Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Zimbra has issued a warning regarding a serious vulnerability in its Classic Web Client that could allow attackers to execute malicious code through specially crafted emails. This vulnerability falls under the category of stored cross-site scripting (XSS) and poses a significant risk as it could enable unauthorized actions within a user's session. While the flaw has not yet been assigned a CVE identifier, Zimbra is urging all customers to implement the necessary updates to mitigate this risk. The potential for arbitrary code execution raises alarms about data security and user safety, making it crucial for affected users to take prompt action. Companies that rely on Zimbra for email services should prioritize applying the updates to protect their systems from potential exploitation.

Read Original

Matt Burch, a principal security researcher at Atredis Partners, has discovered nine vulnerabilities in the CryptoPro Secure Disk software, which is used in ATM security. These vulnerabilities could potentially allow attackers to bypass security measures and gain unauthorized access to sensitive data stored on ATMs. Burch is set to present his findings at the upcoming Black Hat USA 2026 conference, emphasizing the need for financial institutions to address these weaknesses promptly. The implications are significant as they could affect the integrity of ATM transactions and the security of customer information. As vulnerabilities in ATM systems can lead to financial losses and breaches of personal data, it is crucial for vendors and banks to take immediate action to mitigate these risks.

Read Original
Actively Exploited

A recent report by QiAnXin, a Chinese cybersecurity firm, reveals that the Silver Fox group is using a new Remote Access Trojan (RAT) called MODBEACON, which is developed in Rust. Although their methods, such as SEO poisoning and fake software installers, may seem basic, the group's operation is more intricate, involving several distributors. This complexity raises concerns about the potential reach and effectiveness of their attacks. Organizations and users need to be vigilant about the software they download and the links they click to avoid falling victim to these tactics. The emergence of this Rust-based RAT signifies a shift in how attackers are developing malware, possibly making it harder to detect and mitigate.

Read Original

The NHS has launched a new awareness campaign aimed at preventing unauthorized access to patient data. This initiative comes in response to growing concerns about the security of sensitive health information. Healthcare staff are being reminded that unauthorized access to patient records can lead to severe consequences, including potential jail time. The NHS is updating its guidance for organizations to help monitor and report any breaches more effectively. This move is crucial as it seeks to protect patient privacy and maintain trust in the healthcare system.

Read Original

A staff member at a Scottish NHS Trust mistakenly emailed a spreadsheet containing sensitive patient data from the maternity system to their personal email address. This incident raises serious concerns about data handling and privacy within healthcare organizations. Affected individuals include patients whose information was included in the spreadsheet, potentially exposing them to risks such as identity theft or misuse of their personal information. The situation emphasizes the need for strict data management policies and training for staff on the importance of safeguarding patient data. As healthcare entities continue to digitize records, ensuring robust data protection measures is more crucial than ever.

Read Original

A Bulgarian inmate, already serving a long prison sentence for laundering money from American fraud victims, has been charged with stealing $290,000 in cryptocurrency that had been seized by the government. The theft reportedly occurred while the individual was incarcerated, raising questions about security measures surrounding seized digital assets. This incident highlights vulnerabilities in the management of confiscated cryptocurrencies, which are becoming increasingly common in law enforcement. The case serves as a reminder of the challenges authorities face in safeguarding digital currencies from theft, even within prison systems. It underscores the need for stronger protocols to prevent such incidents in the future.

Read Original

Zimbra has identified a serious cross-site scripting (XSS) vulnerability in the Classic Web Client of its Collaboration suite, which is widely used by various organizations, including businesses and government entities. The flaw currently does not have a Common Vulnerabilities and Exposures (CVE) ID, making it crucial for users to take immediate action to protect their systems. This vulnerability could allow attackers to execute scripts in the context of a user's browser, potentially leading to data theft or other malicious activity. Organizations relying on Zimbra should prioritize patching this vulnerability to safeguard their information and maintain the integrity of their communications. Without a fix, they remain at risk of exploitation.

Read Original

On February 7, 2023, a data breach at Odido compromised the personal information of 6.2 million customers. The breach was made public on February 12, and Dutch police are currently investigating the incident, with suspicions pointing towards local hackers. This breach raises concerns about the security of personal data, especially given the scale of the impact. Affected customers may face risks such as identity theft and fraud. The investigation is ongoing, and it remains crucial for users to monitor their accounts and be aware of potential phishing attempts in the aftermath.

Read Original

Progress Software has issued a warning to users of ShareFile who are using Storage Zone Controllers, which enable on-premises file hosting in conjunction with ShareFile's cloud platform. The company has advised these customers to shut down their servers immediately due to a potential external security threat. This alert affects organizations relying on these specific setups for file management and storage, raising concerns about the safety of their data. The urgency of the warning highlights the need for users to take prompt action to protect their systems from possible breaches. Companies should ensure they follow Progress Software's guidance to mitigate risks associated with this security threat.

Read Original

A long-standing vulnerability in the Squid proxy server, known as 'Squidbleed,' has been identified, which can potentially leak sensitive HTTP requests. This bug has been present for 29 years, raising concerns about the security of systems still using affected versions of the Squid software. Administrators of web servers and proxies that rely on Squid need to take immediate action to mitigate any risks associated with this vulnerability. Researchers have flagged the issue as significant, given the age of the flaw and its potential impact on data security. Users of Squid should verify their software versions and apply necessary updates to protect against possible exploitation.

Read Original

Zimbra has issued a warning regarding a serious stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which is commonly used for accessing Zimbra Collaboration. This flaw allows attackers to execute malicious code when users open compromised emails. The company has released version 10.1.19 to address this vulnerability, which currently does not have a CVE ID. Users of the Classic Web Client should update to this latest version as soon as possible to safeguard their mailboxes from potential exploitation. This incident emphasizes the need for prompt software updates to protect sensitive information from cyber threats.

Read Original

In May, a significant leak of credentials prompted the Cybersecurity and Infrastructure Security Agency (CISA) to take action. A forensic report released by CISA outlines their plans to enhance protections for sensitive materials and improve the process for researchers to report vulnerabilities within the agency. This incident highlights the need for stronger security measures, especially within government agencies that handle critical infrastructure data. The leak raises concerns about the potential misuse of exposed credentials, which could lead to unauthorized access and other security risks. CISA's proactive steps are essential to prevent similar incidents in the future and to maintain public trust in their operations.

Read Original

Injective Labs' GitHub repository was compromised by unknown attackers who uploaded a malicious package to the npm registry. This malicious version, identified as @injectivelabs/sdk-ts@1.20.21, was designed to steal private keys and mnemonic seed phrases from cryptocurrency wallets. The attackers disguised the harmful code as telemetry functionality, tricking users into believing it was legitimate. This incident poses a significant risk to users of the Injective Labs SDK, as their sensitive information could be at risk of theft. Cryptocurrency users should be cautious and verify the integrity of packages before installation, especially those that seem to come from compromised sources.

Read Original

Cyberattacks on healthcare businesses are on the rise, with a significant increase in attacks targeting service providers. While hospitals and clinics saw a modest growth in cyber incidents during the first half of 2026, the number of attacks on healthcare-related businesses more than doubled. This surge in attacks poses a serious threat to patient data and the overall healthcare infrastructure, making it essential for these organizations to bolster their cybersecurity measures. The rising trend indicates that cybercriminals are increasingly focused on exploiting vulnerabilities in the healthcare sector, which could have dire consequences for patient safety and privacy. As attackers become more aggressive, healthcare providers must remain vigilant and proactive in their defenses.

Read Original

The Dutch National Police have indicated that they suspect local hackers were involved in a breach at Odido, a telecommunications provider, which occurred in February. While the police have not disclosed specific details about the hackers' identities or methods, they noted that the evidence suggests a domestic connection. This incident is significant as it raises concerns about the security of telecommunications infrastructure in the Netherlands and the potential for cybercriminals to exploit vulnerabilities in such critical services. Users of Odido and related services may be at risk of data exposure, which could have broader implications for customers' personal information security. The investigation is ongoing, and police are working to determine the full extent of the breach and any potential repercussions.

Read Original
PreviousPage 113 of 370Next