This week, several cybersecurity issues emerged, highlighting vulnerabilities in everyday technology. Home devices are being exploited as routing tools for proxy botnets, allowing attackers to route malicious traffic through unsuspecting networks. Additionally, researchers discovered that clean code can inadvertently introduce vulnerabilities through flawed dependencies. AI systems are also being misled by incorrect instructions, raising concerns about their reliability. These incidents emphasize a common theme: many systems and processes that people trust are not as secure as they should be, potentially putting users at risk. As the lines blur between convenience and security, users and developers alike must be more vigilant about the technologies they rely on.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Hackread – Cybersecurity News, Data Breaches, AI and More
Malwarebytes has reported that attackers are using fake Google and Cloudflare verification pages as part of a scheme to distribute multiple families of malware, including StealC and NetSupport. This operation is linked to a shared infrastructure known as ClickFix. The fraudulent pages trick users into believing they are legitimate, making it easier for the malware to be delivered. This affects anyone who may inadvertently interact with these deceptive sites, potentially leading to data theft and system compromise. The incident emphasizes the need for users to be cautious about online verifications and the sites they engage with, as the risks of malware infections continue to rise.
Researchers have discovered two campaigns that use indirect prompt injection attacks to manipulate AI agents browsing the web. These attacks embed malicious code in websites, tricking the AI into making unauthorized cryptocurrency payments. The implications of this finding are significant, as it indicates that even autonomous systems can be compromised through cleverly designed prompts. This raises concerns for developers and companies relying on AI for financial transactions, as they may inadvertently expose themselves to fraud. Users of AI systems need to be aware of these vulnerabilities and take steps to protect their assets.
The Hacker News
A group of hackers, believed to be linked to China, has launched a campaign targeting Indian taxpayers and finance professionals using a fake tax filing tool. This operation, dubbed Operation DragonReturn by Seqrite Labs, involves sending emails that appear to be from the Income Tax Department of India. The goal is to deliver a remote access trojan (DcRAT) that can steal sensitive information from infected systems. This attack not only threatens individual taxpayers but also poses risks to corporate finance teams who handle sensitive financial data. As cyber threats continue to evolve, awareness and vigilance are crucial for those in the affected sectors.
France is pushing for a major shift in its cybersecurity approach by announcing that it will stop certifying encryption products that are not resistant to quantum computing. This decision, communicated by the French cybersecurity agency ANSSI, will take effect in 2027, with a push for businesses to adopt quantum-safe encryption by 2030. The move will primarily impact government agencies and critical infrastructure operators, as ANSSI approval is mandatory for their encryption systems. The urgency behind this transition stems from the potential threats posed by quantum computers, which could break traditional encryption methods. By enforcing this policy, France aims to enhance the security of its digital communications and protect sensitive information from future quantum attacks.
Hackread – Cybersecurity News, Data Breaches, AI and More
Generative AI technology is rapidly evolving, making it significantly easier for individuals to create convincing fake documents. This rise in document forgery poses a serious challenge for security teams, who now have to ensure the authenticity of documents by verifying their origins, signatures, and overall integrity. The ability of AI to produce documents that 'look right' complicates the verification process, as traditional methods may no longer suffice. As a result, organizations need to adopt more stringent measures to combat this emerging threat. This situation not only affects businesses but also raises concerns about trust in digital documentation across various sectors.
Securelist
A new phishing attack is exploiting the OAuth 2.0 Device Authorization Grant, commonly used for authenticating smart devices like TVs and printers. Attackers have created a fake Microsoft website that mimics the legitimate login process, tricking users into entering their credentials. This type of attack is particularly concerning as it targets users who may not be familiar with the intricacies of secure URL verification. As a result, anyone using devices that rely on OAuth for authentication could be at risk. Users are advised to be cautious and verify URLs carefully before entering sensitive information, especially when prompted by unexpected requests.
Infosecurity Magazine
The National Crime Agency (NCA) and the Internet Watch Foundation (IWF) are sounding alarms about a troubling trend where images and videos of children are being manipulated into sexual abuse material using artificial intelligence tools. This growing issue is alarming for parents, as it not only exploits innocent images shared online but also poses a significant risk to children's safety. The agencies are urging parents to be vigilant about the images they share, as these could be misused. The manipulation of such content highlights the darker side of AI technology and the urgent need for awareness and preventive measures in the digital space. Parents and guardians are encouraged to monitor their children's online activities and educate them about the potential dangers of sharing personal images.
The article discusses the growing role of artificial intelligence in identifying software vulnerabilities at an unprecedented scale. However, the challenge lies in determining which of these vulnerabilities are significant and require immediate attention. Many organizations struggle to prioritize these findings, potentially leaving them exposed to real risks. This situation emphasizes the need for better tools and strategies to assess and manage vulnerabilities effectively. As AI continues to evolve, companies must adapt to ensure they can protect their systems from serious threats stemming from these identified issues.
Help Net Security
Organizations are increasingly using guest accounts to provide temporary access to contractors and partners. However, many of these accounts remain active long after their purpose has ended, posing risks to corporate data security. According to Kaseya’s 2026 SaaS Security Report, guest accounts made up 69% of monitored SaaS accounts in 2025, which is a significant rise of over 1.9 million accounts from the previous year. This surge indicates that guest accounts now outnumber licensed users, creating potential vulnerabilities. Companies need to reassess their access management policies to ensure that these accounts are disabled promptly after use, to prevent unauthorized access to sensitive information.
Help Net Security
Last week, vulnerabilities in SimpleHelp and Oracle EBS Payments were actively exploited. The SimpleHelp flaw allows attackers to gain unauthorized access to systems, posing a serious risk to users of the remote support software. Meanwhile, a vulnerability in Oracle's EBS Payments system has also come under attack, potentially compromising financial data for organizations using this enterprise resource planning software. These incidents emphasize the growing challenges in securing software, particularly as companies increasingly integrate AI features, which often introduce new vulnerabilities. Organizations relying on these systems need to prioritize patching and monitoring to protect sensitive information.
Security Affairs
The U.S. government recently paid $1 million to the data extortion group Kairos after a significant breach. This incident involved the FBI reporting that a group called TeamPCP compromised developer tools, leading to sensitive data being stolen. The impact of this breach extends to various government operations, raising concerns about the security of critical infrastructure and sensitive information. The decision to pay the ransom highlights the ongoing challenges government agencies face in dealing with cyber threats and the difficult choices they must make when confronted with extortion attempts. This situation serves as a reminder for organizations to strengthen their cybersecurity measures and be prepared for potential attacks.
Security Affairs
A U.S. government agency has reportedly paid $1 million to the data extortion group Kairos, according to a case study by Ransom-ISAC. This incident marks a significant shift in the tactics employed by cybercriminals, as Kairos focuses on stealing data and extorting victims instead of traditional ransomware attacks. The case study reconstructed the negotiation process using a leaked transcript and blockchain analysis to trace the ransom payment. This situation raises concerns about the security of government data and the lengths to which agencies may go to recover sensitive information. The payment also highlights the growing threat of data extortion, which can have serious implications for public trust and national security.
A U.S. government entity has reportedly paid around $1 million to a group named Kairos to prevent the release of stolen data. This situation arose from a data theft incident where sensitive files were taken, and negotiations revealed the payment through leaked chat logs and blockchain tracking. Interestingly, it appears that Kairos may not operate like traditional ransomware groups, as there is no evidence of them locking files or demanding ransom in the typical sense. This incident raises concerns about how government entities handle data breaches and the potential for attackers to exploit these situations for financial gain. The event reflects the growing challenge of data protection in the public sector and the lengths to which organizations may go to safeguard sensitive information.
Stelios Kouloglou, a former Member of the European Parliament, was targeted with Pegasus spyware while investigating its use in surveillance. This revelation comes from a report by Citizen Lab, which documented multiple instances of the spyware infecting Kouloglou's devices during his tenure. The irony of a lawmaker probing into the misuse of such technology becoming a victim himself underscores serious concerns about privacy and the misuse of surveillance tools. This incident raises significant questions about the accountability of companies like NSO Group and the implications for individuals involved in political and human rights advocacy. The findings serve as a stark reminder of the potential risks faced by those investigating or opposing powerful surveillance technologies.