Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

The European Parliament has taken a significant step towards a new law aimed at combating child sexual abuse material (CSAM) online. In a recent vote, lawmakers approved a bill that would allow tech companies to scan for CSAM on their platforms. This bill will now be sent to EU member countries for further approval. If enacted, the law could change how companies handle user data, as they would be legally obligated to monitor and report any abusive content they find. Advocates argue that this is a necessary measure to protect children, while critics raise concerns about privacy and potential misuse of the scanning technology. The outcome of this legislation could have wide-ranging implications for internet safety and user privacy across Europe.

Read Original

The OpenMandriva Linux project recently revealed that it faced an internal sabotage attempt linked to disagreements among contributors. This incident appears to stem from a conflict within the community, raising concerns about the integrity and collaboration in open-source projects. Though details on the specific actions taken during the sabotage were not disclosed, the situation emphasizes the challenges that open-source projects face when contributors disagree. Such internal strife can affect project stability and trust among users. As the open-source community relies heavily on collaboration, incidents like this can have broader implications for software development and user confidence.

Read Original

INTERPOL's Operation First Light 2026 has resulted in a significant crackdown on global fraud and money laundering activities, leading to 5,811 arrests across 97 countries. The four-month operation, which wrapped up recently, blocked approximately $293 million in criminal assets. This operation not only targeted individuals involved in financial crimes but also disrupted networks that facilitate these illegal activities worldwide. The scale of the operation underscores the ongoing challenge of tackling international crime, especially in the digital space where fraud and money laundering often thrive. The impact of such coordinated law enforcement efforts is crucial for enhancing global security and deterring future criminal undertakings.

Read Original

Recent reports indicate that Iranian cyber actors are shifting their focus from just targeting critical infrastructure to a broader range of Internet-facing vulnerabilities. This means that any company with exposed systems could be at risk of cyber attacks. Researchers emphasize that even businesses that might think they are safe, due to their obscurity or size, are not immune. The situation is a wake-up call for organizations to reassess their cybersecurity posture and ensure they are protected against potential intrusions. Companies need to prioritize identifying and patching vulnerabilities to avoid becoming targets of these increasingly sophisticated attacks.

Read Original

Hackers have compromised the GitHub repository of the Injective Labs SDK project and used it to distribute a malicious package on npm, the Node Package Manager. This malicious package is designed to steal private keys and mnemonic seed phrases from users' cryptocurrency wallets. Developers and users who downloaded the affected package could find their digital assets at risk. This incident raises significant concerns about the security of open-source projects and the potential for similar attacks on other repositories. Users are urged to be cautious and verify the integrity of packages before installation to protect their cryptocurrency holdings.

Read Original

Organizations are currently unprepared for the security challenges posed by AI agents, which require a different management approach than traditional service accounts or API tokens. As AI technology becomes more integrated into various operations, the potential for misuse or exploitation increases, leading to significant security risks. Companies need to rethink their security strategies to accommodate the unique characteristics of AI agents. This includes understanding how these agents operate and implementing appropriate safeguards to protect sensitive data and systems. Failing to adapt could leave businesses vulnerable to attacks that exploit these new AI-driven tools.

Read Original

Datadog Security Labs has raised concerns about ongoing attacks that target corporate GitHub organizations. These attackers use automated tools to scrape data from GitHub, accessing information about organizations, repositories, and user accounts through the GitHub API. They often utilize 'ghost' accounts that have been dormant for years, as well as compromised OAuth tokens, making their activities harder to detect. This situation poses a risk to businesses, as it allows attackers to map out corporate structures and potentially plan further attacks. Companies should be vigilant about the security of their GitHub accounts and consider reviewing access tokens and account activity to mitigate these risks.

Read Original
Actively Exploited

A new ransomware strain called GodDamn has emerged, targeting systems by disabling security software using a signed driver known as PoisonX. Discovered by Symantec's Threat Hunter Team, GodDamn is considered an advanced version of the Beast ransomware family, and it first appeared on May 21, 2026. The ransomware's ability to circumvent security measures poses a significant risk to organizations, as it can lead to data breaches and financial losses. The analysis of an attack in early June indicates that the group behind it is actively exploiting this vulnerability, making it imperative for companies to assess their defenses. Users and companies need to be aware of this threat and take immediate steps to bolster their security protocols.

Read Original

Interpol recently conducted a major operation called Operation First Light, which led to the arrest of 5,800 individuals involved in cybercrime across 97 countries. This initiative targeted social-engineering scams, revealing over 142,000 victims affected by various fraudulent schemes. The operation underscores the global scale of cybercrime and the need for international cooperation to combat it. Law enforcement agencies worldwide are now more aware of the tactics used by scammers, highlighting the importance of public awareness and prevention strategies. As these scams continue to evolve, it’s crucial for individuals to stay informed and vigilant against such threats.

Read Original

A new group called Helix has emerged, employing tactics like voice phishing (vishing) to target SharePoint environments for data theft. They are using identity-focused strategies to gain access to sensitive information by tricking users into providing their credentials. This method includes device code phishing and exploiting multi-factor authentication (MFA) weaknesses. The emergence of Helix poses a significant risk to organizations that rely on SharePoint for data management, as attackers can bypass traditional security measures. Companies must remain vigilant and educate their employees about these tactics to prevent falling victim to such scams.

Read Original

Recent findings have revealed that Tenda routers may contain a hidden backdoor in their firmware, potentially allowing unauthorized access to users' networks. Security researchers have urged users to take immediate action to protect themselves, as this vulnerability could expose sensitive information. Until Tenda releases a patch to address this issue, users should disable certain settings to minimize the risk of exploitation. This situation is particularly concerning given the popularity of Tenda routers among consumers, making a significant number of users vulnerable to potential attacks. It's essential for users to stay vigilant and follow recommended safety measures to secure their home networks.

Read Original

The article discusses the impact of cyberwarfare on businesses, using the example of a Ukrainian tax software company that has suffered due to the ongoing conflict in Ukraine. This situation illustrates how cyberattacks can extend their reach far beyond the immediate battlefield, affecting companies worldwide. Businesses in other countries, especially those connected to or reliant on technology, need to recognize the risks posed by cyber conflicts and take proactive measures to safeguard their operations. It emphasizes the necessity for companies to develop strategic plans to respond to potential cyber threats stemming from global conflicts. This is particularly relevant as the nature of warfare evolves into a digital arena.

Read Original

The Armored Likho APT group is reportedly using a sophisticated toolkit that includes AI-generated malware alongside existing threats like the BusySnake Stealer, a Python-based tool designed to siphon off sensitive information. This group is known for its modular approach, which allows them to adapt their methods and tools quickly, making it difficult for organizations to defend against their attacks. The use of obfuscated remote access trojans (RATs) and network tunneling tools like Go2Tunnel adds another layer of complexity to their operations. As a result, businesses and individuals need to be vigilant about their cybersecurity measures to protect against these evolving threats. Given the capabilities of this APT group, the potential for data breaches and unauthorized access remains high, raising concerns for organizations that store sensitive information.

Read Original

On July 7, 2026, the UK government announced its Agentic AI Defense Plan, aiming to enhance the nation's cybersecurity capabilities. This initiative comes alongside a pledge from various industry players to strengthen cooperation in tackling cyber threats. The government is prioritizing the integration of artificial intelligence to better predict and respond to cyber incidents. This move is significant as it reflects a proactive approach to safeguarding sensitive information and critical infrastructure against increasingly sophisticated cyberattacks. By fostering collaboration between public and private sectors, the UK aims to build a more resilient cybersecurity framework.

Read Original
Actively Exploited

Researchers at Huntress have discovered a threat actor using a technique called vibe-coded PowerShell to map out Active Directory networks. This method allows attackers to gather detailed information about network configurations and user accounts, which can be crucial for planning further attacks. The use of PowerShell in this context is concerning, as it is a legitimate tool that can be exploited for malicious purposes. Companies with Active Directory environments should be particularly vigilant, as this type of reconnaissance can lead to more severe security breaches. The findings emphasize the need for organizations to monitor their networks for unusual PowerShell activity and tighten their security measures.

Read Original
PreviousPage 116 of 370Next