Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A newly discovered vulnerability in React Native has been exploited in the wild, allowing attackers to disable security protections and deliver malware to affected devices. This flaw, which was previously thought to be a theoretical risk, has now raised alarms among developers and users of applications built with React Native. The impact of this vulnerability can be significant, as it compromises the integrity and security of applications, potentially affecting millions of users. Developers are urged to take immediate action to secure their applications and protect user data from malicious exploitation.

Impact: React Native applications, including those developed by various companies using this framework.
Remediation: Developers should apply security patches provided by React Native, review their application code for vulnerabilities, and enhance security measures to prevent unauthorized access. Regularly updating to the latest versions of React Native is also advised.
Read Original
Actively Exploited

Researchers have identified a new ransomware-as-a-service (RaaS) variant known as 'Vect'. This operation stands out due to its custom malware, which poses a significant threat to organizations. The Vect RaaS allows attackers to easily deploy ransomware attacks, potentially affecting a wide range of victims, from small businesses to larger enterprises. The introduction of this variant raises concerns about the increasing sophistication of ransomware operations, making it crucial for companies to bolster their cybersecurity measures. Users are advised to stay vigilant and regularly update their security protocols to defend against such evolving threats.

Impact: Organizations utilizing outdated cybersecurity measures and systems.
Remediation: Organizations should implement strong security protocols, regular software updates, and employee training on phishing and ransomware prevention.
Read Original

A serious security vulnerability, identified as CVE-2025-11953 and nicknamed Metro4Shell, has been discovered in the Metro Development Server, which is part of the '@react-native-community/cli' npm package. This flaw, rated 9.8 on the CVSS scale, allows remote attackers to execute arbitrary code without authentication. Researchers from VulnCheck first detected active exploitation of this vulnerability on December 21, 2025. This poses a significant risk for developers and organizations using this package, as it could lead to unauthorized control over their systems. Users of the affected npm package need to take immediate action to protect their applications.

Impact: Metro Development Server in the '@react-native-community/cli' npm package.
Remediation: Developers should update their '@react-native-community/cli' package to the latest version to mitigate the vulnerability. They should also review their server configurations and implement security best practices to limit exposure to such attacks.
Read Original

A vulnerability has been discovered in OpenClaw, also known as Moltbot and Clawdbot, which allows attackers to execute remote code with just one click. This flaw poses a significant risk as it could enable hackers to take control of the AI assistant, potentially compromising user data and system integrity. The issue affects users of OpenClaw across various platforms, raising concerns about the security of AI tools that are increasingly integrated into everyday applications. It's essential for users and organizations to be aware of this vulnerability and take necessary precautions to protect their systems. The situation underscores the need for vigilance in managing software vulnerabilities, particularly in AI technologies that handle sensitive information.

Impact: OpenClaw, Moltbot, Clawdbot
Remediation: Users should apply any available patches or updates for OpenClaw and consider disabling the AI assistant until a fix is confirmed.
Read Original

On April 20, 2026, the Cybercrime Unit of Paris prosecutors conducted a raid on the offices of Elon Musk's social media platform, X, in France. This action came after both Musk and the former CEO of X were summoned for voluntary interviews regarding unspecified issues related to the platform. While details about the nature of the investigation remain unclear, the involvement of high-profile individuals like Musk suggests significant implications for the company's operations and legal standing. The situation raises questions about compliance with local laws and regulations, particularly in the realm of cybersecurity and user data protection. This incident underscores the increasing scrutiny on tech companies operating in Europe, especially concerning their responsibilities towards user privacy and security.

Impact: X social media platform
Remediation: N/A
Read Original

French prosecutors have conducted a raid on the offices of X, formerly known as Twitter, in Paris as part of a criminal investigation into the platform's Grok AI tool. This tool has been implicated in the creation of sexually explicit deepfake images, raising serious concerns about its misuse. The investigation has also led to a summons for Elon Musk, the owner of X, indicating the gravity of the situation. The use of AI to generate harmful content poses significant ethical and legal challenges, particularly regarding consent and the potential for exploitation. This incident not only highlights the risks associated with AI technologies but also places pressure on social media companies to implement stricter regulations and safeguards.

Impact: Grok AI tool, X platform
Remediation: N/A
Read Original
Everest Ransomware Claims 90GB Data Theft Involving Legacy Polycom Systems

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

Everest ransomware has claimed responsibility for a data breach involving legacy Polycom systems, which are now part of HP Inc. The attackers allege that they have stolen 90GB of internal data from these systems. This incident raises concerns about the security of older technology that may not receive regular updates or patches, leaving them vulnerable to exploitation. Organizations using such legacy systems should assess their security measures and consider upgrading to more secure solutions. The breach not only threatens sensitive internal information but also highlights the risks associated with maintaining outdated technology in a rapidly evolving cybersecurity landscape.

Impact: Legacy Polycom systems, HP Inc.
Remediation: Organizations should assess their security measures for legacy systems and consider upgrading to more secure solutions.
Read Original
Everest Ransomware Claims 90GB Data Theft From HP Inc’s Polycom Systems

Hackread – Cybersecurity News, Data Breaches, AI, and More

Everest ransomware has claimed responsibility for a data breach affecting legacy Polycom systems owned by HP Inc. The attackers allege that they have stolen around 90GB of internal data. HP has yet to confirm the breach or provide details about the incident. This situation raises concerns about the security of legacy systems, which often have vulnerabilities that can be exploited by cybercriminals. As organizations increasingly rely on such systems, the potential for significant data theft becomes a pressing issue that companies need to address.

Impact: Polycom systems under HP Inc.
Remediation: N/A
Read Original

Recent outages at major cloud service providers like AWS, Azure, and Cloudflare have significantly disrupted internet services, affecting countless websites and applications. These incidents caused widespread interruptions for businesses and consumers who rely on these platforms for daily operations. Not only did users face difficulties accessing services, but many organizations found their workflows halted as a result of the outages. The ripple effects of these disruptions highlight the interconnected nature of online services and the vulnerabilities that can arise from relying on a few key providers. As outages become more frequent, understanding their impact is crucial for organizations that depend on cloud infrastructure.

Impact: AWS, Azure, Cloudflare, various websites and applications
Remediation: Organizations should evaluate their cloud dependencies and consider diversifying their service providers to reduce risk.
Read Original

Rob Allen discusses the rising concern of malware that utilizes large language models (LLMs) to enhance its effectiveness. These AI-assisted attacks pose a significant risk to both individuals and organizations, as they can automate and refine the process of creating malicious content. Allen emphasizes the need for proactive cybersecurity measures, urging companies to stay ahead of potential threats by implementing advanced detection tools and employee training. The article serves as a warning that as technology evolves, so too do the tactics employed by cybercriminals, making it essential for businesses to adapt their defenses accordingly. This is a call to action for organizations to prioritize cybersecurity and prepare for the challenges posed by AI-driven malware.

Impact: N/A
Remediation: Implement advanced detection tools and conduct employee training on recognizing AI-assisted threats.
Read Original

The manufacturing industry in the U.S. is facing increasing cybersecurity threats, particularly from intensified cyberattacks believed to be originating from China. In response to these growing risks, manufacturing firms are coming together to strengthen their cybersecurity efforts through the Manufacturing Information Sharing and Analysis Center (ISAC). This collaboration aims to enhance the sharing of information about potential threats and vulnerabilities among companies within the sector. As critical infrastructure becomes more targeted by malicious actors, these partnerships are essential for protecting sensitive data and ensuring operational continuity. The move reflects a recognition that collective defense strategies are crucial in combating sophisticated cyber threats.

Impact: Manufacturing sector, critical infrastructure
Remediation: N/A
Read Original

Tulsa International Airport has reportedly been compromised by the Qilin ransomware group, which claims to have stolen more than a dozen files from the airport's internal systems. This incident raises concerns about the security of critical infrastructure, as airports handle sensitive data and operations that are vital for public safety and travel. The breach could potentially disrupt airport operations or expose personal information of employees and travelers. As ransomware attacks continue to target essential services, this incident serves as a reminder for organizations to bolster their cybersecurity measures against increasing threats from cybercriminals. The situation is still developing, and further details regarding the extent of the breach and its implications are awaited.

Impact: Tulsa International Airport internal network systems
Remediation: N/A
Read Original

Iranian hackers have utilized artificial intelligence to carry out cyberattacks targeting individuals and organizations that have reported on human rights abuses amid ongoing protests in the country. This campaign, known as RedKitten, aims to intimidate and silence voices critical of the Iranian government. The use of large language models in these attacks indicates a shift in tactics, as attackers look to enhance their capabilities in spreading misinformation and conducting surveillance. Those affected include non-governmental organizations, activists, and journalists who are documenting the protests and human rights violations. This development raises significant concerns about the intersection of technology and state-sponsored aggression, particularly in how it can stifle dissent and manipulate narratives during critical social movements.

Impact: Individuals and non-governmental organizations reporting human rights abuses in Iran.
Remediation: Organizations should enhance their cybersecurity measures, including employee training on recognizing phishing attempts and employing robust monitoring tools to detect unusual activities.
Read Original
Actively Exploited

Recent reports indicate that several threat groups, including UNC6661, UNC6671, and UNC6240, have intensified their cyber attacks under the ShinyHunters name. These attacks primarily target cloud-based software-as-a-service (SaaS) applications, employing tactics such as voice phishing and creating fake websites to steal user credentials. This surge in extortion-themed intrusions poses a significant risk to organizations relying on SaaS platforms, as attackers aim to exploit vulnerabilities for financial gain. Businesses and users need to be vigilant about potential phishing attempts and ensure their security practices are up to date to safeguard sensitive information.

Impact: Cloud-based software-as-a-service (SaaS) applications
Remediation: Users should verify the legitimacy of communications and avoid sharing sensitive information over untrusted channels. Implementing multi-factor authentication (MFA) may also help mitigate risks.
Read Original

A Chinese-speaking cybercrime group known as UAT-8099 has been attacking unsecured Internet Information Services (IIS) servers across Asia, with a focus on Thailand and Vietnam. This campaign started late last year and has raised concerns among cybersecurity experts. The attackers are exploiting vulnerabilities in these servers, which could lead to unauthorized access and data breaches. Organizations using IIS servers in the targeted regions need to prioritize their security measures to prevent exploitation. The ongoing attacks highlight the risks associated with unprotected web servers, especially in areas where cybersecurity practices may not be as stringent.

Impact: Internet Information Services (IIS) servers in Thailand and Vietnam
Remediation: Organizations should secure their IIS servers by applying the latest security patches, configuring firewalls, and implementing strong access controls.
Read Original
PreviousPage 135 of 219Next