A new bill proposed by Senator Mark Warner aims to establish a federally vetted registry for AI agent software. This registry would be managed by the Federal Trade Commission (FTC) and would certify the privacy and cybersecurity measures of AI software sellers. The goal is to ensure that consumers and businesses can identify trustworthy AI agents that adhere to strict security standards. By creating this list, the bill seeks to enhance accountability in the AI industry, addressing growing concerns about data privacy and the potential risks associated with AI technologies. This initiative reflects a proactive approach to regulating a rapidly evolving field and aims to protect users from potential security breaches linked to AI applications.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Hackread – Cybersecurity News, Data Breaches, AI and More
Following the recent earthquake in Venezuela, researchers identified 212 newly registered domains that could be linked to donation scams. These domains are likely set up to take advantage of people's goodwill in the aftermath of the disaster. Experts are warning potential donors to be cautious and to verify the legitimacy of any relief sites before contributing. This situation underscores the need for vigilance when it comes to online donations, especially during crises when scammers often exploit public sympathy. Ensuring that donations go to reputable organizations can help prevent fraud and ensure that aid reaches those in need.
A researcher has identified several vulnerabilities in Indian government systems, with one particularly alarming flaw that could have allowed unauthorized users to take control of a national government portal. This breach raises serious concerns about the security of sensitive government data and the potential for misuse by malicious actors. If exploited, these vulnerabilities could compromise personal information of citizens and disrupt essential government services. The findings emphasize the need for immediate action to secure these systems and protect public data from potential breaches. As the situation develops, it is crucial for the government to address these vulnerabilities swiftly to maintain public trust and ensure the safety of its digital infrastructure.
Recent reports indicate that state-sponsored hackers from Iran, Russia, and China are targeting water systems worldwide. These attackers are exploiting weak passwords, poorly configured programmable logic controllers (PLCs), and inadequate network segmentation to gain access. Notably, they are not using advanced malware but rather taking advantage of basic security oversights. This poses a significant risk to critical infrastructure, as water systems are essential for public health and safety. The findings underscore the need for better cybersecurity practices within these vital sectors to prevent potential sabotage and ensure the reliability of water services.
WhatsApp has introduced a new feature that allows users to create usernames, enabling them to keep their phone numbers private from individuals who are not in their contact lists. This update aims to enhance user privacy, particularly in conversations with strangers or in group chats. With this change, users can interact without revealing their phone numbers, which can help reduce the risk of unwanted contacts and potential harassment. The rollout of usernames is a significant step for WhatsApp, as it aligns with growing demands for better privacy measures in messaging apps. Users should consider adopting this feature to enhance their security and maintain greater control over their personal information.
The Supreme Court recently issued a ruling in the Chatrie case that is seen as a significant victory for technology privacy rights. Dissenting justices warned that this decision could lead to major changes in how the Fourth Amendment is interpreted, particularly regarding digital privacy and law enforcement's ability to access personal data. This ruling could impact how tech companies manage user data and how law enforcement conducts investigations. It raises important questions about the balance between privacy rights and public safety, making it a pivotal moment in the ongoing debate over digital privacy.
WhatsApp has introduced a new feature allowing users to reserve usernames, which aims to enhance privacy for its more than three billion users. This optional feature enables individuals to connect with each other using usernames instead of sharing their phone numbers directly. The rollout of username reservations began on Monday, giving users a way to maintain their privacy while using the messaging service. This change is particularly significant as it reflects growing concerns about personal data exposure in digital communications. By providing an alternative to phone numbers, WhatsApp is responding to user demands for increased security and anonymity in their interactions.
SCM feed for Latest
A recent phishing campaign is targeting hotels in Europe and Asia by using deceptive emails that reference common operational issues, such as guest complaints and health inspections. The attackers employ a Node.js implant to execute their malicious activities. Microsoft has not linked this campaign to any known threat actor, making it difficult to predict future attacks. The phishing email lures are designed to exploit hotel staff's urgency to resolve these issues, potentially leading to compromised systems and data breaches. This incident serves as a reminder for hospitality businesses to remain vigilant against phishing attempts that exploit everyday concerns.
The U.S. Department of State is offering a reward of up to $10 million for information leading to the identification or location of hackers associated with two groups, UNC5792 and UNC4221. These groups are believed to have ties to Russian intelligence and military services and have been targeting users of encrypted messaging platforms like WhatsApp and Signal. This move underscores the ongoing concern about cyber threats to secure communication channels, particularly as more people rely on these platforms for private conversations. By incentivizing information about these hackers, the U.S. aims to disrupt their operations and enhance the security of messaging services used by millions. The reward reflects the seriousness of the threat posed by these groups and the need for collaboration in addressing cybercrime on a global scale.
This week, a new vulnerability named DirtyClone was discovered in the Linux kernel, allowing local attackers to escalate privileges. This flaw emphasizes how even minor oversights, such as unpatched vulnerabilities or outdated access paths, can lead to significant security breaches. The threat is particularly concerning for users of affected Linux distributions, as attackers could potentially exploit this vulnerability to gain unauthorized access to sensitive systems. Additionally, discussions are underway in various forums about other emerging threats, including AI-driven malware tactics and the Turla backdoor, which could further complicate the security landscape. Organizations are urged to stay vigilant and apply necessary updates to protect against these risks.
A new campaign involving the Millenium RAT, a remote access trojan, has reportedly affected over 62,000 devices across more than 160 countries. Researchers from Group-IB have identified that the malware has been rewritten in C++, making it more sophisticated and harder to detect. This malware primarily spreads through Telegram, which has raised concerns about the platform being exploited for malicious purposes. Users of various devices are at risk, as the trojan could allow attackers to gain unauthorized access and control over their systems. This incident underscores the need for users to be vigilant about the software they install and the links they click, particularly in messaging applications.
The article discusses the growing security risks associated with AI agents in enterprise systems. These AI agents have the ability to access sensitive data and perform actions across different platforms, which makes them a valuable target for attackers. Token Security emphasizes that as organizations increasingly rely on these AI tools, the importance of managing and securing their identities becomes critical. Failure to do so could lead to unauthorized access and data breaches, potentially compromising the entire enterprise infrastructure. It is essential for companies to implement robust identity governance strategies to mitigate these risks and protect their systems.
Hackers are taking advantage of a serious vulnerability (CVE-2026-48558) in SimpleHelp, a remote support software, to deploy a new type of malware known as Djinn Stealer. This malware is capable of stealing information across multiple operating systems, including Windows, macOS, and Linux. Users of SimpleHelp are at risk as the flaw allows attackers to infiltrate systems and extract sensitive data without detection. The emergence of this undocumented malware raises concerns about the security of remote support tools, as they are commonly used by businesses and individuals for remote access. It is crucial for users to remain vigilant and apply any necessary updates to protect their information.
Hackers are actively exploiting a serious vulnerability, identified as CVE-2026-46817, in the Oracle E-Business Suite (EBS) financial application. This flaw poses a significant risk to businesses using the software, as it allows unauthorized access to sensitive financial data. Threat intelligence firm Defused reported that the attacks are already underway, making it crucial for organizations to take immediate action to protect their systems. Users of Oracle EBS should prioritize updating their software and implementing any available security patches to mitigate the risk of exploitation. The urgency of this situation highlights the ongoing need for vigilance in cybersecurity practices, especially for widely used enterprise applications.
Hackread – Cybersecurity News, Data Breaches, AI and More
Cybersecurity firm Cyberbit has decided to shut down its operations in Israel and will be laying off local employees. This decision comes as the company shifts its focus primarily to the US market following its acquisition of RangeForce. Cyberbit, which was originally a spin-off from Elbit Systems, has been transitioning its business strategy to align with growing opportunities in the US cybersecurity landscape. The move raises concerns about job losses and the impact on the local tech ecosystem in Israel, a country known for its robust cybersecurity industry. As Cyberbit consolidates its resources, it reflects broader trends in the cybersecurity sector, where companies are increasingly looking to the US for growth.