A new malware called RustDuck is actively hijacking various devices, including home routers, IP cameras, Android boxes, and poorly secured servers. The malware operates in two stages and connects these compromised devices into a botnet designed to launch Distributed Denial of Service (DDoS) attacks, effectively taking websites and online services offline. Researchers from QiAnXin's XLab have been monitoring RustDuck since February 2026 and note that its rapid evolution is particularly concerning. This highlights the vulnerability of consumer devices and poorly secured servers, which can be easily exploited by attackers. Users and organizations need to ensure their devices are secured to prevent becoming part of such a botnet.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Hackread – Cybersecurity News, Data Breaches, AI and More
A new phishing technique known as EvilTokens is raising concerns among security operations centers (SOCs) due to its ability to conceal account takeover indicators until the attack is executed within a browser. This tactic complicates the detection of threats, leaving SOC teams struggling to validate risks quickly. As a result, organizations may face increased vulnerability to account takeovers, putting sensitive information at risk. The need for enhanced visibility into browser activity is becoming clearer, highlighting a gap in current security measures that companies need to address to protect their users and data. This incident emphasizes the ongoing challenges faced by enterprises in maintaining security in an evolving cyber environment.
SCM feed for Latest
The article discusses the growing reliance on AI for writing code and the security vulnerabilities that can arise from this practice. Researchers have found that AI-generated code often contains flaws and security weaknesses that can be exploited by attackers. This is a concern for developers and companies who use these tools, as insecure code can lead to data breaches and other serious security incidents. The article emphasizes the importance of reviewing and testing AI-generated code before deployment to mitigate risks. With more organizations adopting AI for software development, understanding these potential security pitfalls is crucial.
Researchers have discovered that attackers are exploiting a serious vulnerability in Langflow, identified as CVE-2026-33017, which has a CVSS score of 9.3. This flaw allows for unauthenticated remote code execution (RCE), making it a prime target for cybercriminals. In recent attacks, these hackers have been using the vulnerability to deploy a Monero cryptocurrency miner on exposed AI application endpoints. Organizations using Langflow need to be particularly vigilant as the vulnerability is actively being exploited. This situation underscores the critical need for timely updates and security measures to protect sensitive systems from unauthorized access.
Attackers have taken advantage of a serious vulnerability in SimpleHelp's remote management tool to deliver malware, specifically TaskWeaver and Djinn Stealer. This exploit allows the malware to infiltrate systems that utilize SimpleHelp, which is commonly used for remote support and management. The incident poses a significant risk to organizations relying on this software, as it could lead to unauthorized access and data theft. Users and companies are urged to assess their systems and apply any necessary patches or updates to mitigate the threat. The exploitation of this vulnerability highlights the ongoing risks associated with remote management tools in the current cybersecurity environment.
Nissan Americas has been impacted by a significant data breach linked to a zero-day vulnerability in Oracle’s PeopleSoft software, identified as CVE-2026-35273. This vulnerability has led to a series of attacks, with researchers connecting it to a group known as UNC6240, which is believed to be exploiting the weakness. The breach raises serious concerns about the security of sensitive employee information and operational data within Nissan Americas and potentially other organizations using the same software. As attackers continue to exploit this vulnerability, affected companies must act quickly to secure their systems and protect their data from further unauthorized access.
Aikido Security has acquired Root to enhance its efforts in addressing vulnerabilities in open source software. This move is part of a broader initiative to help developers and organizations mitigate risks associated with supply chain attacks, which have increased as open source components are widely used in applications. With attackers often embedding malware in these packages, the collaboration aims to streamline the process of implementing backported fixes for known vulnerabilities. By combining their resources, Aikido and Root hope to fortify the security of open source software, which is foundational to modern applications. This acquisition is significant for organizations that rely on open source, as it directly addresses the growing threat of compromised software packages.
Business Email Compromise (BEC) is a significant cybersecurity issue that goes beyond simple email scams. It involves sophisticated operations where attackers compromise email accounts, conduct financial research, and utilize cash-out networks to steal money from businesses. Research into underground forums reveals the methods and strategies used by these attackers, emphasizing the need for companies to be vigilant. The impact of BEC is widespread, affecting organizations of all sizes and sectors, as it can lead to substantial financial losses. Understanding how these attacks are planned and executed is crucial for businesses to develop effective defenses against them.
The Microsoft Defender vulnerability identified as CVE-2026-33825 has been actively exploited in ransomware attacks before any patches were made available. This zero-day vulnerability poses a significant risk to users of Microsoft Defender, as attackers have been able to take advantage of this flaw to deploy ransomware. The situation is urgent, as organizations using this security software may find themselves vulnerable to data breaches and financial loss. Experts strongly recommend that all users of Microsoft Defender remain vigilant and apply any available security updates as soon as they are released to mitigate potential risks. Immediate action is crucial to protect sensitive information from being compromised by malicious actors.
SCM feed for Latest
An anonymous researcher has released zero-day exploits for several software products, raising concerns among users and developers. Notably, a critical vulnerability in libssh2 (CVE-2026-55200) allows attackers to execute code remotely without authentication. Additionally, a flaw in self-hosted Gitea Docker deployments (CVE-2026-20896) permits authentication bypass, enabling attackers to impersonate users and potentially take over Git servers. This incident is significant as it exposes serious weaknesses in widely used software, which could lead to unauthorized access and data breaches if not addressed promptly. Organizations using these products should be vigilant and take immediate steps to secure their systems.
SCM feed for Latest
Cyber threat intelligence provider WhoisXML API has reported a surge in newly registered domains related to the recent earthquake in Venezuela, with 212 domains registered between June 24 and June 28, 2026. This spike raises concerns about potential online scams or phishing attempts, as attackers often take advantage of natural disasters to exploit unsuspecting users. Individuals looking for information or assistance after the earthquake may inadvertently visit these malicious sites. It's crucial for users to be cautious and verify the legitimacy of websites before providing any personal information or clicking on links. This incident underscores the need for heightened awareness during crises, as cybercriminals are quick to capitalize on public interest and vulnerability.
The Financial Times reports on how artificial intelligence is transforming video surveillance capabilities, particularly in regions like Israel, Iran, and Russia. Unlike traditional surveillance systems that rely on limited preset searches, new AI tools allow users to ask natural language questions about video footage. This advancement significantly enhances the ability to analyze and interpret vast amounts of video data. The implications are profound, as these technologies could facilitate mass surveillance and monitoring, raising concerns about privacy and civil liberties. As AI continues to evolve, the potential for misuse in state and corporate surveillance becomes a critical issue that demands attention.
The Hacker News
A new security vulnerability, CVE-2026-48558, has been identified in SimpleHelp, a remote support software. This critical flaw, which has a maximum severity score of 10.0, allows attackers to bypass authentication during the OpenID Connect (OIDC) flow. As a result, these attackers have been exploiting this weakness to deploy two malware families: TaskWeaver and Djinn Stealer. The situation poses significant risks for users of SimpleHelp, as the malware could lead to data theft and further system compromises. Organizations using this software should take immediate action to secure their systems against this ongoing threat.
Aflac, the American insurance company, has revealed a data breach involving its subsidiary in Japan. Attackers gained unauthorized access to the subsidiary's systems, resulting in the theft of personal and bank account information belonging to customers. This incident raises significant concerns about the security of sensitive data, especially in the financial sector, where trust is paramount. Aflac has not disclosed the exact number of customers affected, but the breach could impact many individuals who rely on their services. As companies increasingly face cyber threats, this incident serves as a reminder for organizations to prioritize data security measures and protect their clients' information.
Hackread – Cybersecurity News, Data Breaches, AI and More
WhatsApp is preparing to roll out a new feature that allows users to reserve usernames, enabling them to chat without needing to share their phone numbers. This feature is set to launch in 2026, and users can start reserving their usernames now. The move aims to enhance privacy, giving users an alternative way to connect without exposing their personal contact information. However, while this could improve privacy for many, there are still security considerations to keep in mind, such as the risks of impersonation and the need for strong username management. As users begin to adopt this feature, it will be important for WhatsApp to implement strong security measures to protect these usernames and the privacy of its users.