Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

A recent study by ReliaQuest reveals that artificial intelligence is being utilized in cyberattacks in six significant ways. Attackers are using AI to automate processes, making attacks faster and cheaper while also allowing for more covert operations. This trend affects a wide range of organizations, as the increased sophistication of attacks can lead to more successful breaches. Companies need to be aware of these evolving tactics to better defend themselves against potential threats. The findings emphasize the urgent need for enhanced cybersecurity measures to counteract these AI-driven strategies.

Read Original

The article discusses the ongoing challenges that open-source security poses to governments, particularly in the U.S. It highlights how the vast number of open-source software projects creates numerous potential targets for attackers. Companies are reportedly not doing enough to secure their products, which adds to the problem. Additionally, the influence of artificial intelligence is changing the dynamics of these security challenges, making it harder for governments to keep up. The situation is concerning as it raises questions about the safety of critical systems that rely on open-source components.

Read Original

The U.S. Department of Justice has seized a cloud computing account linked to subsidiaries of the Cambodia-based HuiOne Group, which is accused of facilitating money laundering for cyber scams. This action comes alongside new sanctions imposed by the Treasury on nine individuals and 26 entities associated with Prince Group. The account was reportedly used to help transfer illicit funds, raising concerns about the role of these companies in supporting cybercriminal activities. This incident illustrates the ongoing efforts by U.S. authorities to combat financial crimes tied to cyber scams and highlights the broader implications of international financial networks being exploited for illegal activities.

Read Original

A recent report from the Public Accounts Committee (PAC) in the UK has raised alarms about the cybersecurity vulnerabilities facing museums and galleries. According to the PAC, these institutions are not receiving adequate support from the government to bolster their cybersecurity defenses. This lack of resources puts valuable cultural assets at risk, as museums can be attractive targets for cybercriminals seeking to steal sensitive data or disrupt operations. The report emphasizes the need for increased funding and strategic support to protect these institutions from potential cyberattacks, which could lead to significant financial and reputational damage. As digital systems become more integrated into museum operations, the urgency for improved cybersecurity measures becomes increasingly apparent.

Read Original

A serious security flaw has been discovered in Cisco Unified Communications Manager (Unified CM) and its Session Management Edition (Unified CM SME). The vulnerability, identified as CVE-2026-20230, has a CVSS score of 8.6, indicating its severity. It involves improper input validation for specific HTTP requests, which could allow attackers to execute commands remotely without authentication. This means that unauthorized individuals could potentially gain root access to affected systems. Companies using these Cisco products need to act quickly to protect their networks, as the flaw is already being exploited in the wild.

Read Original

Recent discussions have emerged around the identity management challenges associated with AI agents. Researchers have pointed out that as organizations increasingly deploy AI systems, they often overlook the need for robust identity verification processes. This oversight can lead to unauthorized access and manipulation of sensitive data, putting both companies and users at risk. The implications are significant, as weak identity management can result in data breaches and loss of trust in AI technologies. Organizations are urged to implement stricter identity controls to safeguard against these vulnerabilities.

Read Original

Dify has experienced a serious security vulnerability identified as CVE-2026-41947, which affects its tracing system. This flaw allows attackers to establish a persistent channel that can extract any messages and responses from applications that the attacker can access, all without needing authentication. This could potentially expose sensitive data across different tenants using Dify's services. Organizations using Dify must take this issue seriously as it poses a risk to their data security. It's crucial for affected users to assess their exposure and implement necessary security measures to mitigate this risk.

Read Original

Meta has decided to pause its MCI program, which began in April, due to concerns about potential data exposure. The program was designed to enhance the company's artificial intelligence by monitoring how employees interact with their computers, including tracking mouse movements and keyboard shortcuts. However, this employee-tracking initiative raised significant privacy issues, prompting the company to reconsider its approach. By halting the program, Meta aims to address these concerns before moving forward. This incident highlights the ongoing tension between technology advancements and employee privacy rights, prompting discussions about how companies should balance innovation with ethical practices.

Read Original

Samsung has patched a serious vulnerability in its KNOX security software that affects millions of Galaxy devices. The flaw, identified as CVE-2026-20971, is a use-after-free vulnerability located in the kernel, specifically within the PROCA/FIVE component. This issue could allow attackers to exploit the software designed to protect devices, raising significant security concerns for users. Samsung released a fix for this flaw in January 2026, but the potential for exploitation underscores the need for users to update their devices promptly. The vulnerability puts millions of Galaxy users at risk, highlighting the importance of maintaining security updates for mobile devices.

Read Original
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks

BleepingComputer

Actively Exploited

A serious vulnerability, identified as CVE-2026-20230, has been discovered in Cisco's Unified Communications Manager Server. This Server-Side Request Forgery (SSRF) flaw is currently being exploited by attackers, raising concerns for organizations using this software. The vulnerability could allow malicious actors to manipulate requests sent from the server, potentially leading to unauthorized access to sensitive systems. Companies that rely on Cisco's Unified Communications infrastructure need to prioritize patching their systems to protect against these active exploits. As the situation evolves, it is crucial for affected users to stay informed and take immediate action to mitigate risks.

Read Original

Tata Electronics has confirmed that it suffered a cyberattack that affected parts of its IT infrastructure. The company reported that hackers gained access to its systems and subsequently leaked sensitive data. While specific details about the type of data compromised have not been disclosed, the incident raises concerns about the security of sensitive information within the company. This attack highlights the ongoing risks that organizations face from cybercriminals, emphasizing the need for robust cybersecurity measures. Companies must remain vigilant and proactive in protecting their data to prevent similar incidents.

Read Original

Xsolis, a healthcare technology firm, reported a data breach affecting approximately 1.4 million individuals. The breach occurred due to a phishing attack, which allowed attackers to gain unauthorized access to the company's network. The compromised data includes sensitive personal information, raising serious concerns about privacy and security for those affected. This incident underscores the vulnerability of healthcare organizations to cyberattacks, especially as they increasingly rely on digital systems. Individuals whose data was exposed may face risks such as identity theft and fraud, prompting a need for vigilance and protective measures.

Read Original

A significant cyber operation called FortiBleed has been uncovered, targeting over 430,000 FortiGate firewalls worldwide. This operation, attributed to a Russian-speaking group known as an initial access broker, has been active since February 2026 and focuses on harvesting user credentials. The attackers are employing various tactics, including probing for exposed services and brute-forcing systems to gain unauthorized access. With the scale of this operation, organizations using FortiGate firewalls should be particularly vigilant about their security practices. Failure to address these vulnerabilities could lead to compromised systems and sensitive data breaches.

Read Original

A recent discussion has emerged regarding the security of AI agents, particularly concerning how these machine accounts can be authenticated. Researchers are finding that the current methods for managing identity and access for AI agents are lagging behind their rapid deployment. This gap exposes vulnerabilities that could leave systems open to unauthorized access. Organizations that rely on AI technologies need to reassess their security protocols to ensure that these agents cannot be easily exploited. The implications are significant, as poor governance of AI accounts could lead to data breaches or compromised systems.

Read Original

Researchers from Zafran Labs have uncovered four vulnerabilities in Dify, an open-source AI platform widely used by companies like Volvo and Maersk. These flaws put over one million AI applications at risk, exposing sensitive cross-tenant data, documents, and conversations. Notably, two of the vulnerabilities are critical, allowing unauthenticated users to gain access to and potentially steal data. This situation raises serious concerns for organizations that rely on Dify for their AI operations, as sensitive information could be compromised. Companies using this platform should take immediate action to assess their exposure and implement security measures to protect their data.

Read Original
PreviousPage 140 of 370Next