Latest Cybersecurity Threats

Real-time threat intelligence from trusted sources

Actively Exploited

Researchers at JFrog discovered an npm package that mimics the popular postcss-selector-parser library, which is used in web development. This malicious package is designed to deliver a multi-stage Remote Access Trojan (RAT) on Windows systems. Users who unwittingly install this lookalike package could find their systems compromised, allowing attackers to gain control and potentially access sensitive information. The incident raises concerns about software supply chain security and the need for developers to verify the authenticity of packages before installation. This situation serves as a reminder for developers and organizations to exercise caution and implement security measures to protect against such deceptive tactics.

Read Original

Abdellah Belmili, an Algerian man, has been charged by federal prosecutors for allegedly operating two online marketplaces that specialize in cybercrime. These websites reportedly sold stolen financial credentials and custom-designed phishing kits specifically aimed at major American banks. This situation raises significant concerns as it highlights the ongoing issue of cybercrime and the ease with which sensitive information can be bought and sold on the dark web. The impact of such marketplaces can be far-reaching, potentially affecting countless individuals and businesses as attackers exploit the stolen data. Law enforcement's action against Belmili underscores the need for continued vigilance in the fight against cybercrime and the protection of financial systems.

Read Original

GitHub is enhancing its software supply chain security by updating the 'actions/checkout' feature to prevent pwn request attacks. These attacks take advantage of the 'pull_request_target workflow' trigger, allowing malicious code to run with full privileges. The update, set to take effect on June 18, 2026, aims to protect users from potential exploitation by ensuring that workflows cannot execute harmful code from untrusted contributors. This change is significant for developers and organizations that rely on GitHub for their workflows, as it directly addresses vulnerabilities that could compromise their projects. By implementing this update, GitHub is taking proactive steps to secure the development process and maintain trust in its platform.

Read Original

OpenAI has rolled out an expanded version of its Daybreak tool, now featuring a full GPT-5.5-Cyber release. This tool is designed to assist cybersecurity professionals in identifying and patching software vulnerabilities more effectively. By improving the capabilities of Daybreak, OpenAI aims to support defenders in their efforts to secure systems against potential attacks. This expansion is crucial as software flaws continue to pose significant risks to organizations, making timely remediation essential for safeguarding sensitive data and maintaining operational integrity. The release emphasizes OpenAI's commitment to enhancing cybersecurity tools that can adapt to the evolving landscape of threats.

Read Original

Recently disclosed vulnerabilities can be exploited by attackers much faster than organizations can patch them. This has raised concerns among security teams about their ability to validate whether these vulnerabilities can be exploited, even before public exploits are available. Picus Security has suggested methods for security teams to assess the exploitability of these vulnerabilities proactively. This approach is crucial for organizations to stay ahead of potential attacks and mitigate risks effectively. As the pace of vulnerability disclosure increases, companies need to develop strategies to quickly evaluate and address these security gaps to protect their systems and data.

Read Original

Former President Trump has signed an executive order mandating that all U.S. federal agencies transition to post-quantum cryptography by 2031. This move comes in response to increasing concerns about the potential vulnerabilities of current encryption methods in the face of advancing quantum computing technology. The order requires agencies to develop and implement plans to ensure their data remains secure against future quantum attacks. This is significant because existing encryption techniques could become obsolete, putting sensitive government data at risk. The deadline emphasizes the urgency for agencies to adopt new standards and technologies to protect national security and personal information.

Read Original
Actively Exploited

Researchers have taken action against SocGholish, a malicious traffic distribution system (TDS) that has been used by cybercriminal groups, including the well-known Evil Corp, to gain unauthorized access to victims' networks. This system is designed to deliver malware to unsuspecting users, making it a significant threat to various organizations. The impact of SocGholish is widespread, as it affects any entity that could fall victim to its deceptive tactics. The operation's disruption is crucial, as it not only helps protect potential targets but also disrupts the financial schemes of the cybercriminals behind it. Companies and individuals are urged to remain vigilant and enhance their cybersecurity measures to defend against such threats.

Read Original
Critical
GTA 6 Scams Emerge as Pre-Orders Open

Infosecurity Magazine

Actively Exploited

As pre-orders for Grand Theft Auto 6 open, cybercriminals have begun exploiting the excitement by creating fake pre-order websites. These fraudulent sites promise early access to the game in exchange for cryptocurrency payments. Unsuspecting fans are at risk of losing their money as they may think they are securing a legitimate pre-order. This situation is concerning because it not only affects potential players but also highlights the ongoing issue of online scams that thrive around popular game releases. Users should be cautious and verify sources before making any payments to avoid falling victim to these scams.

Read Original

Cybercriminals have developed a Golang-based sniffer that targets FortiGate firewalls, impacting around 430,000 devices and potentially exposing 110 million credentials. This ongoing attack campaign is a serious threat to organizations relying on these firewalls for network security. The attackers are using this sophisticated tool to intercept and steal sensitive login information, which could lead to further breaches or unauthorized access to systems. Companies using FortiGate firewalls should be particularly vigilant and consider immediate security assessments to safeguard their networks. The scale of this incident raises concerns about the effectiveness of current security measures in protecting critical infrastructure.

Read Original

A newly discovered vulnerability in FFmpeg, dubbed ‘PixelSmash’, could allow attackers to execute remote code via specially crafted video files. This flaw occurs due to a heap buffer overflow that can overwrite a function pointer, potentially giving the attacker control over the affected system. Users of FFmpeg, especially those incorporating it into other applications or services, need to be aware of this risk, as it could lead to serious security breaches. Developers and system administrators are urged to monitor their systems closely and apply any available patches to mitigate the threat. The vulnerability underscores the importance of maintaining up-to-date software in order to protect against exploitation.

Read Original

A security vulnerability known as the PixelSmash flaw has been discovered in FFmpeg's libavcodec library, which is used by various video players, media servers, and NAS appliances. This weakness allows attackers to craft malicious media files that can execute arbitrary code in any application leveraging this library. As a result, systems using FFmpeg could be compromised simply by processing these specially designed files. This is a significant concern for users and organizations relying on FFmpeg for media handling, as it opens the door for potential remote code execution attacks. Companies should prioritize reviewing their media processing systems and apply necessary updates to mitigate this risk.

Read Original
The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027

Hackread – Cybersecurity News, Data Breaches, AI and More

The article discusses how emerging technologies like artificial intelligence, deepfakes, synthetic identities, and fraud-as-a-service are expected to change the landscape of iGaming fraud by 2027. As these technologies advance, security teams will face new challenges in detecting and preventing fraudulent activities that can harm both operators and players. The rise of synthetic identities, for instance, could make it easier for fraudsters to bypass security measures. The piece emphasizes the need for proactive strategies and updated detection methods to stay ahead of these evolving threats. As the iGaming industry continues to grow, understanding these potential risks will be crucial for maintaining trust and security.

Read Original

OpenAI has announced an expansion of its Daybreak cybersecurity initiative, which now includes new tools and partnerships aimed at improving security measures. The focus has shifted from discovering vulnerabilities to patching existing ones, signaling a proactive approach to cybersecurity. This change comes as companies face increasing pressure to protect their systems against cyber attacks. By prioritizing patch management, OpenAI aims to reduce the risk of exploitation and enhance overall security for its users. This initiative is particularly significant as organizations continue to adapt to evolving cyber threats and the need for robust defenses.

Read Original
Actively Exploited

Anthropic's Fable 5 model, designed to be a safer version of its Mythos Preview, has been compromised shortly after its release. The model was built with guardrails to prevent its misuse in creating cyberattacks. However, researchers discovered that these protections could be bypassed within days of the model becoming available. This incident raises concerns about the security of AI models and the potential for misuse, particularly as they become more integrated into various applications. The ability to circumvent these safety measures could lead to harmful applications, emphasizing the need for stronger safeguards in AI technologies.

Read Original

Vishing, or voice phishing, is emerging as a significant cybersecurity threat as attackers increasingly target employees through phone calls instead of emails. This method of social engineering exploits human behavior, tricking individuals into divulging sensitive information or performing actions that compromise security. Companies must be vigilant, as these attacks can lead to data breaches or financial loss. To protect against vishing, organizations should educate employees about the risks, establish clear protocols for verifying callers, implement call monitoring systems, and encourage reporting of suspicious calls. By taking these proactive measures, companies can reduce their vulnerability to this type of fraud.

Read Original
PreviousPage 141 of 370Next