Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

Ransomware groups are increasingly targeting organizations in Europe, marking a shift in their focus after a period of decreased activity. This trend poses significant risks to EU businesses and their suppliers, as attackers exploit vulnerabilities to gain access to sensitive data and demand ransoms. The rise in attacks could disrupt operations and compromise the security of critical services across the region. Companies in Europe need to bolster their cybersecurity measures to defend against these evolving threats. The situation highlights the need for ongoing vigilance in protecting against ransomware, especially as attackers find new opportunities in lucrative markets like the EU.

Read Original

Curl, the widely used open-source data transfer tool, has patched a vulnerability that has existed for 25 years. This update also addresses a total of 18 medium and low-severity vulnerabilities. The fixes are crucial for developers and organizations that rely on Curl for transferring data over various protocols, as these vulnerabilities could potentially be exploited if left unaddressed. Users of Curl should ensure they update to the latest version to protect their systems and data from possible attacks. Regular updates are essential in maintaining security, especially with tools that have been in use for such a long time.

Read Original
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited Months Before Disclosure

Security Affairs

Actively Exploited

A serious vulnerability in Cisco Catalyst SD-WAN, identified as CVE-2026-20245, has been exploited by hackers for months before it was publicly disclosed. This flaw, which has a CVSS score of 7.8, allows authenticated attackers to execute privileged commands on affected systems. Google-owned Mandiant reported that the exploitation occurred at least two months prior to the disclosure, raising concerns about the security of networks using this technology. Organizations using Cisco Catalyst SD-WAN should take immediate action to secure their systems, as this vulnerability poses a significant risk to network integrity. The incident serves as a reminder of the importance of timely disclosure and patch management in cybersecurity.

Read Original

Entrust has launched a new biometric authentication solution designed to enhance security during high-risk transactions such as account recovery and large purchases. As cybercriminals increasingly target these vulnerable moments, traditional authentication methods are proving inadequate. The new system aims to confirm the identity of users more effectively, reducing the risk of account takeovers. By focusing on verifying the individual behind a transaction rather than just granting access, Entrust hopes to strike a balance between security and user experience. This advancement is crucial for organizations looking to prevent fraud while maintaining a seamless process for their customers.

Read Original

A new backdoor known as Mistic has been discovered in a series of financially motivated cyberattacks targeting organizations across various sectors, including insurance, education, IT, and professional services. This backdoor, also referred to as MLTBackdoor, has been linked to an initial access broker called KongTuke. Researchers from Symantec and Carbon Black's Threat Hunter Team have traced the deployment of Mistic back to April 2026. The stealthy nature of this backdoor raises concerns as it allows attackers to infiltrate systems undetected, potentially leading to data theft or other malicious activities. Organizations in the affected sectors should be on high alert and strengthen their cybersecurity measures to combat this emerging threat.

Read Original

The National Institute of Standards and Technology (NIST) has opened up its updated guidance on Internet of Things (IoT) security for public review. This guidance is designed to set cybersecurity standards for IoT devices used in federal agencies' networks. By establishing clear product requirements, NIST aims to enhance the security posture of these devices, which are increasingly integrated into critical government operations. The public review period allows stakeholders, including industry experts and the general public, to provide input on the proposed guidelines. This initiative is significant as it addresses growing concerns over the vulnerabilities associated with IoT devices, which can be entry points for cyberattacks.

Read Original
Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

The Hacker News

Actively Exploited

A recently discovered vulnerability in Cisco Catalyst SD-WAN has been exploited by an unknown attacker for at least two months before its public disclosure. This security flaw, identified as CVE-2026-20245, has a high severity rating of 7.8 and allows an authenticated local attacker to execute arbitrary commands with elevated privileges. This means that if an attacker gains access to a system, they could potentially take control of critical functions within the network. Companies using Cisco Catalyst SD-WAN should be aware of the risk posed by this vulnerability and take immediate action to protect their systems. The findings from Mandiant underscore the importance of timely patching and monitoring for unusual activity in network environments.

Read Original

London police are set to expand their use of live facial recognition technology, which involves the temporary installation of cameras on public infrastructure such as lampposts. These cameras will monitor individuals in real time, comparing their faces against a watchlist of suspects. This move raises significant concerns about privacy and surveillance, as it could impact everyday citizens who are not involved in criminal activity. Critics argue that the technology could lead to wrongful identifications and an erosion of civil liberties. The increased use of such surveillance tools reflects a broader trend in law enforcement adopting advanced technologies, prompting ongoing debates about the balance between security and privacy rights.

Read Original

A young hacker known by the alias "Snoopy" has been sentenced to 18 months in prison for his involvement in a cyberattack on DraftKings in November 2022. The 21-year-old was part of a scheme that compromised user accounts on the popular sports betting platform, affecting many users who had their information and possibly funds at risk. This incident illustrates the ongoing challenges companies face in securing their platforms against cybercriminals. Snoopy's sentencing serves as a reminder of the legal consequences of hacking and the importance of robust security measures for online services. Users of such platforms need to remain vigilant and take steps to protect their accounts, especially in light of similar incidents in the future.

Read Original

Mandiant has reported on a serious vulnerability in Cisco's Catalyst SD-WAN, identified as CVE-2026-20245, which has been exploited by hackers to gain root access to affected devices. This zero-day attack allows attackers to create unauthorized root accounts, compromising network security for organizations using this technology. The vulnerability poses a significant risk to businesses relying on Cisco's SD-WAN solutions, as it can lead to unauthorized access and potential data breaches. Companies should urgently assess their systems for this vulnerability and implement necessary security measures to protect their networks.

Read Original

Researchers are warning about a new type of cybersecurity threat where attackers manipulate trusted data sources to trick autonomous AI systems. This tactic includes techniques such as hidden content injections and cognitive state poisoning, which can lead AI agents to make incorrect decisions based on compromised information. The implications are significant, as this could affect various industries relying on AI for decision-making, potentially leading to misinformation or harmful actions. Organizations using AI need to be aware of these vulnerabilities and ensure their data sources are secure and reliable to prevent exploitation. As these methods evolve, continuous monitoring and updates to AI training processes will be crucial.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a serious vulnerability affecting Lantronix EDS5000 Series devices. This flaw, identified as CVE-2025-67038, has a high severity score of 9.8 and involves a code injection issue that could allow attackers to execute malicious code. CISA is urging Federal Civilian Executive Branch agencies to implement available fixes before the deadline of June 26, 2026. The active exploitation of this vulnerability raises concerns about potential unauthorized access and control over affected devices, which could lead to significant security breaches. Organizations using these devices should prioritize applying security updates to mitigate risks.

Read Original

OpenClaw recently removed five malicious packages from its skills marketplace, ClawHub, after they were found to bypass security checks. These packages included infostealers and other harmful threats that could compromise the security of users' systems. This incident raises concerns about the effectiveness of security measures in place at ClawHub and the potential risks faced by users who might unknowingly download these malicious skills. The presence of such threats not only endangers individual users but also poses a risk to the broader AI supply chain, as these vulnerabilities could be exploited by attackers to gain unauthorized access to sensitive information. Companies and developers using OpenClaw should be vigilant and ensure their systems remain secure against such threats.

Read Original

Researchers from LayerX have successfully tricked AI browsers, including ChatGPT Atlas and Comet, into revealing sensitive user credentials. By exploiting weaknesses in the systems' guardrails, they demonstrated that these AI tools could be manipulated to bypass security measures designed to protect user data. This incident raises significant concerns about the reliability of AI-driven applications, especially as they become more integrated into daily online activities. Users of these AI browsers should be aware of the potential risks and take extra precautions when sharing sensitive information. The findings suggest that AI systems need stronger safeguards to prevent similar exploits in the future.

Read Original
Critical
New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

The hacking group GhostShell is targeting Ukraine's drone defense sector by using fake documents related to drones to deceive defense teams. Researchers have identified that this cyber campaign is aimed at stealing passwords and sensitive information from these teams. The implications of this attack are significant, as it not only compromises the security of critical defense systems but also highlights the ongoing risks faced by Ukraine amid its conflict. The attackers' tactics demonstrate a sophisticated approach to infiltrating sensitive areas, raising concerns for national security. As the situation evolves, it's crucial for defense organizations to remain vigilant and enhance their cybersecurity measures.

Read Original
PreviousPage 138 of 370Next