Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

The Medusa ransomware group has successfully targeted over 500 victims since its emergence in 2021. The attackers exploit significant vulnerabilities to infiltrate systems at an alarming rate. This surge in attacks raises concerns about the security measures in place across various sectors. Organizations that have fallen victim to Medusa may face severe operational disruptions and financial losses due to data encryption and ransom demands. As the group continues to evolve its tactics, it’s crucial for companies to remain vigilant and implement robust cybersecurity practices to protect against such threats.

Read Original
Actively Exploited

In a recent cyber campaign called CameraSwarm, hackers managed to compromise over 14,500 Dahua IP cameras, primarily located in Ukraine and Russia. The attackers exploited vulnerabilities in the camera systems, which raises significant security concerns, especially given the sensitive nature of surveillance equipment. This incident not only affects the users of these cameras but also poses potential risks to privacy and security in the areas where these devices are deployed. Researchers are urging owners and operators of Dahua cameras to take immediate action to secure their devices to prevent further exploitation. The scale of this breach highlights the ongoing risks associated with IoT devices and the need for better security measures in their design and deployment.

Read Original

OpenAI has temporarily paused its reinforcement learning training for new AI models for two weeks to enhance its safety protocols. This decision comes as the company aims to prevent incidents similar to a recent problem experienced by Hugging Face, which raised concerns about potential unsafe AI behaviors. As AI models become more advanced, OpenAI recognizes that the risks associated with their development and testing increase significantly. By taking this step, OpenAI is prioritizing the safety of its AI systems and ensuring stricter monitoring to mitigate any potential issues. This move reflects ongoing concerns in the tech community about the responsible development of AI technologies and their implications for users and society at large.

Read Original

U.S. cybersecurity agencies have issued a warning that malicious actors are using AI-generated scripts to target Siemens S7 Series programmable logic controllers (PLCs) within critical infrastructure across the United States. These PLCs are commonly used in various industrial settings, making them a significant focus for potential attacks. The use of AI in crafting these scripts could make it easier for attackers to exploit vulnerabilities, posing a serious risk to essential services and operations. As these systems control important infrastructure, any successful breach could lead to severe disruptions. Organizations utilizing Siemens PLCs should be especially vigilant and take proactive measures to secure their systems against these AI-driven threats.

Read Original

A security incident has been reported involving the compromise of over 14,000 Dahua cameras, primarily located in Ukraine and Russia. This breach occurred between June 17 and July 22, 2026, when a researcher found an exposed directory that contained the attacker's tools. Alarmingly, most of the affected cameras did not require any passwords for access, making it easier for the attacker to take control. This incident raises significant concerns about the security of surveillance systems, especially in sensitive geopolitical regions. The exposure of such a large number of cameras can have serious implications for privacy and security, as these devices are often used for monitoring critical infrastructure and public spaces.

Read Original

A spear-phishing campaign linked to a China-based group known as FamousSparrow is targeting organizations in Central Asia with various remote access trojans (RATs). These attacks are part of a broader strategy that reflects the geopolitical tensions in the region and the ongoing activities of advanced persistent threat (APT) groups. The campaign uses deceptive emails to trick recipients into installing malware, which can give attackers control over compromised systems. This poses significant risks for the affected organizations, as it could lead to data breaches, espionage, and further exploitation of sensitive information. Security experts are urging organizations in Central Asia to strengthen their defenses against such targeted attacks, especially as the threat landscape continues to evolve with geopolitical developments.

Read Original

Tina Peters, who previously served time for felony election-related crimes, is being considered for a role in election administration by a county in California. Her past actions raised significant concerns about election security and integrity, making her potential hiring controversial. Peters gained notoriety for her involvement in spreading false claims about the 2020 election and was convicted for tampering with voting equipment. This situation has sparked debate over the qualifications necessary for overseeing elections, as well as the implications of employing someone with a criminal background in such a sensitive role. The decision could affect public trust in the electoral process, particularly in a state that plays a crucial role in national elections.

Read Original

The Linux Foundation is launching its Akrites initiative in September, which aims to enhance security for open-source projects by accepting AI-powered vulnerability reports. This program will allow developers and researchers to submit findings on potential vulnerabilities, facilitating a more proactive approach to security in the open-source community. By leveraging AI, Akrites seeks to streamline the reporting process and improve the overall safety of software projects. This initiative is particularly relevant as the use of open-source software continues to grow, making it essential to address vulnerabilities effectively. With Akrites, developers can better protect their projects and users from potential security risks.

Read Original
Actively Exploited

A new malware campaign has been identified by eSentire that combines tactics from three different types of malware: ClickFix, ErrTraffic, and Cruciferra. This campaign employs ClickFix lures to deceive users into clicking on malicious links. Once users engage, ErrTraffic takes over to manipulate traffic, while Cruciferra is used to execute the final malicious actions. This combination poses a significant risk to users who may unknowingly engage with these deceptive tactics. The research underscores the evolving strategies of cybercriminals and the need for heightened awareness and vigilance among users and organizations alike.

Read Original

The Clop ransomware group has reportedly exploited a serious vulnerability in PTC’s product lifecycle management software. This breach occurred in June, well before the group began sending out ransom demands to affected companies. The implications of this attack could be significant, as it not only compromises sensitive data but also puts the operations of various businesses at risk. Organizations using PTC’s software should be particularly vigilant, as the threat of extortion looms large. The situation is still developing, and the full impact of the attack is just starting to become clear.

Read Original
Actively Exploited

Geekom has acknowledged that a malware strain known as Asruex was found embedded in a LAN driver available for download on its legacy support page. This particular driver allowed the malware to execute with administrator-level permissions, raising significant security concerns. Users who downloaded and installed this compromised driver may be at risk of unauthorized access and control over their systems. The discovery emphasizes the importance of ensuring that software and drivers are sourced from trusted and current locations to avoid potential security breaches. Geekom's admission serves as a reminder for users to regularly check for updates and security advisories from their hardware vendors.

Read Original
Actively Exploited

The Grandoreiro malware has resurfaced in Mexico, accounting for 40% of its recent detections following a disruption in 2024. This malware primarily employs DLL sideloading techniques, which allow it to execute malicious code by leveraging legitimate software. Researchers indicate that this recent activity underscores a renewed focus on targeting users in Mexico, raising concerns among individuals and organizations alike. The resurgence of Grandoreiro poses significant risks, especially as it may lead to data theft and unauthorized access to sensitive information. Users and companies operating in Mexico should be vigilant and consider enhancing their security measures to defend against this threat.

Read Original

A new cyber espionage campaign known as SilkParasite is targeting government entities in Central Asia. Researchers have identified that this operation utilizes seven remote access tools (RATs), five of which are new to the cybersecurity community: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. This campaign, which was first detected in late 2025, raises concerns due to its focus on government systems, suggesting a potential risk to national security and sensitive information. The use of previously undocumented RATs indicates that attackers are evolving their tactics, making it crucial for governments and cybersecurity teams to stay alert and enhance their defenses. The situation underscores the ongoing threat of cyber espionage in the region, necessitating a proactive approach to cybersecurity for those affected.

Read Original

Cyberattacks are becoming faster and more sophisticated, largely due to advances in artificial intelligence. A recent report indicated that AI-driven attackers increased their activity by 89% from the previous year in 2025. This rapid escalation means that the time between discovering a vulnerability and exploiting it is shrinking, posing a significant risk to organizations. Despite the growing threat, federal response efforts have not kept pace with these advancements, leaving many systems vulnerable. Companies and government entities need to urgently update their cybersecurity measures to address these evolving threats and protect sensitive data.

Read Original

On August 18, 2026, Apple addressed a significant security vulnerability in its image handling framework that could allow malicious images to execute harmful code on both desktop and mobile devices. This vulnerability is identified as CVE-2026-65346 and poses a risk to users who may unknowingly open compromised image files. The issue could potentially lead to unauthorized access or control over affected devices, making it crucial for users to update their systems promptly. Apple has released patches to fix this vulnerability, emphasizing the importance of keeping software up to date to protect against such threats. Users of both macOS and iOS devices should ensure they are running the latest versions to mitigate this risk.

Read Original
PreviousPage 12 of 363Next