Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Palo Alto Networks has addressed 13 vulnerabilities in its PAN-OS software, which includes serious issues like buffer overflow, denial-of-service (DoS), command injection, server-side request forgery (SSRF), and authentication bypass. These vulnerabilities could allow attackers to gain unauthorized access, disrupt services, or execute harmful commands. Organizations using PAN-OS should prioritize these updates to protect their networks from potential exploitation. The presence of these vulnerabilities emphasizes the need for companies to stay vigilant and regularly update their systems. Users are urged to apply the latest patches as soon as possible to mitigate risks.

Read Original
Actively Exploited

A recent cryptomining incident has revealed that AI gateways can be exploited by attackers to gain access to sensitive resources like AI models, cloud infrastructure, and identity and access management (IAM) data. This situation raises concerns for organizations that rely on these technologies, as it highlights vulnerabilities that could be leveraged for unauthorized activities. The incident serves as a warning that companies need to reassess their security measures around AI and cloud systems to prevent similar breaches. As these technologies become more integrated into business operations, the potential for exploitation increases, making it essential for users to understand the risks involved. The implications of such breaches could be significant, affecting not only data security but also operational integrity.

Read Original
Actively Exploited

A data breach at KDDI, a major Japanese telecommunications company, has compromised the personal information of approximately 12 million users. Hackers took advantage of a zero-day vulnerability found in a third-party system to gain unauthorized access to KDDI's email system used by Internet Service Providers (ISPs). This breach raises concerns about user privacy and the security of sensitive data, as affected individuals could face risks like identity theft or fraud. KDDI has not yet released detailed information on how they plan to address the breach or what specific data was stolen, but the scale of the incident underscores the need for companies to bolster their cybersecurity measures, especially when relying on third-party systems.

Read Original

Microsoft has rolled out a security update to address a serious vulnerability in its Malware Protection Engine, specifically CVE-2026-50656. This flaw, which affects Windows 10 and Windows 11, allows authenticated attackers to escalate their privileges to SYSTEM-level by exploiting improper link resolution before file access. The vulnerability was brought to light on June 10, and it poses a significant risk as it can be exploited with relatively low complexity. Users of affected systems should prioritize applying this update to safeguard their devices against potential attacks that could compromise system security.

+1 more
Read Original

CISA recently experienced a cybersecurity incident that raised concerns about the agency's internal security measures. The incident involved unauthorized access to sensitive information, although specific details about the type of data compromised remain unclear. This breach not only affects CISA but also raises alarms for other government agencies and private sectors that rely on CISA for guidance on cybersecurity practices. Experts emphasize the need for improved security protocols and stronger safeguards to protect sensitive information from similar attacks in the future. As CISA plays a crucial role in national cybersecurity, its vulnerabilities could have broader implications for the security posture of the entire country.

Read Original
Critical
OpenPLC v3

All CISA Advisories

A serious vulnerability has been found in OpenPLC v3, which could allow authenticated attackers to write arbitrary files to the filesystem and execute malicious code. This flaw, identified as CVE-2026-14480, stems from how the legacy web user interface handles file uploads, enabling attackers to specify file names without proper validation. If exploited, it could lead to code execution under the OpenPLC runtime user, posing significant risks to critical infrastructure sectors such as manufacturing, energy, and transportation. OpenPLC v3 is now end-of-life and no longer receives security updates, making it essential for users to upgrade to OpenPLC v4 to mitigate this risk.

Read Original

A recent survey by MetaCompliance reveals that a significant number of Chief Information Security Officers (CISOs) are worried that corporate executives do not fully grasp the cybersecurity risks faced by their employees. The survey indicates that 75% of CISOs believe that board members are not sufficiently engaged with the changing landscape of cyber threats. This disconnect could leave organizations vulnerable, as executives may not prioritize necessary security measures or resources. The findings suggest a pressing need for better communication between cybersecurity leaders and company executives to ensure that cybersecurity remains a top priority. Understanding these risks is essential for protecting sensitive data and maintaining trust with customers and stakeholders.

Read Original

Schneider Electric's PowerChute Serial Shutdown software has several vulnerabilities that could allow attackers to manipulate system files, inject malicious data, or gain unauthorized access to accounts. Versions 1.4 and earlier are affected by these security flaws, which include issues like improper path restrictions and output handling. If exploited, these vulnerabilities could disrupt services or expose sensitive information across critical sectors such as energy, healthcare, and transportation. Users of affected versions are urged to upgrade to version 1.5, which includes fixes for these issues. The vulnerabilities were disclosed recently, and it is crucial for organizations to address them promptly to mitigate potential risks.

Read Original

Schneider Electric has reported a vulnerability affecting its Easergy MiCOM Px40 Series protection relays, which are used in medium to extra high voltage applications. The vulnerability allows unauthorized exposure of device identification through the SNMP protocol, impacting various models including the Easergy MiCOM P14x, P24x, P341, and several others, all prior to specific firmware versions. This issue raises concerns for critical infrastructure sectors such as energy and manufacturing, as it could lead to unauthorized access to sensitive device information. Users are advised to implement immediate mitigations or upgrade to firmware versions that eliminate SNMP functionality to protect their systems. This situation is particularly pressing for organizations relying on these devices for operational safety and security.

Read Original

Operation First Light 2026, an initiative funded by the Chinese government and coordinated by Interpol, has resulted in the arrest of 5,811 individuals involved in cybercrime across multiple countries. This large-scale operation targeted various criminal activities, including online fraud and the distribution of malware. The collaboration aims to enhance international law enforcement's ability to combat cyber threats and improve global security. The significant number of arrests suggests a considerable crackdown on organized cybercrime networks, which could disrupt ongoing illegal activities. This operation not only highlights the growing global concern over cybercrime but also emphasizes the role of international cooperation in addressing these challenges.

Read Original
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces

Hackread – Cybersecurity News, Data Breaches, AI and More

Researchers at Wiz have identified vulnerabilities known as GhostApproval symlink flaws in several leading AI coding assistants. These flaws could allow attackers to conceal sensitive file paths, bypass safety checks, and gain unauthorized access to systems. The implications are significant, particularly for developers and organizations that rely on these tools for coding and software development. If exploited, these vulnerabilities could lead to data breaches or other security incidents, jeopardizing sensitive information. Companies using these AI coding tools should assess their systems for potential exposure and take steps to mitigate the risks posed by these flaws.

Read Original

A global enforcement campaign named Operation First Light 2026 has led to the arrest of 5,811 individuals involved in social engineering scams. These scams often see criminals impersonating police officers, romantic partners, or business suppliers to defraud victims. The operation, which spanned four months, included participation from law enforcement in 97 countries and territories. Investigators also seized $293 million in illicit assets linked to these scams, which often involve money laundering to conceal the proceeds. This crackdown is significant as it demonstrates a coordinated international effort to combat fraud that exploits human trust.

Read Original

Microsoft is set to retire the Outlook Web Access (OWA) Light client in an upcoming update to Exchange Server. This lightweight version of the email client was designed for users with limited bandwidth or older devices. The discontinuation means that users relying on OWA Light will need to transition to the standard OWA client, which could impact their ability to access email if their devices or connections are not compatible. Microsoft has not yet specified a timeline for the retirement or provided detailed guidance on the transition process. This change could affect organizations with users who depend on the lighter version for remote access, potentially disrupting their workflow.

Read Original

Wiz has identified a security flaw named GhostApproval that affects six major AI coding assistants. This vulnerability allows attackers to bypass approval processes, potentially leading to unauthorized code execution. The flaw is particularly concerning because it could enable malicious actors to exploit code without proper authorization, putting developers and their projects at risk. The affected coding assistants are widely used in the software development community, which raises alarms about the potential for widespread misuse. It's crucial for users of these tools to stay informed and take necessary precautions as more details about the flaw emerge.

Read Original

A new ransomware strain called GodDamn has been identified by cybersecurity researchers, specifically the Threat Hunter Team at Symantec. This ransomware uses a malicious kernel driver named PoisonX to disable endpoint security measures, allowing it to operate without detection. GodDamn was first observed in the wild on May 21, 2026, and is believed to be a rebranding of an earlier ransomware known as Beast. The use of PoisonX is particularly concerning as it directly undermines the defenses that companies rely on to protect their systems. Organizations need to be vigilant and update their security protocols to defend against this new threat.

Read Original
PreviousPage 117 of 370Next