attack could lead to data breaches or further exploitation. Organizations are urged to review their router security settings and strengthen SNMP credentials to reduce the risk of being compromised. This situation not only highlights the ongoing cyber threats posed by state-sponsored actors but also serves as a reminder for users to prioritize their network security.

Read Original

Zimbra has patched a serious vulnerability that allows attackers to execute malicious code through specially crafted emails. When a user opens one of these emails, the embedded code runs without their consent, posing a significant security risk. This flaw affects users of Zimbra's email software, which is widely used by organizations for communication. The potential for exploitation makes it crucial for users to update their systems promptly. Patching this vulnerability helps protect against unauthorized access and data breaches, which could have serious consequences for affected organizations.

Read Original

The European Union has taken action against several Russian intelligence officers believed to be involved in a long-term cyber espionage campaign. This campaign allegedly targeted various government entities and conducted sabotage operations aimed at critical infrastructure across the EU. The EU's decision to target these individuals and related entities is part of a broader strategy to counteract cyber threats originating from Russia. This incident underscores the ongoing tensions between Russia and the EU, particularly in the realm of cybersecurity, and highlights the risks posed by state-sponsored cyber activities. The ramifications of such actions could lead to increased cybersecurity measures and diplomatic responses from affected nations.

Read Original
Actively Exploited

Cybersecurity agencies from the United States and eight allied nations have issued a warning about Russian state-sponsored hackers targeting vulnerable routers to gain access to critical infrastructure networks. These hackers are exploiting poorly configured devices, which could lead to significant disruptions if successful. The warning emphasizes the need for organizations to enhance their cybersecurity measures and ensure their network devices are properly secured. This attack method poses a serious risk to essential services and could potentially impact public safety. Agencies are urging businesses and government entities to remain vigilant and take proactive steps to protect their systems.

Read Original

An Armenian man has admitted his involvement in the Ryuk ransomware scheme, which has been responsible for numerous high-profile cyberattacks. Ryuk ransomware typically targets large organizations and demands hefty ransoms to restore access to encrypted data. The man was extradited from Ukraine to the United States to face charges, marking a significant step in holding perpetrators of ransomware attacks accountable. This case not only highlights the ongoing threat posed by ransomware but also underscores international cooperation in tackling cybercrime. As these types of attacks continue to disrupt businesses and public services, this guilty plea serves as a reminder of the need for robust cybersecurity measures across all sectors.

Read Original

Dutch police are investigating a cyberattack on telecom provider Odido that occurred in February 2026, which led to the theft of data belonging to over six million customers. Authorities believe that local hackers, possibly Dutch nationals, were behind the phishing attack that initiated the breach. The police are currently seeking public assistance to identify these suspects. This incident raises serious concerns about the security of customer data in the telecommunications sector and highlights the ongoing risks posed by phishing schemes. As the investigation unfolds, affected customers should be vigilant about potential misuse of their personal information.

Read Original

Attackers are exploiting vulnerabilities in two Joomla extensions: Balbooa Forms and iCagenda. These flaws allow for remote code execution, meaning that hackers can run malicious code on affected systems without authorization. Organizations using these extensions are at risk, and the situation is particularly urgent as these vulnerabilities are being actively targeted. Website administrators need to be vigilant to protect their sites from potential breaches. It's crucial for users of these extensions to apply any available patches and review security measures to safeguard their data.

Read Original

The article discusses the growing challenge of managing security risks associated with AI-generated code. As companies increasingly adopt AI tools for software development, the speed and volume of code produced can outpace traditional security measures. This situation has led to what experts are calling 'security debt,' where vulnerabilities accumulate without adequate oversight. Chief Information Security Officers (CISOs) are urged to move beyond merely approving tools and instead implement robust governance frameworks to manage these risks effectively. The implications are significant, as a lack of governance can leave organizations vulnerable to cyberattacks and compliance issues.

Read Original
Actively Exploited

The Australian Cyber Security Centre (ACSC) has issued a warning about a global campaign targeting Content Management Systems (CMS). This campaign involves mass scanning and attempts to exploit vulnerabilities in popular CMS platforms. Users of these systems are urged to take immediate precautions, as attackers are actively seeking to compromise websites and web applications. The ACSC's alert emphasizes the need for CMS users to ensure their software is up to date and to implement strong security measures to defend against potential breaches. The situation is concerning as it could lead to widespread website compromises if users do not act swiftly.

Read Original

Progress has alerted its customers about a credible security threat concerning the ShareFile Storage Zone Controller. As a precaution, the company is advising users to manually shut down their servers while they investigate the situation. This move is intended to protect sensitive data and prevent any potential breaches. The security concerns arise from unknown vulnerabilities that could affect data integrity and confidentiality. Users of the ShareFile service need to take this warning seriously to safeguard their information until the company provides further updates.

Read Original
PreviousPage 111 of 370Next