A serious vulnerability in the Linux Kernel-based Virtual Machine (KVM) has been discovered, allowing attackers to potentially escape from a virtual machine (VM) to the host system. This flaw, which is 16 years old, affects both Intel and AMD systems. Security researcher Hyunwoo Kim reported that the issue is a use-after-free vulnerability, enabling malicious code running in a guest VM to corrupt the memory of the host kernel. The implications are significant, as it could allow unauthorized access to sensitive data or control over the host. Organizations using affected systems should take immediate action to assess their vulnerability and apply necessary patches to safeguard their environments.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Recent phishing attacks have targeted Facebook users by offering fake verification processes, aiming to steal sensitive information from business accounts. Attackers utilized a compromised chatbot to enhance their deception, making it easier for them to extract data from unsuspecting users. This campaign specifically affected individuals and businesses that rely on Facebook for communication and marketing. The incident raises concerns about the security of online platforms and highlights the importance of user awareness regarding potential scams. Users are advised to verify requests for information directly through official channels and to be cautious about sharing personal details online.
The CERT Coordination Center (CERT/CC) has issued a warning about a serious vulnerability in several firmware versions from Tenda, a Chinese manufacturer of network devices. Researchers discovered an undocumented backdoor that allows attackers to gain administrative access to the web management interfaces of affected routers, bypassing the usual password protections. This vulnerability is identified as CVE-2026-11405 and poses a significant risk to users, as it could enable unauthorized control of the devices. Owners of Tenda routers are urged to take immediate action to secure their devices, as this flaw could lead to further exploitation. The discovery raises concerns about the security practices of IoT device manufacturers and the implications for consumer privacy and network safety.
BeyondTrust has issued urgent updates to fix two serious vulnerabilities in its Remote Support and Privileged Remote Access products. These flaws, identified as CVE-2026-40138 and another unnamed vulnerability, could allow attackers to gain control over affected devices without needing authentication. The vulnerabilities score a high 9.2 on the CVSS scale, indicating their severity. Users of BeyondTrust's Remote Support and PRA should prioritize applying these updates to mitigate the risk of unauthorized access. With the potential for exploitation, this situation underscores the importance of timely patch management in maintaining security.
CrowdStrike has identified new techniques related to prompt injection, a method that allows attackers to manipulate AI systems. These techniques can lead to unauthorized access to sensitive information or the execution of harmful commands by tricking AI models into providing misleading outputs. The research emphasizes the need for organizations using AI tools to be vigilant, as these vulnerabilities can affect a wide range of applications and systems that rely on natural language processing. As AI technology becomes increasingly integrated into various sectors, understanding and addressing these injection techniques is crucial for maintaining security. Companies should implement stricter validation and monitoring protocols to mitigate these risks.
SCM feed for Latest
Several U.S. Army websites were defaced in an incident that appears to be part of a 404 hijacking campaign. The affected sites include oil.army.mil and ai2c.army.mil, which are associated with the Army’s Open Innovation Lab and the Artificial Intelligence Integration Center. The attackers manipulated error pages to display unauthorized content, raising concerns about the security of military web properties. This incident not only disrupts the online presence of these Army branches but also poses potential risks by undermining trust in military communications. Ensuring the integrity of government websites is crucial, especially as cyber threats continue to evolve.
SCM feed for Latest
Check Point Research has identified a new group of Iranian hackers using a modular command and control (C2) framework called Cavern Manticore. This group shows tactical similarities to other known hacking organizations like MuddyWater and Lyceum. Their activities have primarily targeted Israeli organizations, raising concerns about the potential for increased cyberattacks in the region. The modular nature of their framework suggests that the hackers can easily adapt and evolve their tactics, making it challenging for defenders to keep up. This development underscores the ongoing cyber threats facing critical infrastructure and organizations in Israel.
Sainsbury's, the UK supermarket chain, is ramping up its use of facial recognition technology to tackle shoplifting. The company plans to increase the number of stores using this system from over 55 to around 200 by the end of the year. This move comes as retailers face rising theft rates and seek new ways to protect their merchandise. While the facial recognition technology aims to deter criminals, it raises privacy concerns among customers and civil rights advocates, who worry about surveillance and data security. As Sainsbury's expands its surveillance measures, the balance between loss prevention and customer privacy will be a critical topic of discussion.
SCM feed for Latest
Vietnamese authorities have arrested seven individuals linked to HiAnime, a large-scale anime piracy site that operated under various domains, including Zoro.to and Aniwatch. This site provided free access to a vast library of anime, attracting hundreds of millions of visitors each month and briefly outpacing legal streaming platforms in terms of web traffic. The arrests come as part of a broader crackdown on copyright infringement in the region, which has raised concerns among content creators and legal streaming services. The operation of such piracy sites not only violates copyright laws but also undermines the revenue of legitimate platforms that rely on subscriptions and advertising. This incident highlights the ongoing battle against online piracy and its implications for the entertainment industry.
Hackread – Cybersecurity News, Data Breaches, AI and More
Spanish police, in collaboration with the FBI, have arrested a member of the group known as the Cyber Army of Russia Reborn. This arrest is part of ongoing international efforts to combat pro-Russian cyberattacks, which have been increasingly targeted at various global entities. The individual's involvement in this group highlights the persistent threat posed by cybercriminal organizations aligned with political agendas. As these groups continue to operate, their activities can have significant implications for cybersecurity across multiple sectors, emphasizing the need for robust defenses against such attacks. The collaboration between U.S. and European law enforcement illustrates a united front in tackling cybercrime.
The Moody Bible Institute (MBI) has experienced a significant data breach that has affected approximately 2.3 million individuals. This incident was first reported in June and involved the hacker group ShinyHunters, which leaked the stolen data after MBI allegedly refused to comply with their extortion demands. The leaked information could potentially include sensitive personal details of students, alumni, and staff. Such breaches raise serious concerns about the security of personal data at educational institutions, highlighting the risks they face from cybercriminals. As the situation develops, those affected should remain vigilant about potential identity theft and fraud.
SCM feed for Latest
A security vulnerability has been discovered in the Opera GX browser that could allow attackers to steal user data and launch denial-of-service (DoS) attacks. Identified by researcher zhero_web_security, this issue arises from a zero-click cross-site leak (XS-Leak), which takes advantage of the automatic installation feature for GX Mods. This means users could be at risk without needing to interact with any malicious content. Given that the Opera GX browser is popular among gamers and tech-savvy users, the potential for data theft and service disruption is significant. Users and organizations relying on this browser should stay alert for updates and consider disabling the automatic mod installation feature until a fix is available.
SCM feed for Latest
France's cybersecurity agency, ANSSI, has announced a significant shift in its certification process for security products. Starting in 2027, any security products that do not incorporate quantum-resistant encryption will no longer receive certification. This decision reflects a proactive approach to future-proofing the nation's cybersecurity infrastructure against the potential threats posed by quantum computing. By mandating the use of quantum-resistant encryption, France aims to safeguard sensitive data and communications from being compromised by the advanced capabilities of quantum technology. This move will impact various vendors and their security products, pushing them to adapt and innovate to meet these new standards. As quantum computing continues to evolve, this initiative is a crucial step in ensuring the resilience of France's digital security landscape.
A hacking group known as Armored Likho has reportedly infiltrated critical infrastructure networks, targeting government agencies and electrical power companies in Russia, Brazil, and Kazakhstan. This group is using a malware called BusySnake, which is designed to steal sensitive data from its victims. The breach raises significant concerns about the security of vital services in these countries, as access to such networks can lead to serious disruptions or manipulation of essential operations. The incidents underline the ongoing vulnerabilities within critical infrastructure and the need for increased cybersecurity measures to protect against such intrusions. Continued monitoring and defensive strategies are essential to mitigate the risks posed by these types of attacks.
Researchers have identified a serious memory disclosure vulnerability in Citrix's NetScaler products, which has already attracted the attention of attackers. Following the release of a proof-of-concept exploit, malicious actors are actively trying to exploit this flaw. This vulnerability could potentially expose sensitive information from affected systems, putting organizations at risk. Companies using Citrix NetScaler should urgently assess their systems and apply any necessary patches or mitigations to protect against potential breaches. As the situation develops, it's crucial for users to stay informed and take proactive measures to secure their environments.