Scam websites are targeting gamers with fraudulent offers claiming to provide early access to Grand Theft Auto VI for a fee paid in cryptocurrency. These sites ask users to enter a payment code, promising that the game will unlock upon payment. However, these claims are false, and anyone who engages with these scams is left empty-handed. Rockstar Games has explicitly stated that any site selling early access to GTA 6 is unauthorized and should be avoided. This situation is particularly concerning as it exploits the excitement around the game's release, potentially leading to financial losses for unsuspecting gamers.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
A Russian initial access broker has been linked to the FortiBleed campaign, employing a custom sniffer to capture more than 110 million user credentials since at least February 2026. This campaign raises significant concerns as it highlights the scale at which attackers are operating and the potential dangers to various organizations that may be compromised by these stolen credentials. The threat actor's methods indicate a sophisticated approach to infiltrating networks, which could lead to further exploitation or data breaches. Organizations need to be vigilant and enhance their security measures to protect against such attacks, particularly as the stolen credentials could be used in various malicious activities. The implications of this breach extend beyond immediate threats, as it underscores the ongoing risk posed by credential theft in the cybersecurity landscape.
Xsolis, a healthcare technology company based in Tennessee, has reported a data breach that has affected approximately 1.4 million individuals. The breach occurred due to a phishing attack that compromised personal and health information stored in the systems of its hospital clients. Xsolis provides essential services in utilization management and revenue cycle solutions, making the breach particularly concerning for those whose data was exposed. This incident raises alarms about the security of sensitive health data and the potential risks for identity theft and privacy violations. As healthcare providers increasingly rely on technology, the need for robust cybersecurity measures becomes even more critical to protect patient information.
Former President Donald Trump has signed an executive order aimed at speeding up the transition to post-quantum cryptography (PQC) for federal agencies. This directive mandates that agencies move high-value assets and high-impact systems to PQC by the end of 2030 and 2031. The shift is significant because quantum computing poses a potential threat to current encryption methods, which could be vulnerable to decryption by advanced quantum algorithms. By adopting PQC, the government aims to enhance the security of sensitive data against future quantum attacks. This initiative reflects a growing recognition of the need to prepare for the evolving landscape of cybersecurity threats posed by new technologies.
Infosecurity Magazine
The Five Eyes Alliance, which includes intelligence agencies from the UK, US, Canada, Australia, and New Zealand, has issued an urgent warning about the growing threats posed by advanced artificial intelligence technologies. This unprecedented call to action aims to encourage organizations to address potential risks associated with AI, such as misinformation, deepfakes, and other malicious uses that could affect national security and public safety. The group emphasizes the need for collaboration among governments and private sectors to develop effective strategies and regulations to mitigate these risks. This announcement reflects a recognition that AI is not just a technological advancement but also a significant security concern that demands immediate attention. Organizations across various sectors should take this warning seriously and start implementing measures to safeguard against these emerging threats.
A supply chain attack has targeted users of ShapedPlugin Pro by backdooring plugin updates. Attackers exploited vulnerabilities in the vendor's build and distribution system between April and June 2026, allowing them to deploy malware that steals user credentials and two-factor authentication secrets. If you installed and updated the ShapedPlugin Pro plugin during this period, your website may be at risk. This incident highlights the dangers of relying on third-party plugins and the potential consequences of a compromised vendor's security infrastructure. Users should take immediate steps to assess their sites for potential breaches and consider removing the affected plugin to secure their information.
Xsolis, a company that handles personal and protected health information, recently suffered a data breach affecting approximately 1.4 million individuals. Attackers gained unauthorized access to sensitive data that Xsolis had received from its clients, which raises serious concerns about patient privacy and data security. The breach highlights the risks associated with handling sensitive health information, especially in an era where healthcare data is increasingly targeted by cybercriminals. Affected individuals are at risk of identity theft and other forms of exploitation. Companies in the healthcare sector need to bolster their security measures to protect against similar incidents in the future.
A research team developed a new AI system called EVOHUNT, which improves security auditing by teaching AI agents to identify software bugs using an external playbook. This system keeps the core AI model unchanged, focusing instead on enhancing the way the agent works through a written method. Notably, an open-source model utilizing this evolved playbook outperformed OpenAI's commercial Codex in finding actual vulnerabilities. This finding is significant for organizations looking to enhance their cybersecurity tools, as it suggests that innovative, cost-effective approaches can yield better results than established products. The research emphasizes the potential for AI to improve software security and the need for companies to consider alternative auditing solutions.
Help Net Security
A recent investigation by Spur Intelligence revealed that many smart TV apps from LG and Samsung are embedding residential proxy software. Out of 6,038 apps analyzed on LG's webOS and Samsung's Tizen platforms, 2,058 were found to contain this proxy code. Specifically, 42.5% of LG apps and 26.9% of Samsung apps were implicated. This type of software can reroute internet traffic from other users through a home network, potentially exposing personal data and compromising user privacy. The findings raise concerns about the security practices of app developers and the implications for users who may unknowingly share their internet connections with external parties.
SCM feed for Latest
On June 20, Brazil's national emergency alert system, managed by Defesa Civil Nacional, was compromised, resulting in a false alert that caused panic among residents. The alert, which warned of extreme weather conditions, was sent out despite no actual threat being present. Authorities are investigating how the dispatch platform was breached and are working to prevent similar incidents in the future. This situation raises concerns about the security of emergency communication systems, which are vital for public safety. The incident underscores the need for stronger cybersecurity measures to protect against unauthorized access and misinformation during emergencies.
SCM feed for Latest
A recent survey conducted with over 7,800 participants from eight different countries revealed that a significant number of users, between 40% and 50%, still choose to store their passwords in web browsers for the sake of convenience. This practice raises concerns about security, as browser-based password storage can be vulnerable to various cyber threats, including phishing attacks and malware. Many users may not realize the risks associated with this method of password management, potentially exposing their sensitive information to attackers. The survey indicates a need for greater awareness about secure password practices and encourages individuals to consider more secure alternatives, such as dedicated password managers. As cyber threats continue to evolve, users should reassess their password storage methods to better protect their online accounts and personal data.
SCM feed for Latest
Researchers from Flare examined 470 posts on underground forums from January 2025 to June 2026. They discovered a worrying trend where services are offering targeted searches for login credentials harvested from infostealer malware. This means that stolen data is being actively sold and used for account takeovers, posing significant risks to users whose credentials have been compromised. The implications are serious as it enables cybercriminals to easily access sensitive accounts across various platforms. Companies and individuals should be aware of this threat and take steps to secure their accounts, such as enabling two-factor authentication and regularly updating passwords.
SCM feed for Latest
Anthropic, the AI research company, has updated its privacy policy to require some users to provide additional identification. Under certain circumstances, users may need to submit a scan of a government-issued ID, such as a passport or driver's license, along with a selfie and a facial geometry template. This change is aimed at enhancing user verification and ensuring compliance with regulatory standards. It may affect users who are signing up for specific services or features that require higher security measures. This move raises concerns about user privacy, as it involves sharing sensitive personal information, and could deter some potential users from accessing their services.
Check Point Research has reported a significant rise in the registration of Amazon-themed domains, with 6,843 new domains registered between December and May. Alarmingly, nearly 10% of these domains have been flagged as malicious or suspicious. This spike coincides with Amazon Prime Day, a time when many consumers are actively shopping online, making them prime targets for cybercriminals. The increase in malicious domains could lead to phishing attempts and scams, putting users' personal and financial information at risk. As shoppers gear up for sales events, researchers urge users to be vigilant and verify the authenticity of websites before making purchases.
Researchers have identified four vulnerabilities in Dify, a platform designed for building and managing AI applications. These flaws allow attackers to gain unauthorized access to sensitive chat histories, effectively enabling them to 'wiretap' conversations. This is a significant security concern for users of Dify, as it could lead to the exposure of private and potentially sensitive information. The implications are serious, particularly for businesses and individuals who rely on the platform for confidential discussions. Immediate action is needed to address these vulnerabilities and protect user data from exploitation.