Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A Chinese cyber espionage group known as UNC3886 has successfully infiltrated Singapore's four largest telecom providers: Singtel, StarHub, M1, and Simba. This breach occurred at least once last year, raising concerns about the security of sensitive user data and the potential for espionage. The attackers' motives likely include gathering intelligence and accessing confidential information. The incident underscores the vulnerability of critical infrastructure in the telecommunications sector, which is essential for both personal and national communications. This breach could have significant implications for customer privacy and national security, prompting a need for enhanced security measures across the industry.

Impact: Singtel, StarHub, M1, Simba
Remediation: Companies should enhance their security protocols, conduct regular security audits, and ensure employee training on cybersecurity best practices.
Read Original

The ransomware group known as Warlock Gang has successfully breached SmarterTools by exploiting vulnerabilities in the company's SmarterMail product. This breach raises significant concerns for organizations that rely on SmarterMail for email communication, as attackers could potentially access sensitive information. The incident serves as a reminder of the importance of regularly updating and patching software to protect against known vulnerabilities. Users of SmarterMail should be particularly vigilant and ensure their systems are secure to prevent further exploitation. As the cyber landscape continues to evolve, incidents like this highlight the ongoing risks businesses face from ransomware attacks.

Impact: SmarterMail
Remediation: Users should apply the latest security patches for SmarterMail and regularly review their security configurations.
Read Original
Hackers Deliver Global Group Ransomware Offline via Phishing Emails

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A new strain of ransomware known as Global Group is being distributed through phishing emails. This malware is particularly concerning because it can encrypt files without requiring an internet connection, meaning that even offline systems are at risk. Organizations and individuals who fall victim to these phishing attacks could face significant data loss and operational disruptions. Cybersecurity experts warn that the ease of delivery via email makes this a widespread threat that could affect various sectors. Users are advised to be cautious with unsolicited emails and to implement robust security measures to protect against potential attacks.

Impact: N/A
Remediation: Users should be cautious with unsolicited emails and ensure they have updated antivirus software and phishing protection in place.
Read Original

A group known as TeamPCP has been targeting cloud infrastructures with automated attacks that resemble worm-like behavior. These attacks exploit exposed services and interfaces, allowing the attackers to compromise cloud environments on a large scale. Organizations using cloud services need to be particularly vigilant, as these automated attacks can lead to significant data breaches and operational disruptions. The scale of these attacks poses a serious risk to businesses that may not have adequate security measures in place to protect their cloud environments. Companies are urged to strengthen their defenses against these types of vulnerabilities to prevent falling victim to such automated threats.

Impact: Cloud services and infrastructures with exposed services and interfaces
Remediation: Implement robust security measures for cloud environments, such as restricting access to exposed services and regularly monitoring for unusual activity.
Read Original

Hackers are exploiting vulnerabilities in SolarWinds Web Help Desk (WHD) to gain unauthorized access to systems. This allows them to execute code on affected machines, deploying legitimate forensic tools like Velociraptor to maintain persistence and enable remote control. Organizations using SolarWinds WHD should be particularly vigilant, as these vulnerabilities can lead to serious security breaches. The situation underscores the need for companies to regularly update and patch their systems to protect against such attacks. Users of the software must act quickly to ensure their environments are secure.

Impact: SolarWinds Web Help Desk (WHD)
Remediation: Organizations should patch SolarWinds WHD to the latest version and implement security best practices to mitigate exposure.
Read Original

SmarterTools has reported that its network was breached by the Warlock ransomware gang, which gained access through a vulnerability in the company's email system. Fortunately, this incident did not compromise any business applications or account data, meaning that sensitive user information remains secure. However, the breach raises concerns about the security of email systems and the potential for ransomware attacks targeting software vulnerabilities. Organizations using SmarterTools should review their email security practices and ensure they are employing appropriate safeguards against such threats. This incident serves as a reminder that even established software can have weaknesses that attackers might exploit.

Impact: SmarterTools email system
Remediation: Organizations should review email security practices and apply necessary updates or patches as they become available.
Read Original
Cyber Attack Hits European Commission Staff Mobile Systems

Hackread – Cybersecurity News, Data Breaches, AI and More

The European Commission has reported a cyber attack on its mobile infrastructure, which potentially exposed the names and phone numbers of its staff members. This breach raises concerns about the security of sensitive personal information within a major governmental body. Such incidents can lead to targeted phishing attacks and further exploitation of the compromised data. The European Commission has not disclosed specific details about how the attack occurred or whether it has affected other systems. The revelation serves as a reminder of the ongoing risks faced by public institutions in safeguarding their digital assets.

Impact: European Commission staff mobile systems
Remediation: N/A
Read Original

Organizations need to rethink how they manage printers as part of their cybersecurity strategy. Many companies overlook printers when it comes to security, leaving them vulnerable to attacks. Experts suggest closing the ownership gap by clearly defining who is responsible for printer security and implementing strong security controls. This includes treating printers like any other endpoint in the network, ensuring they are updated and monitored for threats. Failing to secure printers can lead to data breaches and unauthorized access, putting sensitive information at risk.

Impact: Printers, networked printers, endpoint devices
Remediation: Establish ownership for printer security, implement durable security controls, monitor and update printers regularly
Read Original

Two men from Connecticut have been charged with a federal crime for allegedly running a fraudulent scheme that targeted online gambling platforms, swindling approximately $3 million. The accused reportedly used sophisticated techniques to manipulate betting systems, allowing them to place bets without the necessary funds. This case raises concerns about the security measures employed by online gambling sites and highlights the vulnerabilities that can be exploited by fraudsters. The investigation into their activities suggests that such schemes could undermine the integrity of online gaming, affecting both the platforms and their users. Law enforcement is taking this case seriously, as it not only involves financial loss but also potential impacts on the reputation and trustworthiness of online gambling environments.

Impact: Online gambling platforms
Remediation: Strengthening security protocols on online gambling platforms to prevent manipulation and fraud.
Read Original

VoidLink is a newly identified Linux-based command-and-control (C2) framework that is designed to facilitate credential theft and data exfiltration across multiple cloud platforms. This malware allows attackers to gain unauthorized access to sensitive information, posing a significant risk to organizations that rely on cloud services. As it targets systems in a multi-cloud environment, companies using cloud storage and applications are particularly vulnerable. The presence of AI code within VoidLink suggests that it may employ advanced techniques to evade detection and enhance its operational capabilities. This development is concerning for cybersecurity professionals, as it indicates a growing sophistication in the tools used by cybercriminals.

Impact: Linux-based systems, multi-cloud environments
Remediation: Organizations should implement strong access controls, regularly update their systems, and monitor for unusual activity across their cloud infrastructures to mitigate risks associated with VoidLink.
Read Original

Attackers are increasingly using targeted wordlists to guess passwords, and they don’t need artificial intelligence to do it. Instead, they rely on tools like CeWL, which scrape an organization’s public-facing content—such as websites and social media—to generate lists of likely passwords based on the language and terms used by that organization. This approach can be highly effective, as it capitalizes on the tendency of users to create passwords that are familiar or meaningful to them. The article emphasizes that simply having complex password policies is not enough to protect against such attacks, as attackers can easily bypass these measures by using personalized wordlists. Organizations need to be aware of this tactic and take steps to educate their users about creating stronger, more secure passwords.

Impact: N/A
Remediation: Organizations should educate users on creating strong, unique passwords and consider implementing multi-factor authentication to enhance security.
Read Original

The European Commission is currently investigating a cyberattack that appears to have breached its mobile device management system. Initial findings suggest that attackers may have accessed some personal information of staff members, including names and phone numbers. However, there are no indications that more sensitive data has been compromised so far. This incident raises concerns about the security of governmental systems and the potential risks to employee privacy. As investigations continue, it remains crucial for organizations to maintain strong cybersecurity measures to protect sensitive information from similar attacks.

Impact: European Commission mobile device management system
Remediation: N/A
Read Original

The European Commission is taking action against Meta, alleging that the company violated EU competition laws by restricting access to WhatsApp for third-party AI assistants. In a change announced on October 15, 2025, Meta updated its WhatsApp Business Solution Terms, effectively preventing outside AI programs from interacting with users on the platform. Since January 15, 2026, Meta's own AI assistant has been the only one allowed on WhatsApp. The Commission is planning to impose interim measures while investigating these practices. This situation raises concerns about competition and innovation in the AI space, as limiting access could stifle the development of alternative AI solutions that could benefit users.

Impact: WhatsApp, Meta AI, third-party AI assistants
Remediation: N/A
Read Original

BeyondTrust has issued a warning about a serious vulnerability in its Remote Support (RS) and Privileged Remote Access (PRA) software. This flaw could let unauthorized attackers run arbitrary code on affected systems, posing a significant security risk. Users of these software products are strongly advised to apply the necessary patches to protect their systems from potential exploitation. The vulnerability's nature means that it could be exploited without requiring any form of authentication, making it particularly dangerous. Organizations using BeyondTrust's software should prioritize updating to secure their environments against this threat.

Impact: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) software
Remediation: Customers should patch their BeyondTrust Remote Support and Privileged Remote Access software as soon as possible.
Read Original

In December 2025, vulnerabilities in SolarWinds Web Help Desk instances were exploited, allowing attackers to gain initial access to compromised systems. This incident raises concerns for organizations using SolarWinds products, as it indicates that these flaws may have been leveraged as zero-day exploits. Such vulnerabilities can lead to unauthorized access and potential data breaches, making it crucial for affected companies to address these security gaps promptly. Users should be vigilant and monitor their systems for unusual activity while applying any available patches or updates. The incident serves as a reminder of the ongoing risks associated with third-party software vulnerabilities.

Impact: SolarWinds Web Help Desk instances
Remediation: Organizations should apply any available patches or updates from SolarWinds and monitor their systems for unauthorized access.
Read Original
PreviousPage 126 of 218Next