Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Huntress has reported an ongoing attack exploiting vulnerabilities in SolarWinds Web Help Desk software. Attackers are targeting unpatched versions of this tool to execute remote code, which allows them to install Zoho ManageEngine software for persistent access and Velociraptor for control over compromised systems. This incident was confirmed on February 7, 2026, and it raises significant concerns for organizations that rely on SolarWinds products, as it highlights the risks associated with unaddressed software vulnerabilities. Companies using this software should prioritize patching to safeguard against these exploits and prevent unauthorized access to their systems.

Impact: SolarWinds Web Help Desk, Zoho ManageEngine, Velociraptor
Remediation: Organizations should update to the latest patched versions of SolarWinds Web Help Desk to mitigate these vulnerabilities.
Read Original

SmarterTools has reported a ransomware attack that compromised a data center used for quality control testing. The breach occurred due to a vulnerability in one of SmarterTools' own products, which allowed hackers to infiltrate their systems. As a result, customers have been affected, although specific details on the extent of the impact have not been disclosed. This incident raises concerns about the security of software products, especially those used in business environments. Companies using SmarterTools' services should review their security measures and remain vigilant for any unusual activity.

Impact: SmarterTools products, data center operations
Remediation: Customers should review their security protocols and monitor for unusual activity. Specific patches or updates were not mentioned.
Read Original

Two men from Connecticut have been charged with defrauding FanDuel and other online gambling sites out of approximately $3 million by using the stolen identities of around 3,000 individuals. This scheme involved creating fake accounts on these platforms to place bets and withdraw winnings. The accused allegedly operated this scam for several years, taking advantage of the online gambling system's vulnerabilities. This incident is a stark reminder of the risks associated with identity theft and online gambling, as it shows how easily personal information can be exploited for financial gain. The fallout from such fraudulent activities can lead to financial losses for both the victims and the companies involved, highlighting the need for better identity verification processes in online services.

Impact: FanDuel, online gambling sites
Remediation: Improved identity verification processes for online gambling platforms
Read Original

BeyondTrust has addressed a serious remote code execution vulnerability, identified as CVE-2026-1731, which affects its Remote Support (RS) and Privileged Remote Access (PRA) solutions. This vulnerability can be exploited without authentication, making it particularly dangerous for self-hosted customers. BeyondTrust is urging users to apply the patch immediately to protect their systems. Unlike a previous zero-day vulnerability exploited by threat actors linked to China, this issue was discovered by a security researcher and disclosed privately. The prompt action by BeyondTrust highlights the necessity for timely vulnerability management in remote access tools, which are critical for many organizations.

Impact: BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) solutions.
Remediation: BeyondTrust has released a patch for CVE-2026-1731. Self-hosted customers are urged to apply this patch as soon as possible.
Read Original

BridgePay, a payments platform based in Florida, has confirmed that its services are currently offline due to a ransomware attack. While the company has been affected by this incident, it has reassured users that no card data has been compromised during the attack. The disruption highlights the ongoing risks that payment processing companies face from cybercriminals. As users rely on these platforms for financial transactions, the incident raises concerns about the security measures in place to protect sensitive information. BridgePay is working to restore its services while ensuring the safety of its users' data.

Impact: BridgePay payment processing services
Remediation: N/A
Read Original

The article discusses the challenges of AI security, emphasizing that the vulnerabilities lie beyond just cloud infrastructure. Instead, the real risks come from the complex web of supply chains, agents, and human interactions that support AI systems. This means that organizations need to focus on securing these interconnected elements to prevent potential attacks. As AI becomes more integrated into various sectors, the need for comprehensive security measures that address these broader vulnerabilities is critical. Companies must recognize that traditional security practices may not be sufficient to protect against sophisticated threats targeting these components.

Impact: N/A
Remediation: N/A
Read Original

A cybercriminal group known as Bloody Wolf is targeting organizations in Uzbekistan and Russia with a spear-phishing campaign designed to deploy a remote access trojan called NetSupport RAT. This group, which has been active since at least 2023, is focusing its attacks on the manufacturing, finance, and IT sectors. Kaspersky, a cybersecurity firm, is tracking this activity under the name Stan Ghouls. The use of spear-phishing indicates that the attackers are likely customizing their messages to trick specific individuals or organizations into downloading the malicious software. This type of threat can lead to significant data breaches and operational disruptions for the affected companies, making it crucial for them to enhance their email security and user awareness training.

Impact: NetSupport RAT, manufacturing, finance, IT sectors
Remediation: Enhance email security, implement user awareness training, and monitor for unusual system activity.
Read Original

Microsoft is currently investigating an issue with Exchange Online that incorrectly identifies legitimate emails as phishing attempts, leading to their quarantine. Users of Exchange Online are facing disruptions as important emails may be blocked or filtered out. This problem raises concerns about email security and the reliability of filtering systems, as it could hinder communication and operations for businesses relying on this service. Microsoft has not yet provided a timeline for resolving the issue, leaving users uncertain about when they can expect a fix. This situation emphasizes the need for effective email security measures and accurate detection systems to prevent legitimate correspondence from being flagged incorrectly.

Impact: Exchange Online
Remediation: N/A
Read Original

The European Commission has confirmed a data breach linked to its mobile device management platform, prompting an investigation into the incident. While specific details about the number of affected staff or the nature of the exposed data have not been released, the breach raises concerns about the security of sensitive information held by the Commission. This incident is particularly significant given the Commission's role in managing policies and regulations across the European Union. Officials are working to understand the scope of the breach and are likely to implement measures to prevent future incidents. The situation underscores the ongoing challenges organizations face in protecting their data against cyber threats.

Impact: Mobile device management platform of the European Commission
Remediation: N/A
Read Original

Researchers from SecurityScorecard have discovered that over 40,000 instances of OpenClaw, a software tool, are exposed to potential attacks. This exposure raises significant security concerns, as it could allow attackers to exploit these deployments for unauthorized access or data breaches. OpenClaw is used in various applications, and organizations relying on it need to ensure their systems are secure. The large number of exposed instances suggests that many users may not be aware of the vulnerabilities associated with their deployments. Companies should prioritize reviewing their OpenClaw configurations and take steps to secure their systems against possible exploitation.

Impact: OpenClaw deployments
Remediation: Organizations should review their OpenClaw configurations and implement necessary security measures to protect against potential attacks.
Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that all federal agencies must decommission any edge devices that are no longer supported within the next 12 months. This directive aims to mitigate risks associated with these outdated devices, which are more susceptible to exploitation by cyber attackers. End of support devices lack critical security updates, making them a target for those looking to breach federal networks. By enforcing this rule, CISA is taking proactive steps to enhance the security posture of government systems and protect sensitive data from potential threats. Agencies must now prioritize replacing or upgrading these devices to comply with the new directive and safeguard their networks.

Impact: End of support edge devices used by federal agencies
Remediation: Decommission all end of support edge devices within 12 months.
Read Original

Romania’s national oil pipeline operator, Conpet, recently experienced a cyberattack that disrupted its business systems and caused its website to go offline temporarily. As a state-controlled company responsible for transporting crude oil and liquid petroleum products, any disruption in its operations can have significant implications for the country's energy supply. The incident highlights the vulnerabilities that critical infrastructure companies face, especially in the current digital landscape where such attacks are increasingly common. While Conpet has not disclosed specific details about the attack or the extent of the damage, the incident raises concerns about the security measures in place to protect essential services from cyber threats.

Impact: Conpet's business systems and website
Remediation: N/A
Read Original

Researchers have identified a significant cyber campaign known as the TeamPCP worm, which has been targeting cloud-native environments since late December 2025. This worm exploits vulnerabilities in widely used technologies, including exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers. By hijacking these services, attackers are able to create a malicious infrastructure for further exploitation. This situation is alarming as it can potentially affect numerous organizations that rely on these cloud services for their operations. Companies need to ensure their cloud environments are properly secured against such vulnerabilities to prevent unauthorized access and data breaches.

Impact: Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers
Remediation: Organizations should secure their Docker APIs and Kubernetes clusters, apply the latest security patches, and implement strict access controls to mitigate unauthorized access.
Read Original

The European Commission is currently investigating a potential cyberattack that has targeted its mobile device management systems. Initial indications suggest that unauthorized access may have occurred, raising concerns about the security of sensitive data managed by the EU's main executive body. This incident could have implications for the integrity of communications and operations within the EU, particularly as cyber threats continue to evolve. The investigation aims to determine the extent of the breach and implement necessary security measures to protect against future attacks. As the situation develops, the EU will likely increase its focus on cybersecurity protocols to safeguard its systems and data.

Impact: EU mobile device management systems
Remediation: N/A
Read Original
UK Construction Firm Hit by Prometei Botnet Hiding in Windows Server

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

A UK construction firm has fallen victim to an attack by the Russian Prometei botnet, as detailed by cybersecurity firm eSentire. The attack involved the use of TOR for anonymity, and attackers focused on stealing passwords and employing decoy tactics to mislead security measures. This incident raises concerns about the security of critical infrastructure in the construction sector, which may not be as fortified against cyber threats as other industries. The implications are significant, as compromised systems can lead to operational disruptions and financial losses for businesses. Companies in similar sectors should take note and assess their own cybersecurity defenses to prevent similar attacks.

Impact: UK construction firm's Windows Server systems
Remediation: Implement strong password policies, enhance network monitoring, and consider using intrusion detection systems.
Read Original
PreviousPage 127 of 218Next