Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A phishing campaign has been preying on hotels and hospitality organizations in Europe and Asia since April 2026, according to Microsoft. The attackers use ZIP files disguised as photo attachments to deliver a Node.js implant, targeting front-desk computers. While Microsoft has not linked this activity to any known threat actor, the exact objectives of the attackers remain unclear. This type of attack is particularly concerning because it exploits the routine operations of hotels, potentially compromising sensitive guest information and operational systems. Organizations in the hospitality sector need to be vigilant and enhance their security measures to protect against such targeted phishing attempts.

Read Original

A Russian advanced persistent threat (APT) group known as Turla has been using a new backdoor called 'StockStay' to target Ukrainian government and military organizations. This espionage campaign aims to gather sensitive information amidst the ongoing conflict in Ukraine. The backdoor allows attackers to maintain persistent access to compromised systems, facilitating data theft and surveillance. The situation raises significant concerns about the security of vital governmental infrastructure and the potential for further cyberattacks as tensions in the region continue to escalate. Ukrainian authorities and cybersecurity experts are urged to enhance their defenses against this ongoing threat.

Read Original

The UK Cyber Monitoring Centre has released an analysis regarding the recent data breach involving Canvas, which has impacted 160 universities across the UK. This breach raises significant concerns about the theft of sensitive data and the financial repercussions for the affected institutions. The analysis indicates that the breach could lead to various risks, including compromised personal information of students and staff. Universities are urged to enhance their cybersecurity measures to prevent further incidents. This situation serves as a stark reminder of the vulnerabilities in educational technology platforms and the need for robust security protocols.

Read Original

Poland's Central Bureau for Combating Cybercrime has arrested four individuals linked to a SIM-swapping gang involved in stealing cryptocurrency and laundering money. This crackdown was part of a coordinated effort that included the FBI and Homeland Security Investigations. The suspects are accused of orchestrating SIM swap attacks, a technique where attackers take control of a victim's phone number to access sensitive accounts. The operation is still ongoing, with the Regional Prosecutor’s Office in Kraków overseeing the investigation. This incident underscores the persistent threat of organized cybercrime and the international cooperation needed to combat it effectively.

Read Original

The article discusses the privacy concerns associated with using public malware analysis platforms like VirusTotal and MalwareBazaar. When users submit suspicious files to these services, they become accessible to others, including the original authors of the malware. This can allow malicious actors to track the presence of their tools and potentially adapt them to evade detection. Analysts often rely on these platforms for quick assessments, but the trade-off is that sensitive data may be exposed. The piece advocates for a more privacy-focused approach to malware analysis, emphasizing the need for local solutions that do not share files publicly.

Read Original
Actively Exploited

Polish authorities have arrested four individuals linked to a cybercrime group responsible for SIM-swapping attacks that reportedly led to millions of dollars in cryptocurrency theft. The gang is accused of infiltrating telecommunications companies and hijacking email accounts to facilitate these attacks. SIM swapping involves taking control of a victim's phone number, allowing attackers to access sensitive information and accounts. This incident highlights the ongoing risks associated with SIM swapping, particularly in the cryptocurrency space, where such breaches can lead to significant financial losses for individuals and businesses alike. The arrests aim to disrupt these types of cybercrimes and protect potential victims from future attacks.

Read Original

The new Model Context Protocol (MCP) specification, version 2026-07-28, aims to improve security for developers by eliminating certain protocol-level risks seen in previous versions. Key changes include the removal of stateful initialization and server-initiated prompts, which have been identified as vulnerabilities. The specification now requires the use of OAuth 2.1, enhancing the overall security of authentication processes. While these updates strengthen security, they also introduce new challenges for developers who must adapt their systems to comply with the latest standards. As developers implement these changes, they need to be aware of potential pitfalls and ensure their applications are secure against new risks that may arise from the transition.

Read Original

In a recent discussion, cybersecurity expert Sandy Bird addressed the challenges of maintaining cloud visibility and the risks associated with vulnerabilities like FortiBleed. This specific flaw affects Fortinet's FortiOS and FortiProxy, which are widely used in enterprise environments. If exploited, it can allow attackers to gain unauthorized access to sensitive data. The conversation also touched on how many security incidents occur due to simple oversights, emphasizing the need for better monitoring and security practices. As more organizations move their operations to the cloud, understanding these vulnerabilities is crucial for safeguarding against potential breaches.

Read Original

A major crackdown on sports piracy has resulted in the shutdown of 44 domains associated with PirloTV, a notorious streaming service. This operation was carried out by the Alliance for Creativity and Entertainment (ACE) in partnership with UEFA, the Spanish National Police's Cybercrime Unit (UC3), and Mexican authorities. PirloTV has been linked to illegal streaming of sports events, which undermines the revenue of legitimate broadcasters and affects sports organizations financially. The takedown is a significant step in combating online piracy, aiming to protect the rights of content creators and ensure that fans access sports through legal channels. This action underscores the ongoing efforts to address digital piracy in sports broadcasting.

Read Original

BreachRx has launched a new AI incident command center called the Rex Platform, aimed at addressing the rise in cyberattacks that have become more frequent and sophisticated. The company points to the growing use of AI tools that have made it easier for less experienced attackers to launch these attacks. This new platform is designed to help organizations manage multiple simultaneous cyber incidents more effectively. As cyber threats evolve, having a dedicated tool like the Rex Platform could be critical for companies looking to protect their data and infrastructure. The launch reflects a broader trend in cybersecurity, where the need for advanced solutions is becoming increasingly urgent.

Read Original

A recent report from The Citizen Lab reveals that a Russian government investigative unit hacked the iPhone of opposition politician Andrey Pivovarov using Cellebrite's UFED tool in June 2021. This incident raises serious concerns about the misuse of hacking technology against political dissidents. Cellebrite, a company known for its phone extraction tools, reportedly cut ties with Russian entities, yet their technology was still used in this attack. The implications of such actions highlight the ongoing risks faced by activists and politicians in authoritarian regimes, where surveillance and digital espionage are common. This incident serves as a reminder of the vulnerabilities that exist for individuals opposing oppressive governments.

Read Original

Recent reports indicate a worrying trend where cyber attackers are shifting their focus from educational institutions to the software suppliers that serve them. This means that edtech companies, which provide essential services and tools to schools, are now potential targets for cybercriminals. As these companies often handle sensitive student and institutional data, any breaches could lead to significant data leaks and compromise the security of numerous schools. The implications are serious, as schools may face disruptions in their operations and a loss of trust from parents and students. Stakeholders in education need to be aware of this shift and prioritize cybersecurity measures to protect both their own systems and the software they rely on.

Read Original

The article discusses a shift in cybersecurity focus from external attackers to internal threats. It emphasizes that the biggest risks to organizations now often come from within, citing employees or agents who may unintentionally or maliciously compromise security. This shift means that Chief Information Security Officers (CISOs) are evolving their roles to act more like safety architects, designing systems and protocols that safeguard against these internal vulnerabilities. The article suggests that organizations need to rethink their security strategies, prioritizing training and monitoring of internal personnel. This change is crucial as it impacts how companies protect sensitive data and maintain overall security.

Read Original

The Federal Communications Commission (FCC) has approved new cybersecurity regulations aimed at enhancing the security of national emergency systems and the review processes for undersea cable providers. These rules are designed to prevent potential hijacking of emergency systems, which could lead to significant public safety risks. Additionally, the updated security measures for undersea cables are crucial, as these cables are vital for global communications and can be targets for cyber attacks. The changes reflect a growing recognition of the need to protect critical infrastructure from evolving cybersecurity threats. This move is expected to bolster the overall resilience of the nation’s emergency response capabilities and communication networks.

Read Original

Despite ongoing efforts by law enforcement to crack down on cybercrime, scam centers targeting individuals, particularly in Asian communities, continue to thrive. These centers are part of a larger network that siphons billions of dollars from victims, taking advantage of the lack of effective local oversight. Alarmingly, there are indications of collusion between some local police forces and these scam operations, which complicates enforcement efforts. This situation not only affects the victims directly targeted by these scams but also undermines the trust in law enforcement's ability to protect communities. The persistence of these scams signals a troubling trend in cybercrime that requires urgent attention and action from authorities.

Read Original
PreviousPage 136 of 370Next