Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Progress Software has advised ShareFile customers to shut down their Windows servers that run Storage Zone Controllers due to a credible external security threat. The company has temporarily restricted access to affected accounts as a precautionary measure while they investigate the situation. This warning raises concerns for businesses relying on ShareFile for secure file storage and collaboration, highlighting the potential risks associated with third-party services. Users are encouraged to take immediate action to protect their data until the issue is resolved. Progress is working closely with both internal and external security teams to address the threat effectively.

Read Original

Progress Software has alerted its ShareFile customers to a serious external security threat affecting on-premises Storage Zone Controllers. The company has advised all admins to shut down their servers immediately to protect sensitive data from potential attacks. This warning comes as a response to what has been described as a credible risk, emphasizing the need for users to take swift action to avoid any data breaches. The urgency of this recommendation highlights the severity of the situation, as these systems are commonly used for secure file sharing in various organizations. Customers are urged to stay vigilant and monitor for any further updates from Progress Software.

Read Original

Researchers at Binarly have identified six new vulnerabilities in U-Boot, the bootloader responsible for starting various hardware devices, including routers and smart cameras. Four of these flaws can cause devices to crash, while two others could allow attackers to execute their own code by presenting a malicious image to the bootloader. This is particularly concerning as U-Boot is widely used across many platforms, making a large number of devices potentially vulnerable. If exploited, these vulnerabilities could lead to unauthorized access and control over affected systems before they even fully boot up. Users and manufacturers need to be aware of these vulnerabilities to ensure their devices remain secure.

Read Original
Actively Exploited

Hackers are exploiting a serious vulnerability in the official Docker image for Gitea, a self-hosted Git service. This flaw allows attackers to bypass authentication and impersonate any user, including those with administrative privileges. As a result, unauthorized individuals could gain access to sensitive repositories and potentially compromise projects hosted on Gitea. This situation poses a significant risk for organizations using the affected Docker image, as it could lead to data breaches or loss of intellectual property. Users and companies are urged to take immediate action to secure their installations and prevent exploitation.

Read Original

A Bulgarian man, already serving a lengthy prison sentence for laundering millions from fraud victims, has been charged with stealing $290,000 in cryptocurrency that had been seized by the government. Authorities allege that while incarcerated, he orchestrated the theft of the funds, which were part of a larger investigation into his previous criminal activities. This case raises serious concerns about security within correctional facilities, especially regarding the ability of inmates to manipulate digital assets even while behind bars. The incident highlights the ongoing challenges law enforcement faces in tracking and securing cryptocurrency, particularly in cases involving organized crime and fraud. The implications for victims of fraud and the integrity of the justice system are significant, as this theft undermines efforts to recover stolen funds.

Read Original

The Department of Homeland Security (DHS) has reported a significant data breach involving one of its databases, although specific details about the extent of the breach or the data compromised have not been disclosed. Meanwhile, Adobe is increasing the frequency of its security updates to better protect users from vulnerabilities, responding to the growing number of cyber threats. In another development, Canadian authorities have successfully disrupted ransomware operations, which is a crucial step in combating the rise of these attacks. Additionally, a data breach at AssuranceAmerica has put the personal information of around 7 million individuals at risk. This series of events illustrates the ongoing challenges organizations face in safeguarding sensitive data and the need for improved security measures across various sectors.

Read Original

Researchers from Ledger's Donjon security team have discovered a significant vulnerability in Tangem crypto wallet cards. By using a precisely timed laser pulse directed at the chip inside the card, an attacker can reset the wallet's password to a new one of their choosing. This means that once the password is changed, the attacker gains full control over the wallet and can transfer any cryptocurrency stored on it. While this poses a serious risk, it's important to note that the attack requires specialized equipment and expertise, so it may not be an immediate concern for most users. Nonetheless, it raises questions about the security of hardware wallets, especially those that cannot be patched or updated to fix this flaw.

Read Original

Researchers have identified three serious vulnerabilities in the OpenClaw personal AI assistant that, if exploited, could allow attackers to steal user credentials, escalate privileges, and execute arbitrary code on the host device. These vulnerabilities have been assigned high CVSS scores, with one flaw rated at 8.8, indicating a significant risk. While the vulnerabilities have been patched, the details raise concerns about the security of AI applications and the potential for misuse. Users of OpenClaw and similar AI assistants should ensure they are running the latest updates to protect against these risks. This incident serves as a reminder of the importance of regular software maintenance and vigilance in cybersecurity practices.

Read Original

The article discusses how the rise of AI agents is leading to an increase in non-human identities within organizations, complicating the management of identity security. As these AI agents proliferate, companies struggle to track what identities exist, who controls them, and what access privileges they have. This growing complexity creates a larger attack surface for cybercriminals, making it essential for organizations to enhance their visibility and governance over identity management. Failing to do so could leave companies vulnerable to unauthorized access and data breaches. The piece emphasizes the need for stronger identity governance measures as AI continues to evolve and integrate into business operations.

Read Original

Researchers at the AI Now Institute have created a proof-of-concept exploit that demonstrates how popular AI tools designed for security could be misused to launch cyber-attacks. These tools, often employed to enhance cybersecurity measures, might inadvertently provide attackers with new methods to bypass defenses. The study raises concerns about the dual-use nature of artificial intelligence in cybersecurity, where the same technologies that protect systems can also be exploited for malicious purposes. This finding is significant as it highlights the need for developers and companies to consider the potential for misuse when creating and implementing AI security tools. As AI continues to integrate into security practices, awareness and proactive measures are crucial to prevent potential exploitation.

Read Original
Critical
Cybersecurity Negotiator Gets 70 Months for Helping BlackCat Extort Victims

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Angelo Martino, a former ransomware negotiator, has been sentenced to 70 months in prison for his role in facilitating extortion activities for the BlackCat ransomware group. Martino assisted in negotiating ransom payments and mishandled sensitive client information during cyberattacks against U.S. victims. His actions contributed to the financial and operational distress of the affected organizations, highlighting the ongoing issues with ransomware and the involvement of intermediaries in these crimes. This case serves as a reminder of the legal consequences for those who support cybercriminal operations, as well as the need for organizations to protect their data from exploitation.

Read Original

A new remote access trojan (RAT) named MODBEACON has been linked to the Chinese cybercrime group Silver Fox. This malware, which is built using the Rust programming language, employs gRPC streaming for its command-and-control (C2) traffic, making it more challenging to detect and analyze. Researchers from QiAnXin noted that while the group may seem low-tech, they are actively using SEO poisoning techniques to distribute malicious software through fake installers. This development is concerning as it indicates a shift towards more sophisticated methods of malware distribution, potentially impacting users who unknowingly download compromised software. Organizations and individuals should be cautious of suspicious downloads and ensure they have strong cybersecurity measures in place.

Read Original

A new ransomware known as GodDamn is making waves in the cybersecurity community for its ability to exploit a malicious driver to bypass security measures. This ransomware utilizes remote desktop applications to move stealthily across networks, allowing it to install the PoisonX kernel driver. Once in place, this driver can disable existing cybersecurity protections, making systems more vulnerable to attacks. This development is concerning for organizations relying on traditional security measures, as it highlights the evolving tactics of cybercriminals. Companies need to be vigilant and ensure their networks are protected against this form of exploitation.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The vulnerabilities are CVE-2026-48939 and CVE-2026-56291, both linked to unrestricted file uploads in iCagenda and Balbooa Forms, respectively. These types of vulnerabilities allow attackers to upload potentially harmful files, posing a serious risk to federal agencies and other organizations. CISA's Binding Operational Directive 26-04 emphasizes the need for federal agencies to prioritize the remediation of these high-risk vulnerabilities swiftly. While the directive specifically targets federal entities, CISA encourages all organizations to adopt similar risk-based strategies for vulnerability management.

Read Original

Recent research by SentinelOne reveals that both Chinese and Indian hackers have been targeting the Balochistan Police force in Pakistan for at least two years. This dual approach from rival nations highlights a significant cybersecurity concern for the police, which is responsible for maintaining law and order in a volatile region. The attacks may be aimed at gathering intelligence or disrupting operations, raising alarms about the security of sensitive information within the police force. As the geopolitical tensions between China and India persist, such cyber operations could escalate, posing further risks to national security and public safety in Pakistan. It is crucial for the Balochistan Police to enhance their cybersecurity measures to protect against these persistent threats.

Read Original
PreviousPage 114 of 370Next