Fortinet has acknowledged a serious credential-harvesting campaign known as FortiBleed, which has resulted in the collection of over 86,000 confirmed working credentials. This campaign poses a significant risk to users and organizations that utilize Fortinet's products, as attackers can exploit these credentials for unauthorized access to sensitive systems. The incident is particularly alarming because it affects a wide range of users, potentially including businesses that rely on Fortinet's security solutions. Companies should take immediate steps to secure their systems and monitor for any suspicious activities, as the implications of this data breach could lead to further attacks or data leaks. This situation underscores the ongoing challenges in cybersecurity and the need for constant vigilance.
Latest Cybersecurity Threats
Real-time threat intelligence from trusted sources
Infosecurity Magazine
The Information Commissioner of the UK has resigned after an internal investigation deemed his position 'untenable.' While specific details about the investigation have not been disclosed, the resignation raises concerns about the leadership stability at the UK's data protection authority. This agency plays a crucial role in overseeing data privacy laws and regulations, making the situation particularly significant for individuals and organizations relying on robust data protection. The departure of the commissioner could impact ongoing regulatory efforts and the enforcement of data protection standards in the UK, especially in the wake of increasing scrutiny over data privacy issues. Stakeholders will be watching closely to see who will fill this important role and how it may affect the future of data protection in the country.
Several cybersecurity firms, including HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium, have reported being affected by a recent hack targeting Klue, a company that provides competitive intelligence solutions. The exact nature of the breach and the data compromised remain unclear, but the incident raises concerns about the security of sensitive information held by these firms. As cybersecurity companies, their exposure could have wider implications, potentially affecting their clients and the overall trust in the industry. The situation is still developing, and organizations that rely on Klue's services should be vigilant and assess their security measures in light of this incident.
The Hacker News
A new type of malware called AryStinger is infecting legacy home routers, turning them into a distributed reconnaissance and proxy network. Researchers from QiAnXin's XLab have identified at least 4,300 infected routers, and that number is likely to grow. Unlike typical malware that creates a DDoS botnet, AryStinger is designed for the reconnaissance phase of an attack, gathering information before any actual intrusion occurs. This shift in tactics poses a significant risk as attackers can use these compromised devices to gather sensitive data about potential targets without raising alarms. Home users and organizations relying on older routers could find themselves vulnerable if these devices are compromised.
Texas Parks and Wildlife Department (TPWD) has reported a significant data breach affecting approximately 3 million individuals. The breach occurred after hackers accessed the systems of a third-party vendor that handles licensing for the department. The stolen data includes personal information, although specific details about what types of information were compromised have not been disclosed. This incident raises concerns about the security of third-party services that organizations rely on, as breaches can have widespread impacts on individuals' personal information. Affected individuals may need to monitor their accounts for any suspicious activity and consider additional security measures.
A recent survey by CrowdStrike revealed that a staggering 94% of organizations have experienced breaches in their cloud environments. This alarming statistic highlights the growing concerns around cloud security, as businesses increasingly rely on cloud services for their operations. The survey suggests that many companies are struggling to effectively secure their cloud infrastructures, which can lead to significant data loss and financial repercussions. The findings serve as a wake-up call for organizations to reassess their security measures and implement more robust protections against potential attacks. With cloud breaches on the rise, it’s imperative for companies to prioritize cybersecurity strategies that address these vulnerabilities.
Help Net Security
Recent research from Wake Forest University has revealed that many AI-powered iOS applications are exposing sensitive credentials. Out of 444 apps analyzed, 282 were found to have vulnerabilities that could allow attackers to access backend services and exploit user data. These affected apps span multiple categories, including productivity, entertainment, and education. This situation raises serious concerns about user privacy and the security measures that developers are implementing. It serves as a reminder for app developers to strengthen their security practices and for users to be cautious about the apps they install and the information they share.
The latest Malware newsletter from Security Affairs discusses several significant cybersecurity incidents affecting a wide range of sectors. Notably, a supply chain attack on OptinMonster has compromised 1.2 million websites, raising concerns about the security of third-party services. Additionally, a China-linked threat actor has targeted both public and private medical organizations, focusing on areas like artificial intelligence and national defense research. Another piece highlights the Rokarolla malware, which is designed to steal banking information from Android devices. These incidents underscore the ongoing risks faced by organizations and individuals alike, as attackers increasingly exploit vulnerabilities across various sectors.
Security Affairs
The latest edition of the Security Affairs newsletter discusses several cybersecurity topics, including a new malware called GentleKiller, which is designed to evade endpoint detection and response (EDR) systems. This malware is linked to a global credential-spraying operation that targets numerous organizations, exposing their login credentials. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about active exploitation of various vulnerabilities, urging companies to take immediate action to protect their systems. The newsletter serves as a reminder of the ongoing threats in the cybersecurity landscape and the need for organizations to remain vigilant against evolving attack methods.
A new botnet called AryStinger has been discovered, infecting over 4,000 D-Link routers worldwide. This malware targets outdated devices, converting them into proxies that can handle malicious traffic. Users of affected routers may be unaware that their devices are being misused in cyberattacks. The presence of this botnet raises concerns about the security of Internet of Things (IoT) devices, particularly those that are not regularly updated. This incident serves as a reminder for users to keep their router firmware up to date and to secure their home networks against potential threats.
Cyber Defense Magazine
The article discusses the evolving cyber threats faced by the IT and food and agriculture sectors as we look towards 2025. Researchers from IT-ISAC and Food and Ag-ISAC have highlighted that both industries are increasingly vulnerable to sophisticated attacks that can disrupt operations and compromise sensitive data. The findings indicate that cybercriminals are targeting critical infrastructure, which could impact everything from cloud services to the global food supply chain. This is particularly concerning as these sectors are essential for economic stability and public health. Organizations in these fields need to bolster their cybersecurity measures to mitigate the risks posed by these evolving threats.
A new ransomware strain called 'Prinz Eugen' has emerged, targeting recently modified files for encryption while notably avoiding the use of a ransom note on the infected systems. This approach may confuse victims, as they might not realize they've been attacked until it's too late. The ransomware's focus on recent files could affect businesses and individuals who regularly update their documents and data, making recovery more complicated. Users are urged to maintain regular backups and enhance their cybersecurity measures to protect against this evolving threat. The absence of a ransom note also raises questions about the attackers' intentions and future tactics.
Hackers are taking advantage of a recently patched vulnerability in the Gravity SMTP plugin for WordPress, which is used on around 100,000 websites. This security flaw, identified as CVE-2026-4020, allows attackers without authentication to access sensitive information, including API keys and OAuth tokens. The vulnerability has a medium severity score of 5.3, but the potential exposure of critical data makes it a significant concern for site administrators. Users of the Gravity SMTP plugin need to ensure they update to the latest version to protect their sites from these attacks. The urgency of addressing this issue is heightened by the fact that the vulnerability is currently being exploited in the wild.
Hackers are taking advantage of an unauthenticated information disclosure vulnerability in the Gravity SMTP plugin for WordPress, which is installed on around 100,000 websites. This vulnerability allows attackers to access sensitive information without needing to log in, potentially exposing user data and other critical site details. The flaw poses a serious risk to website owners and their users, as it could lead to further attacks or data breaches. Website administrators are urged to assess whether they are using this plugin and to take necessary actions to secure their sites. Ignoring this issue could leave users’ information vulnerable and put the integrity of the websites at risk.
Hackread – Cybersecurity News, Data Breaches, AI and More
Rocket.Chat has successfully migrated from Node.js 14 to Node.js 20, thanks to the release of Meteor 3.0. This upgrade is significant as it addresses the removal of Fibers, which had been a source of runtime debt. By moving to a more current version of Node.js, Rocket.Chat aims to minimize supply-chain risks, especially for its federal users who depend on secure and up-to-date software. This change not only enhances the performance of Rocket.Chat but also aligns it with modern security standards, making it less vulnerable to potential exploits associated with outdated runtimes. Overall, this migration reflects a proactive step toward improving software security and reliability.